Australia’s National AI Plan is a welcome start on skills and safety, but it plays too safe. While the US, Europe and the Gulf pour sovereign capital into chips, compute and energy, Canberra is still talking about catalysing investment rather than committing.
A significant supply chain attack has struck the US financial sector, with fintech vendor Marquis Software Solutions confirming a ransomware incident that exposed the sensitive data of hundreds of thousands of customers from dozens of American banks and credit unions.
South Korean e-commerce giant Coupang has confirmed a massive data breach exposing the personal information of 33.7 million customers. The incident, which began in June 2025, is one of the largest in the nation's history and is linked to a former employee's active credentials.
Cybersecurity in Corporate Australia: ASIC's Strategic Push
ASIC's Cyber Pulse Survey 2023 shows a low cyber maturity score of 1.66/4, highlighting reactive approaches to cyber risks. ASIC calls for improved resilience, aligning with the SIX Shields Cyber Strategy 2030 and global trends for stronger cybersecurity practices.
The Australian Securities and Investments Commission (ASIC) unveiled the Cyber Pulse Survey 2023 in November, providing a critical evaluation of Australia's corporate cybersecurity posture. The survey revealed a concerning trend: with an average cyber maturity score of 1.66 out of 4, most organisations are reacting to cyber risks rather than proactively managing them. This assessment, derived from measures of governance, risk management, information asset protection, and incident responsiveness, signals a pressing need for enhanced cyber resilience.
ASIC's Focus on Practical Cyber Resilience
ASIC Chair Joseph Longo stressed the importance of resilience, advocating for regular and rigorous testing of cybersecurity plans. This stance is part of ASIC's larger mission to pinpoint and address industry-specific cyber vulnerabilities, guiding an overall improvement in cyber resilience. The survey's individual reports, received by 95% of participants, provide valuable insights for organisations to gauge their cybersecurity standing against industry benchmarks.
The SIX Shields Cyber Strategy 2030 and Regulatory Policy Evolution
The findings from the survey are pivotal in shaping both ASIC's and the Federal Government's strategic policies, particularly in light of the SIX Shields Cyber Strategy 2030. Endorsed by key figures like Clair O'Neill, this comprehensive strategy aims to enhance the security and handling of financial institutions, addressing emerging concerns in corporate Australia highlighted in the latest regulatory reports.
Guidance and Recommendations from ASIC
ASIC's report offers tailored guidelines for organisations, establishing a baseline standard for cybersecurity practices. These standards are expected to influence ASIC's future regulatory actions. Key recommendations include conducting risk assessments, establishing contractual obligations with third parties, identifying critical business services, and implementing advanced encryption and email security practices. The report, useful for both technology experts and leadership teams, outlines red flags and provides practical guidance for meeting minimum standards.
ASIC's and the U.S. Securities and Exchange Commission Parallel Regulatory Tightening
ASIC's regulatory expansion into cybersecurity was notably exemplified in 2020 with action against RI Advice for inadequate cyber protections, a case that set a precedent for future regulation. This expansion aligns with global trends, paralleling initiatives in the U.S. and emphasising the proactive management of cyber risks.
ASIC's ASIC's approach parallels regulatory tightenings seen in the U.S., underscoring a global trend towards heightened cybersecurity vigilance. Like its American counterpart, ASIC is placing increased emphasis on directors' responsibilities to proactively mitigate cyber risks.
In his address at the Australian Financial Review Cyber Summit, Longo warned of potential enforcement actions against boards and directors who neglect cybersecurity and cyber resilience. This stance highlights ASIC's commitment to an "active approach" in managing cyber risks, particularly concerning third-party dependencies.
Editor outlook
The Cyber Pulse Survey 2023 and the alignment with the SIX Shields Cyber Strategy 2030 mark a critical juncture in corporate Australia's approach to cybersecurity. This shift towards a more resilient, proactive stance is in line with global trends and reflects a deeper understanding of cybersecurity's importance in the corporate sector.
As regulatory bodies evolve their strategies, companies are encouraged to bolster their cyber defences and align with these new standards, ensuring protection against the dynamic and challenging landscape of cyber threats.
A wave of cyber attacks disrupted Australia’s defence and industry sectors, as confidential military data and industrial networks were exposed by state backed and criminal groups. ASIO’s director warns these persistent threats now demand urgent, coordinated cyber security action.
Kmart’s facial recognition breach exposes more than a privacy violation. This extended analysis unpacks Wesfarmers’ compliance failures, the identity risks of biometric data, and how retail surveillance linking with social media could erode consumer trust.
Microsoft 365 remains healthcare’s weakest security link, with breaches rising from 43% in 2024 to 52% in mid-2025. Patient data exposure, soaring costs, and AI-driven cyberattacks in Australia highlight urgent gaps. Policymakers face mounting pressure to safeguard data sovereignty.
Cyber incidents in the Asia-Pacific have surged 29% in the past year, with Australia facing major breaches at the University of Western Australia and Qantas. Manufacturing is the top target, deepfakes are on the rise, and experts warn the region is in a digital arms race demanding urgent action.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!