What do director duties for cyber security in Australia actually attach to?
The Corporations Act 2001 (Cth) contains no cyber security duty. It contains section 180(1), which requires a director to exercise their powers and discharge their duties with the care and diligence a reasonable person would exercise if they held that office, with those responsibilities, in that company's circumstances. Cyber risk sits inside that duty in the same way as any other material business risk. The duty is one of oversight and it attaches to each director personally, so a director who was absent from the discussion takes no comfort from the fact that the discussion happened.
The duty does not reach into implementation, and directors who believe it does end up doing the wrong work. Nobody expects a director to judge whether an identity configuration is sound. The exposure sits a level above that: whether the organisation has a system through which the board would learn that the perimeter appliance was unpatched, whether the board asked, and whether anything followed from the answer.
Section 180(2) offers a safe harbour for a business judgment made in good faith and for a proper purpose, without a material personal interest, where the director informed themselves about the subject matter to the extent they reasonably believed appropriate and rationally believed the judgment was in the company's best interests. Section 180(3) defines a business judgment as a decision to take or not take action in respect of a matter relevant to business operations, and that definition decides more cases than the safe harbour itself. A board that never turned its mind to cyber risk has made no decision, so there is nothing for the protection to attach to.
Sector rules sit on top and turn the general duty into dated artefacts somebody has to sign. An Australian financial services licensee carries the section 912A general obligations, including the obligation to have adequate risk management systems. An APRA-regulated entity operates under CPS 234, which makes the board ultimately responsible for the information security of the entity, and since 1 July 2025 under CPS 230, which puts board accountability for operational risk on the same footing. A responsible entity under the Security of Critical Infrastructure Act 2018 (Cth) must give its critical infrastructure risk management program annual report to the regulator within 90 days of the end of the financial year, approved by the board.
What ASIC v RI Advice settled about adequate cyber risk management
ASIC v RI Advice Group Pty Ltd [2022] FCA 496 is where the Australian standard was first articulated. RI Advice held an Australian financial services licence and ran a network of authorised representatives. Cyber incidents occurred across that network between 2014 and 2020, and in one of them an unknown party held remote access to a server containing client information for months before it was detected. The Federal Court declared that RI Advice contravened section 912A(1)(a) and section 912A(1)(h) by failing to have adequate cyber security documentation and controls across the network operating under its licence.
Three findings travel beyond financial services. Rofe J accepted that it is not possible to reduce cyber security risk to zero, but that it can be materially reduced to an acceptable level through adequate documentation and controls, so a board is measured on adequacy rather than prevention and a breach is not by itself proof the controls were inadequate. Judging adequacy calls for the technical expertise of a relevantly qualified person, which is why the Court worked from expert evidence rather than from the licensee's own assessment of itself. The declarations concerned documentation and controls together, which makes the written programme an element of the standard rather than a record of it.
No pecuniary penalty was imposed. The orders required the licensee to engage a cyber security expert and to implement what that expert identified, so the consequence was the finding, the public record and a court-supervised programme of work. The evidentiary consequence for a director is sharper. If adequacy is judged on expert evidence, a board that has never obtained an independent expert view holds nothing at all to put on the central question.
What does reasonable reliance on an expert require you to have already done?
Section 189 is the provision boards lean on when their reliance is challenged, and the condition attached to it carries the weight. Reliance on information or advice is taken to be reasonable, unless the contrary is proved, where the director relies on an employee they believe on reasonable grounds to be reliable and competent on the matter, or on a professional adviser or expert on a matter they believe on reasonable grounds to be within that person's competence. The reliance has to be in good faith and made after the director carries out an independent assessment of the information, having regard to what they know of the company and the complexity of its structure and operations.
An independent assessment is not verification of the technical content, which no board could perform. It means the director engaged with the material, tested it against what they already knew about the business, noticed what the paper did not say, and asked. Minutes recording that the security update was received and noted describe the absence of that engagement. Minutes recording that a director asked why the supplier assessment covered four of the seven names on the critical list, and recording the answer given, describe reliance that survives being tested later.
Section 190 handles delegation and is stricter than most directors expect. Where the board delegates a power under section 198D, each director remains responsible for the delegate's exercise of it as though the board had exercised it. The exception requires the director to have believed on reasonable grounds that the delegate would act in conformity with directors' duties, and to have believed on reasonable grounds, in good faith, and after making proper inquiry if the circumstances indicated a need for inquiry, that the delegate was reliable and competent for the power delegated. The inquiry clause is the one boards miss, because circumstances indicate a need far more often than a comfortable board notices. Keeping the triggers below in the board's own papers makes inquiry a standing response rather than an act of suspicion aimed at a colleague.
- A peer in the same sector has been compromised in a way that would work against your organisation.
- The person accountable for building the controls is also the only person reporting on whether they work.
- An acquisition, a new platform holding customer data, or a change of major supplier has altered the estate since the last assessment.
- The reporting has described the position as satisfactory for several consecutive periods without the underlying assessment being redone.
- An insurer, a large customer or a regulator has asked a question the organisation could not answer from documents it already held.
What should a cyber security board report actually contain?
Most cyber material that reaches a board is a status report when what the duty calls for is a decision record. Anyone reading the papers afterwards, whether a regulator, a plaintiff, an insurer assessing a claim or an acquirer running diligence, works backwards from the incident and asks four things: was the risk visible to the board before the event, what did the board ask, what was it told, and what changed as a result. A pack made of activity descriptions answers none of them.
So the pack opens with what the organisation is protecting in business terms, meaning the data sets whose exposure would trigger a notification assessment and the systems whose loss stops it trading. Then it carries a position against a named external benchmark with the assessment date and the assessor named, because a benchmark is what turns an opinion into something comparable with last quarter. The gap list that follows shows movement rather than a fresh account of work performed, and the risks currently being accepted appear as acceptances rather than sitting among the open items.
The table below maps the questions a board should be asking to the artefact that answers each one and the person who should own it. Where a row has no artefact, that gap is the finding, and finding it in a board meeting costs considerably less than finding it afterwards.
| Question the board asks | Artefact that answers it | Owner |
|---|---|---|
| What would hurt us most if it were encrypted, stolen or published? | Register of critical systems and data sets mapped to business impact and notification obligations | Executive accountable for the business line, with the security lead |
| Where do we sit against a named external benchmark, and who measured it? | Dated assessment against Essential Eight maturity levels or the certification standard in use, assessor named | Independent assessor, tabled by the risk owner |
| Have our defences been tested by someone who did not build them? | Penetration test report with scope, date, findings and retest status | Independent tester; remediation owned by the platform owner |
| If we were locked out on a Friday night, how would we trade on Monday? | Restore test evidence with the measured time to recover, plus a continuity exercise report | Chief operating officer or equivalent, with technology |
| Which suppliers can we not operate without, and what have we verified? | Critical supplier register with contractual security terms, assurance held and last review date | Contract owner, with the security lead |
| What are we deliberately not fixing, and who decided that? | Risk acceptance records showing residual risk, compensating controls, expiry date and accepting officer | Named accepting officer, tabled by the risk function |
| Who makes the first calls in an incident, and when did we last rehearse it? | Incident response plan with named roles and a dated exercise report covering board escalation | Incident owner, with the company secretary for notifications |
Board questions on cyber risk, the artefact that answers each one, and who owns it
Which cyber measures carry information, and which fill a slide?
The measures that dominate cyber board reporting are the ones a security product generates without being asked: threats blocked, messages quarantined, attacks stopped at the perimeter, training completion percentages, and a colour grid with no stated method behind the colours. These move with attacker volume and vendor tuning rather than with anything the organisation controls, and no board decision follows from any of them. A quarter in which more attacks were blocked is indistinguishable from a quarter in which more attacks were attempted.
A measure earns a place in the pack when it satisfies three conditions. The board can act on it, in the sense that a bad value has an identifiable owner and an identifiable remedy. The value moves when the organisation changes rather than when the outside world does. The method behind it is stable enough that this period's figure compares with the last. Measures built that way are counts of things the organisation owns or elapsed times it controls.
Every number should carry the date it was measured. A maturity rating produced fourteen months ago is a historical fact, and a board that receives it as a current position has created its own problem: the minutes will show the board believed the position was current and the assessment will show it was not.
- The number of internet-facing systems carrying a known critical vulnerability older than the organisation's own patching commitment, with the oldest item named.
- The count of privileged accounts, and how many are not protected by phishing-resistant multi-factor authentication.
- Elapsed time from a critical patch being released to it being deployed across the fleet, reported as a spread rather than an average, because the average hides the systems nobody will restart.
- Assets discovered in the last period that were not on the inventory, which measures whether the inventory describes reality.
- The date of the last successful restore from backup and the time the restore took, rather than the recovery target the policy states.
- Accounts belonging to people who have left, and how long they remained enabled after the departure date.
Third party and supply chain risk at board level
The most transferable fact in the RI Advice matter is that the incidents happened at authorised representatives rather than on the licensee's own systems, and the licensee was still held responsible. Responsibility follows the data and the relationship, and moving the processing to somebody else does not move the duty with it. The regulated overlays say so directly: CPS 234 requires an APRA-regulated entity to assess the information security capability of parties managing its information assets, and the assessment clock under the Notifiable Data Breaches scheme starts when the entity has reasonable grounds to suspect an eligible breach, including one that occurred inside a provider.
Boards should ask for two lists, because they are not the same list. The first is the suppliers the business could not operate without for a week. The second is the suppliers who hold or can reach its sensitive data, which includes small vendors nobody thinks of as critical until their access is understood. For each entry the board needs four facts: what happens operationally if the supplier is unavailable, whether the contract obliges them to notify a breach and within what period, what assurance the organisation actually holds about them, and when that assurance was last refreshed.
Boards ask about concentration less often than they should. Several critical suppliers running on the same underlying platform, or authenticating through the same identity provider, produce a register that looks diversified and behaves as a single item, so the question worth putting on the agenda is which single failure would take out more than one line on the critical list. For the few suppliers that matter most, establish whether their contracts flow the same notification and security obligations down to their own dependencies.
How do you record an accepted risk so the acceptance holds up?
Accepting risk is a legitimate board activity and frequently the correct one, and the business judgment protection in section 180(2) is built for exactly that kind of decision. What it cannot protect is a risk tolerated for years without ever being decided, which is what an unpatched legacy system usually is. The difference between the two is entirely a matter of record, and a defensible acceptance record contains six things.
The board does not need to see every acceptance. It needs a threshold above which an acceptance comes to the board rather than being recorded below it, the full population at least annually so it can see whether the number is growing, and a standing report of acceptances that have passed their expiry date without review. A growing population with lengthening expiry dates is an early signal that security work has lost its funding argument, and it appears in the register long before it appears in an incident.
- The risk stated as a business consequence rather than a control deficiency. An application that cannot support multi-factor authentication is a control deficiency; the consequence worth recording is that one stolen credential on it exposes a named data set and triggers a notification assessment.
- The options considered and rejected, with the reason, including what the alternative would have cost in money or delivery time.
- The compensating controls actually in place, and the name of the person who checks they are still operating.
- The residual risk and whether it sits inside a risk appetite the board has already set. Where no appetite exists for that class of risk, the missing appetite is the finding rather than the acceptance.
- A named accepting officer whose authority is proportionate to the exposure. A risk capable of halting the business or triggering mass notification is not accepted by a manager.
- An expiry date and the event that would force an earlier review, because acceptances without either become permanent through neglect and read to a reviewer as an abandoned control that was later written up.
Reporting cadence, ownership, and the two statutory clocks
Cadence turns the duty into a routine that produces evidence without anyone having to remember to produce it. The pattern below suits an organisation without a dedicated risk committee; where one exists, the material goes there first and the board receives the committee's report together with the questions the committee asked. What matters in either shape is that every row has a producer, a fixed period, and a record showing what the board did with it.
The ownership rule underneath the table is separation. The person accountable for delivering the controls should not be the only person reporting on whether they work, because that leaves the board with a single source it has no way to test. In a smaller organisation one person will hold both jobs, and the fix is a periodic independent test that gives the board a second source rather than a second appointment. That test is also the competence evidence which reliance under section 189 quietly assumes somebody holds.
Two statutory clocks need named owners before an incident rather than during one. Under the Notifiable Data Breaches scheme somebody has to own the assessment of a suspected eligible data breach within 30 days and the decision to notify the Office of the Australian Information Commissioner and affected individuals. Under the Cyber Security Act 2024 (Cth), a business above the turnover threshold set in the rules, or an entity responsible for a critical infrastructure asset, has to report a ransomware or cyber extortion payment to the Commonwealth within 72 hours of making it or becoming aware it was made, so the decision to pay carries a reporting obligation attached to it.
A board that has not settled who authorises a payment, who files that report and who signs the notification statements will be deciding all three at speed while the organisation is degraded. Those decisions attract the closest attention afterwards, because they are dated, they are recorded elsewhere by somebody else, and the timing is checkable. Settling the ownership takes one agenda item in a quiet quarter.
| Cadence | What the board sees | Who produces it | What the record must show |
|---|---|---|---|
| Between meetings | Any incident meeting the board escalation threshold, and any breach or extended outage at a critical supplier | Incident owner, through the chair | The time the board was told, measured against the time the organisation knew |
| Each ordinary meeting | Position against the named benchmark, movement on the gap list, the agreed measures, and new or closed risk acceptances | Risk owner with the security lead | Questions asked, answers given, and decisions carrying an owner and a date |
| Half-yearly | Independent test results and remediation status, plus evidence of a successful restore from backup | Independent assessor or tester | That the tester was independent of the team that built the controls |
| Annually | Refreshed risk assessment, incident exercise including the board's own role, full acceptance population, supplier assurance review | Risk function, with the board in the exercise | Board attendance at the exercise and what was changed as a result |
| On event | A material incident, an acquisition, a new product holding a new class of data, a regulator or insurer question, a peer incident in the sector | Accountable executive with the security lead | The inquiry the circumstances called for, and what it found |
Cyber reporting cadence: what the board sees, who produces it, and what the record has to show
Where the evidence actually comes from
Everything above depends on artefacts somebody has to produce, and most of the gaps we find are gaps in production rather than in intent. Sustaining the reporting line is what organisations without a full-time security executive struggle with, and it is the substance of a vCISO engagement: the benchmark position, the gap list with movement, the acceptance register, and a pack that answers the questions in the first table. The independent second source has to come from work the delivery team does not control, usually a penetration test scoped against what the business cares about, an Essential Eight assessment against the maturity model, a review of the identity configuration in Entra ID, or a secure code review of the systems holding the data.
The other half of the problem is whether the systems producing the record can be trusted to produce it accurately. The operations and compliance portal we built for GRM LAW, a Brisbane law firm, carries intake, conflicts checks, a matter register and AML/CTF readiness over an append-only audit ledger. The staff portal we built for Stone Leaf Capital, an Australian capital-markets firm, carries critical-event tracking and policy modules over a compliance audit log capturing actor, action, and before and after state. A board relying on a report is relying on the system that generated it, and that dependency deserves one question a year.
For a board that has not done this work, the first move is smaller than it looks. Table the seven questions from the first table at the next meeting, record the answers that exist, and record the ones that do not. The gaps become the work programme and the minutes become evidence that the board applied itself, and both exist before anybody outside the organisation asks to see them. Our approach and trust pages set out how we work and what we will show about our own posture.
