top of page
Search

Cybersecurity Is a Governance Issue: How Australian Boards Should Be Responding in 2025

Feb 25
5 min read

Updated: Mar 4


More than half of Australian boards name cybersecurity their top strategic priority. But awareness alone is not governance. Here is what meaningful board-level oversight of cyber risk actually looks like.



Australia has experienced some of the most damaging cyber incidents in its corporate history over the past three years. From large-scale data breaches affecting millions of consumers to ransomware attacks that crippled critical infrastructure, the message for Australian boards has been blunt: cyber risk is not an IT department problem. It is a governance problem.


The data confirms this shift in urgency. A 2025 survey by the Diligent Institute, conducted with the Governance Institute of Australia, found that more than half of Australian boards (53%) identify cybersecurity as their top strategic priority — significantly above the APAC regional average of 39%. Forty-seven percent named it the most urgent issue for their next board meeting.


Yet urgency and genuine oversight are not the same thing. This article examines what effective board-level cybersecurity governance looks like in the Australian regulatory environment, and the steps directors can take to move from awareness to accountability.


The Regulatory Stakes Have Never Been Higher


In 2024, the Federal Court imposed $2.5 million in penalties against FIIG Securities Limited following an ASIC-initiated action for cybersecurity failures that resulted in the theft of approximately 385GB of sensitive client data affecting around 18,000 clients. Critically, this was the first time penalties had been ordered for cybersecurity failures under Australian financial services licensee obligations ... and it will not be the last.

The case establishes a clear precedent: an organisation's failure to implement and maintain adequate cybersecurity governance is not just a technical deficiency, it is a breach of legal obligations. For directors, it reinforces that cyber risk oversight is part of their duty of care under the Corporations Act.


ASIC has since stated clearly that it expects financial services providers to prioritise cyber resilience and invest in governance systems proportionate to the size and sensitivity of the data they hold. APRA's Prudential Standard CPS 234 sets similar expectations for banks, insurers, and superannuation funds, requiring controlled environments, regular testing, and board-level accountability for information security.

Beyond financial services, the Security of Critical Infrastructure Act 2018 (amended) imposes cyber risk management obligations on entities across eleven critical infrastructure sectors, with mandatory incident reporting and, for the highest-risk assets, government step-in rights during serious attacks.


The Evolving Threat Landscape: What Boards Need to Understand


Australian boards cannot govern what they do not understand. CyberCX's 2026 Threat Report, drawing on more than 100 serious incidents handled in 2025, identified cyber extortion as the most prevalent incident type, overtaking business email compromise for the first time. The report also highlighted two trends with direct governance implications:

AI-enabled threats: Malicious use of automation and AI is lowering the barriers to sophisticated attacks, enabling threat actors to operate at greater speed and scale than previously possible. Boards need to understand that the cyber threat environment is escalating, not stabilising.

Internal AI risk: Organisations are increasingly experiencing "data spill" incidents caused by employees uploading sensitive or commercially confidential information into public-facing AI tools. This is not a cybersecurity failure in the traditional sense — it is an AI governance failure. It underscores why AI governance and cybersecurity governance cannot be managed in separate silos.


What Board-Level Cyber Governance Requires in Practice


The ASD's Commonwealth Cyber Security Posture Report and the guidance of ASIC, APRA, and the AICD collectively point to a clear set of expectations for boards overseeing cyber risk. The following components represent the current leading practice standard for Australian organisations:

  • Board-level visibility and reporting: Boards should receive regular, structured cyber risk reporting, not just incident notifications after the fact. This means agreed-upon metrics (e.g., Essential Eight maturity levels, incident response times, third-party assessment outcomes) presented in a format directors can interrogate meaningfully.

  • A named executive accountable for cyber risk: Whether this is a Chief Information Security Officer (CISO) or equivalent, there should be a senior executive with direct board access whose role includes cyber risk management. The CISO should present to the board at least annually.

  • Essential Eight alignment: The Australian Signals Directorate's Essential Eight mitigation strategies represent the baseline cyber security standard for Australian organisations. According to the Commonwealth Cyber Security Posture only 22% of Commonwealth entities reached overall Maturity Level 2 in 2025. For private sector boards, understanding where your organisation sits against the Essential Eight is a reasonable minimum starting point.

  • Incident response planning: Boards should satisfy themselves that the organisation has a tested, up-to-date cyber incident response plan, including communications protocols, regulatory notification timelines, and recovery procedures. The plan should have been exercised through a tabletop simulation within the past 12 months.

  • Third-party and supply chain risk: Significant cyber incidents frequently enter through third-party vendors, suppliers, and service providers. Boards should ensure management has a cyber supply chain risk management program, with vendor assessments proportionate to the access and sensitivity involved.

  • Cyber insurance review: As cyber extortion increases and the cost of incidents rises, boards should ensure cyber insurance policies are reviewed annually and that coverage is adequate given current threat vectors, including AI-enabled attacks and data spill scenarios.


Closing the Gap Between Awareness and Governance

The Diligent/GIA survey identified something that should concern every Australian director: while boards are increasingly aware of cyber risks, many organisations still lack the structures, skills, and governance oversight needed to manage them effectively. Awareness is not accountability.


The gap between awareness and accountability is where reputational and regulatory exposure lives.


Directors do not need to be technical experts, but they do need to ask the right questions, understand the answers, and hold management accountable for maintaining cyber resilience as a genuine organisational capability.


Questions every director should be asking: When was our last independent cyber security assessment, and what did it find? Have we exercised our incident response plan in the past 12 months? Do we have visibility of our critical third-party suppliers' cyber security posture? What is our Essential Eight maturity level, and what is the plan to improve it?

Looking Ahead: Quantum Computing and Post-Quantum Cryptography


Forward-looking boards should also be aware of an emerging, longer-horizon risk. The Australian Signals Directorate has published guidance encouraging all organisations to begin planning for the transition to post-quantum cryptography by 2030. A cryptographically relevant quantum computer would render current public-key encryption protocols insecure, potentially exposing years of archived communications and data. For organisations in critical infrastructure, financial services, and defence supply chains, this is a governance consideration that belongs on the board's longer-term risk horizon now.


Conclusion: Cyber Governance Is Not Optional


The FIIG case demonstrated that Australia's regulators will use existing legal powers to hold organisations accountable for cybersecurity failures. The CyberCX threat data shows that attack frequency and sophistication are increasing. Governance survey data shows that most organisations have not yet matched their growing cyber awareness with the structural oversight it demands.

.

For Australian boards, the path forward is clear: treat cybersecurity as a governance priority with the same rigour applied to financial risk, legal risk, and strategic risk, because in 2025, it is all of these at once.


Is your board's cyber governance fit for purpose? Cipher Advisory offers independent cybersecurity governance reviews, board cyber literacy workshops, and incident response governance assessments for Australian organisations. Reach out to discuss how we can help your board move from awareness to accountability.

 
 
 

Comments


bottom of page