Back

Super Alert – 14 March 2025: ASIC commences proceedings in relation to alleged cybersecurity failures, critical infrastructure rules registered, APRA FAQ’s

Posted by Sanela Diamantopoulos and Natalie Cambrell on March 14, 2025
Treasury Laws Amendment (Miscellaneous and Technical Amendments) Regulations 2025 (Cth)
Treasury Laws Amendment (Time-Limiting Exemptions) Regulations 2025 (Cth)
APRA
ASIC
Superannuation Data Transformation
cyber security
Corporations Regulations 2001 (Cth)
cyber security failures
Disability Services Act 1986(Cth)
infrastructure regulations
KHQ - Super Alert

Welcome to the weekly KHQ Super Alert. The activities of the various regulators have ramped up considerably this week. ASIC has commenced Court proceedings against a further financial services licensee in relation to alleged cybersecurity failures. Various regulations have been registered dealing with the security of critical infrastructure laws and other miscellaneous Treasury laws. Meanwhile, APRA has released new responses to frequently asked questions for its data transformation project.

ASIC – Proceedings commenced in relation to alleged cybersecurity failures

On 13 March 2025, ASIC issued a media release announcing that it has commenced proceedings against a financial services licensee alleging that it ‘failed to have adequate cybersecurity measures for more than four years’ and therefore breached its general obligations under section 912A of the Corporations Act 2001 (Cth) ‘to do all things necessary to ensure that financial services are provided efficiently, honestly and fairly, to have available adequate financial, technological and human resources, and to have adequate risk management systems’.

ASIC’s media release explains that the ‘cybersecurity failures enabled a hacker to enter [the licensee’s] IT network and go undetected from 19 May 2023 until 8 June 2023, resulting in the theft of personal information and subsequent release of client data on the dark web’.

Click here for details.

Legislation – Further critical infrastructure regulations registered

On 13 March 2025, the Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025 (Cth) were registered on the Federal Register of Legislation. According to the Explanatory Statement, these rules amend the existing Security of Critical Infrastructure (Application) Rules (LIN 22/026) 2022 (Cth) and Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (Cth).

The purpose of the latest rules is to clarify various matters relating to the ‘critical infrastructure risk management programs’ that responsible entities of critical infrastructure assets must have and comply with (unless an exemption applies). For example, the rules prescribe that these programs must ‘consider the material risk of an impact to the availability, integrity, reliability or confidentiality of data storage systems holding business critical data’. The Government’s Cyber and Infrastructure Security Centre has released additional guidance materials for impacted entities.

Click here and here for details.

ASIC – Speech in relation to directors’ duties

On 12 March 2025, ASIC published a speech delivered by its Chair, Joe Longo in relation to directors’ duties. The key messages from Mr Longo were that:

  • ‘[a]ddressing regulatory complexity, increasing technical expertise on boards, more effective reporting from senior management – are changes that can help address some of the challenges facing directors’; and
  • ‘[w]hat hasn’t changed – and won’t change – are the foundational duties and expectations of directors. Directors must still act in good faith, in the best interests of the company, for a proper purpose and with due care and diligence’.

Click here for details.

APRA – FAQs in relation to Superannuation Data Transformation project further revised

On 12 March 2025, APRA announced that it had ‘added ten new and revised two frequently asked questions (FAQs) and added two new worked examples for the Superannuation Data Transformation (SDT) project’. Some of the new FAQs that now have responses are as follows:

  • P2.1 Reporting Dates: ‘Can APRA clarify the first reporting periods and transitional reporting requirements for existing reporting standards?’;
  • SRF 332.0 aa: ‘Can APRA clarify if member-initiated advice activities should be reported in SRF 332.0 under Expense Group Type ‘Advice’ in table 2?’; and
  • SRS 607.0 a: ‘Are intermediary arrangements with Australian Financial Services Licensees (AFSLs) expected to be reported as Promoter agreements in the SRS 607.0 table 1A?’.

Click here for details.

Legislation – Time limit to exemptions in corporations regulations prescribed

On 11 March 2025, the Treasury Laws Amendment (Time-Limiting Exemptions) Regulations 2025 (Cth) were registered on the Federal Register of Legislation. According to the Explanatory Statement, these regulations specify a time limit for certain exemptions contained in financial services laws such as the Corporations Regulations 2001 (Cth). There is no limit to these exemptions currently, so the regulations seek to ‘ensure that there is parliamentary scrutiny of any decision to extend the operation of those exemptions’.

For example, regulation 7.8.21A of the Corporations Regulations 2001 (Cth) provides that certain product offers are exempt from the prohibition against hawking in the Corporations Act 2001 (Cth). This includes ‘an offer for the issue or sale of a financial product that is substantially similar to a financial product…that the recipient…already holds with the offeror…and that is in the nature of an offer to renew the current financial product’. This exemption is now prescribed to cease on 31 December 2027.

Click here for details.

APRA – Latest quarterly superannuation statistics released

On 11 March 2025, APRA announced that it has released the latest version of its ‘Quarterly Superannuation Industry Publication, Quarterly Superannuation Product Statistics and the Quarterly Fund-level Statistics’.

Click here for details.

Legislation – Miscellaneous Treasury regulations made

On 7 March 2025, the Treasury Laws Amendment (Miscellaneous and Technical Amendments) Regulations 2025 (Cth) were registered on the Federal Register of Legislation. As referred to in our Super Alert of 31 January 2025, Treasury consulted earlier in the year in relation to the contents of these regulations.

The following key changes have been made:

  • the Corporations Regulations 2001 (Cth) have been amended to replace all references to ‘executive officer’ to ‘senior manager’ instead to ‘replace the outdated terminology’; and
  • the SIS Regulations have been amended to address the repeal of the former Disability Services Act 1986(Cth).

Click here for details.

Want KHQ Super Alerts delivered straight to your inbox each week? Click here to subscribe.

AUTHORS

Subscribe: