X
  • About
  • Advertise
  • Contact
Subscribe to our Newsletter
  • News
    • Markets
    • Regulation
    • Super
    • Tech
  • Analysis
  • M&A
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
    • Super Fund of the Year Awards
    • Australian Wealth Management Summit
    • Australian Wealth Management Awards
    • Fund Manager of the Year Awards
    • Adviser Innovation Summit
    • ifa Excellence Awards
No Results
View All Results
  • News
    • Markets
    • Regulation
    • Super
    • Tech
  • Analysis
  • M&A
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
    • Super Fund of the Year Awards
    • Australian Wealth Management Summit
    • Australian Wealth Management Awards
    • Fund Manager of the Year Awards
    • Adviser Innovation Summit
    • ifa Excellence Awards
No Results
View All Results
No Results
View All Results
Home Analysis

Responding to a regulator’s call to action

When a regulator tells you to table a letter at the board, the question isn't whether your cybersecurity exists — it's whether you can prove it actually works.

by Morey J Haber
June 2, 2026
in Analysis
Reading Time: 5 mins read
Image: Jarretera/stock.adobe.com

Image: Jarretera/stock.adobe.com

When a regulator tells you to table a letter at the board, the question isn’t whether your cybersecurity exists — it’s whether you can prove it actually works.

Imagine it is a Friday morning anywhere in Australia. An executive at your average organisation pours their first coffee, settles into the chair, and opens their email. Somewhere beneath their quarterly earnings report and the average drudgery of correspondence is a three-page letter from the Australian Securities and Investments Commission (ASIC).

X

The letter does not ask, nor does it suggest but rather it instructs with an unmistakable tone of government regulation that has grown tired of watching the same preventable cyber breaches repeat themselves. The setup highlights how artificial intelligence is impacting the world of cybersecurity and what every organisation should be doing to ensure they are not the next victim. The recommendations are nothing new but an affirmation that the basics must be done, and they need to be done well.

That letter, dated May 8, signed by the ASIC commissioner follows APRA’s call to arms for a step-change in how banks, insurers and superannuation trustees manage AI-related risks as the technology continues to rapidly evolve. It deserves more than a forward to the CISO and leadership team. It deserves a conversation in the boardroom as you’re not just putting your customers at risk, you might well be putting the economy at risk.

What ASIC is describing is not an Australian problem but rather a global issue and the companies that understand that distinction will be far better positioned than those that treat it as a compliance burden. Unfortunately, the devil is in the details. The threat to organisations has not changed, but rather it has been multiplied by AI for severity and impact.

ASIC’s framing is precise and worth repeating: AI models and solutions do not introduce entirely new categories of risk but what they do is amplify the pressure on every cybersecurity control you already have in place.

The barrier to sophisticated cyber activity is now much lower enabling even the old concept of script kiddies to conduct even more attacks at machine speed and precision. A threat actor who previously lacked the technical skill to craft a convincing spear-phishing campaign or chain together multiple vulnerabilities into a coherent intrusion now has access to AI engines that can link multiple attack vectors together and conduct nefarious missions simply based on plain English commands. In other words, the threat actor’s capability to inflict damage has been raised significantly while your organisation’s attack surface has not changed nor has your defenses been leveled up either.

ASIC’s call to action is to treat cybersecurity fundamentals as mission-critical disciplines, and in my opinion, is absolutely the right response for organisations to follow. The open letter enumerates expectations that any seasoned security practitioner will recognise.

This includes minimising the attack surface, putting governance frameworks in place, regularly reviewing user access and reassessing privileges, patching systems promptly, and implementing layered defense-in-depth architectures that assume breach and restrict lateral movement.  This will ensure that you have the appropriate incident response plans in case of a worst-case scenario, and actively manage third-party risks.

These are not new recommendations. They have appeared in NIST guidance, in the Australian Signals Directorate’s (ASD) Essential Eight, and in virtually every post-incident review of a significant breach in the past decade. And yet, as ASIC observed in multiple cases, organisations continue to fail on precisely these controls, not because they lack awareness, but because they lack discipline and potentially budget which warrants a board room discussion. Governance without actionable enforcement is simply assurance without evidence.

The letter makes this point with admirable directness: governance should not rely on assurances alone. It should be supported by test results, audit findings, lessons from incidents, and independent validation. Too often, boards receive activity reports without tested proof that cybersecurity is actually working. That distinction matters enormously. A firewall that has not been tested under realistic conditions is not a control point; it is a hypothesis waiting to be stress tested.

With this in mind, one line in ASIC’s letter deserves to be pulled from the list and placed in bold on everyone’s next agenda: “regularly review user access and reassess privileges”. If you can control the privilege, you can control risk and in my opinion, this is one of the most effective strategies for mitigating AI based attack vectors. This reinforces the principle of least privilege and granting only the access necessary to perform a defined function. In the world of AI, this control is critical.

Overprivileged accounts are not just a lateral movement risk for an external attacker; they are a force multiplier for an AI-assisted attacker who can enumerate, correlate, and exploit access gaps at machine speed. Reducing the blast radius of any single compromised identity is no longer a best practice but rather a necessity when privileges are potentially overprovisioned and not properly accounted for.

Finally, ASIC’s closing instruction is unambiguous: ensure this letter is tabled and discussed at your board and risk governance committees. That is not a boilerplate recommendation but rather a regulatory expectation with legal weight and a firm call to action for everyone.

For boards and senior executives, the questions to ask are not technical. They are governance questions:

  • Is our cyber capability proportionate to the threat environment we actually face today, not the one from our last review? This is especially true in light of the new capabilities threat actors possess.
  • Are we receiving meaningful reporting on whether our controls are working and not just that they exist? Have we ever stress tested them?
  • Do we have evidence, not just assurance, that our incident response plans have been tested against realistic scenarios?

ASIC is not asking organisations to reinvent their approach. It is asking them to put strict controls and governance in place to execute the approach they already have, with the rigour and resourcing the current threat environment demands. It is not a matter of if your controls will be tested. It is a matter of when and whether they will hold.  Are you doing them well enough and can you prove it?

By Morey J. Haber, chief security officer, BeyondTrust

Tags: APRAASIC

Related Posts

Image: Mutshino_artwork/stock.adobe.com

Emerging market debt is back as fundamentals strengthen

by Ward Brown
July 14, 2026
0

A weaker US dollar cycle is boosting the case for emerging markets (EM) debt, with stronger fundamentals, enhanced resilience, and...

Image: Sardar/stock.adobe.com

Why the discount isn’t what pays off in secondaries

by David Hallifax
July 14, 2026
0

Discounts explain the entry point, but growth in the underlying assets is what really drives secondaries returns. Private market secondaries...

Image source: Sundry Photography/stock.adobe.com

Investors can’t agree on SpaceX, here’s why

by Henry Fisher Senior Analyst CMC Markets
July 7, 2026
0

Few companies embody that tension more than SpaceX. Many careful investors view the IPO as a trap to be avoided....

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL

The 2026 Australian Wealth Management Summit returns

The highly anticipated 2026 Australian Wealth Management Summit will return on 13 August at the Shangri-La Sydney bringing together senior...

by Staff
June 11, 2026
Promoted Content

Reallocating for Income: Where Real Estate Private Credit Fits Today

Heightened geopolitical tension, persistent inflation and rising interest rates have combined to create one of the more challenging investment environments...

by Adrian Suljanovic
June 1, 2026
Promoted Content

Vinva discusses alpha opportunities in global equities

In this Product Spotlight, journalist Olivia Grace-Curran speaks with Morry Waked from Vinva Investment Management about the firm’s investment philosophy,...

by Staff Writer
May 25, 2026
Promoted Content

The case for cash in a changing market

In the latest episode of Relative Return, journalist Olivia Grace-Curran speaks with Ben Samuel and Ky Van Tang from First...

by Staff Writer
May 25, 2026

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Latest Podcast

Source: supplied, AMP
News

Relative Return Insider: AI, inflation and astrology’s big moment

by Olivia Grace-Curran
July 13, 2026
After more than two decades, InvestorDaily continues to be an institution that connects and influences Australia’s financial services sector. This influential and integrated media brand connects with leading financial services professionals within superannuation, funds management, financial planning and intermediary distribution through a range of channels, including digital, social, research, broadcast, webcast and events.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Markets
  • Appointments
  • Regulation
  • Super
  • Mergers & Acquisitions
  • Tech
  • Promoted Content
  • Analysis

© 2026 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
    • News
    • Markets
    • Regulation
    • Super
    • Tech
  • Analysis
  • M&A
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
    • Super Fund of the Year Awards
    • Australian Wealth Management Summit
    • Australian Wealth Management Awards
    • Fund Manager of the Year Awards
    • Adviser Innovation Summit
    • ifa Excellence Awards
  • About
  • Advertise
  • Contact Us

© 2026 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited