Why do we need another cyber article? Because breaches in Australia average one every six minutes and my virtual audit file keeps getting thicker. While everyone talks about breaches, as an auditor I would like to talk to you about what happens after the breach and why no company should treat security as “just an IT thing” anymore.
(i.e., it is not something exotic anymore – it’s daily bread and butter of digital underworld masterminds)
Financial knock-ons: revised risk premiums by insurers and material provisions for litigations and customer remediation. Medibank, for example, have already spent $86.2M in relation to their October 2022 breach, when thousands of personal customer data was stolen and published on the dark web. Directly associated expenditure is expected to continue well into 2025. Australian Prudential Regulation Authority (APRA) requested additional equity requirement of $250M. On top of this, Medibank faces a civil suit action, consumer class action AND shareholder class action.
Red flags for Going concern: ransomware downtime can wipe out quarterly EBIT. Latitude lost $76M in “pre-tax costs” during the 6 weeks it was paralysed when they refused to pay the cyber attackers in March 2023.
Related disclosures and impairments:
Control deficiencies: your auditors will start raising significant findings about access logging, passwords, privilege sprawl, data confidentiality of your employees, vendors and customers. The Australian cases I was mentioning before illustrate this point:
Optus’ internal review uncovered unauthenticated API points and missing firewall logs after its 2022 breach;
Latitude Financial’s investigation showed attackers leveraged stolen vendor credentials to establish remote access, resulting in the March 2023 compromise; and
In case of Medibank, it was as simple as hackers getting the username and a password that belonged to an outside IT contractor.
ASIC’s Key Issues Outlook 2025 places cyber governance squarely on directors’ duty‑of‑care radar. The regulator has flagged ongoing investigations and personal liability where boards ignore credible risk signals and recent media releases demonstrate that:
In case of FIIG Securities (March 2025) ASIC found 4 years of weak firewalls and no staff training, which lead to 385GB of sensitive client data stolen. ASIC is seeking civil penalties with the case hearing listed for 2 February 2026.
It is alleged that Directors of Fortnum Private Wealth (July 2025) breached its obligations when they failed to implement adequate policies and procedures. As a result: ASIC has commenced court action against the company demanding penalties.
Until Microsoft patched Copilot in June 2025, a booby‑trapped email could quietly order Copilot to ship whatever you were working on—draft contracts, payroll spreadsheets, even board papers—to a thief’s server. No clicks, no pop‑ups, no antivirus alert.
Note to self: Treat AI helpers like privileged users – patch the moment Microsoft tells you, turn Copilot off on sensitive mailboxes, and keep an eye on outbound traffic logs.
Cyber talk is everywhere, and the advantage belongs to those who listen and prepare.
From an auditor’s seat: breaches translate into journal entries, adverse findings, and sleepless nights for directors. For a complementary global lens, read InCorp Global’s When Cyber Risk Hits Home (Jul 2025)—then compare where your controls stack up.
Get in touch for more insights or direct support - we are here to help. You can also find news, webinars and resources online, and contact us on (02) 8999 1199 for all your tax, accounting and advisory needs.