
Australia set out an ambitious cyber security vision in 2023. Three years on, State and Federal regulators continue to find significant cyber security failings.
A proposed $8 million penalty against Bendigo Bank by the Australian Prudential Regulation Authority (APRA) last week was a landmark enforcement under the Banking Executive Accountability Regime (BEAR) for cyber and risk governance failures.
But it was not the first cyber-related regulatory penalty in Australia.
In February this year, the Australian Securities and Investments Commission (ASIC) took FIIG Securities Limited (FIIG) to the Federal Court which imposed a $2.5 million penalty for failing to maintain adequate cybersecurity measures.
This marked the first time penalties were awarded under the general Australian financial services (AFS) licence obligations for cybersecurity deficiencies when threat actors gained access to FIIG's network and exfiltrated approximately 385 gigabytes of data, some of which was later published on the dark web.
"a penalty of $2,500,000 will validate the behaviour and efforts of compliant businesses, and will send a warning to businesses with inappropriate underinvestment in cybersecurity"
Honourable Justice Derrington, Federal Court of Australia
The stolen data included sensitive personal information such as details of driver's licences, passports and Medicare cards, Tax File Numbers and bank account details.
The penalty represented around 20% of FIIG’s net assets and 8% of its annual turnover and was intended by the judge to act as "a warning to businesses with inappropriate underinvestment in cybersecurity."
Back in Novemebr 2025, the Federal Court delivered another first for cyber penalties in the judgement on Australian Information Commissioner v Australian Clinical Labs Limited.
As the first civil penalty imposed under the Privacy Act (AUD $5.8 million) for cybersecurity failure, it's important to note that the decision was handed down under the prior Aussie privacy regime. Since reforms in 2022, the maximum for organisations is now the greater of AUD $50 million, 3x the benefit, or 30% of adjusted turnover.
And it's not just financial sector organisations that are being taken to task.
The Auditor-General for NSW, Bola Oyetunji, has tabled in Parliament a report that analyses the internal controls and governance arrangements of 26 of the State's largest Government agencies.
Less than half of agencies reported compliance with requirements to protect and govern their risk exposure. And some agencies did not assess risks from legacy systems that cannot be patched, increasing their exposure to cyber-attack.
Of the 71 reporting agencies, 33 reported 128 cyber security risks with a significant, high and extreme residual risk that could impact on a critical agency function, or entire agency operations.
"By 2030, Australia will be a world leader in cyber security. We envisage a future where stronger cyber protections enable our citizens and businesses to prosper, and to bounce back quickly following a cyber attack."
Clare O'Neil, Minister for Home Affairs and Cyber Security - 22 November 2023
The 2023–2030 Australian Cyber Security Strategy set out six cyber shields under which the Australian Government would seek to improve cyber security, manage cyber risks and better support citizens and businesses:

Each shield was to provide an additional layer of defence against cyber threats with Australian citizens and businesses at the core:
The Australian Government committed AUD $586.9 million to the Cyber Security Strategy out to 2030:
Just this year, $26.2 million was invested to establish Cyber Rapid Assistance for Pacific Incidents and Disasters (Cyber RAPID) teams led by the Department of Foreign Affairs and Trade and other partnerships with Southeast Asian nations.
“We know that cyber attacks are constant. This guarantees we learn from every attack and keep increasing our resilience"
Tony Burke, Minister for Cyber Security
And in May, the Albanese Government established under the Cyber Security Act 2024, a Cyber Incident Review Board.
Modeled on the now-defunct U.S. Cyber Safety Review Board (CSRB), this public–private body will conduct no-fault, post-incident reviews of significant cybersecurity incidents, extract actionable lessons and strengthen national resilience.

The question Australians should now be asking is surely "is the Strategy working?"
Despite a commitment to invest more than half a billion dollars, the NSW report found that legacy technology and limited resources left cyber risk remediation plan implementation timeframes being set out in months to years.
Full compliance with the NSW Cyber Security Policy is at least four years away for some agencies and only 33% of agencies complied with mandatory requirements in the protect domain, designed to prevent future cyber security incidents.
It's a startling reminder that having a vision and achieving it, may take more money, time and effort than originally planned for.