← Articles
RIPOSTE research · 2026

Can a Director or Company Be Held Liable for Cyber Security Failures?

“Can a company — or its directors personally — actually be held liable for failures in cyber security?” It used to be a theoretical question. It is not any more. Australian regulators have moved from warning about cyber risk to litigating it, and the courts have begun to answer. This is a plain-language look at where the liability actually sits — for the company, and for the people who run it. It is not legal advice; where any of this bears on you, get some.

The short answer: yes — and the ground has shifted

Cyber security is no longer treated by regulators or courts as a purely technical matter that lives in the IT department. It is a governance obligation, and failing to manage it adequately can breach the law in at least two distinct ways: the corporate obligation to run the business with adequate risk management, and the privacy obligation to take reasonable steps to protect personal information. Both have now been tested in the Federal Court — and a director's own duty of care sits squarely over the top of them.

The landmark: ASIC v RI Advice (2022)

In May 2022 the Federal Court delivered the first Australian judgment to find that failing to manage cyber risk can itself breach the law. In ASIC v RI Advice Group Pty Ltd [2022] FCA 496, Justice Rofe held that RI Advice — a financial-services licensee — had breached its obligations under section 912A of the Corporations Act to provide its services “efficiently, honestly and fairly” and to maintain adequate risk-management systems, because its cyber-security documentation and controls were inadequate. Cyber risk, the Court found, is “a significant risk connected with the conduct of the business”; it cannot be reduced to zero, but it can and must be reduced “to an acceptable level” through adequate controls. RI Advice was ordered to engage a cyber-security expert and to pay $750,000 towards ASIC's costs.

The significance is not the sum. It is the principle: an Australian court has confirmed that inadequate cyber-security management is, in itself, a breach of a company's legal obligations — a headline data breach is not even required. The standard is adequacy, and it is judged after the fact.

It is not only financial licensees

RI Advice turned on obligations specific to financial-services licensees, but the reasoning travels. The expectation it crystallised — that a business must actively identify and manage cyber risk as a core operational risk — is being read across the economy, reinforced by regulator guidance and by the general law. Any organisation that holds data or depends on systems is now expected to treat cyber as a board-level risk, not an IT line item.

Directors personally: the duty of care now includes cyber

Beyond the company sits the director. Section 180 of the Corporations Act requires every director to exercise the care and diligence a reasonable person would in their position — and regulators have said, repeatedly and publicly, that this duty now extends to cyber-risk governance. The exposure is often described as “stepping-stone” liability: if a company contravenes the law through inadequate cyber management, a director who failed to exercise reasonable care over that risk may themselves be found to have breached section 180. No Australian court has yet imposed personal liability on a director specifically for a cyber failure — but the legal architecture for it is in place, and it is the direction regulators have signalled. Where the duty is breached, directors can face pecuniary penalties, disqualification and personal liability.

The practical consequence is that a director can no longer discharge the duty by leaving cyber to “the IT people.” Reasonable care now means understanding the organisation's material cyber risks, ensuring there are adequate systems and resourcing to manage them, and being able to show that the board turned its mind to it.

The privacy front: OAIC v Medibank (2024)

The second front is privacy law. In June 2024 the Australian Information Commissioner commenced civil penalty proceedings in the Federal Court against Medibank, alleging it failed to take reasonable steps to protect the personal information of 9.7 million Australians in breach of the Privacy Act — following the 2022 attack in which sensitive health records were stolen and leaked. The Privacy Act allows a civil penalty of up to $2.22 million for each contravention, and the Commissioner's case treats the exposure of each affected individual as a separate contravention, which is what makes the potential exposure so large. However it resolves, the message is unambiguous: “reasonable steps” is now something you may have to prove to a court.

What “adequate” and “reasonable” actually mean

Both standards — adequate risk management, reasonable steps — are deliberately not checklists. They are judged against what a reasonable organisation in your position would have done, in light of the sensitivity of your data and the threats you realistically face. That cuts both ways. There is no single certificate that makes you compliant; but the expectation is also proportionate — a small practice is not held to the standard of a bank. What matters is that you identified your real risks, took steps a reasonable person would consider adequate to them, and can demonstrate it.

What this means for boards and directors

The throughline is demonstrability. After an incident, the question will not be “were you unlucky?” but “can you show you took cyber risk seriously and managed it reasonably?” In practice that means treating cyber as a standing board risk, understanding your genuine exposure rather than assuming it, resourcing its management proportionately, and keeping a record that the organisation turned its mind to it. Good governance here is not only prudent — it is increasingly the difference between a defensible position and an indefensible one.

How RIPOSTE helps

We help organisations build exactly that defensible position: an honest, intelligence-led assessment of your real cyber risk, calibrated to the threats you actually face and set out in terms a board can act on and stand behind. That is the evidence that a reasonable, proportionate view was taken and reasonable steps were considered — the documented judgement regulators and courts now look for. We are not lawyers, and this article is not legal advice; where your obligations are in question, seek qualified advice. But when the question is whether you understood and managed your cyber risk, that is precisely what we exist to help you answer.

Sources

  1. ASIC media release 22-104MR — Court finds RI Advice failed to adequately manage cybersecurity risks
  2. ASIC v RI Advice Group Pty Ltd [2022] FCA 496 — Federal Court judgment (ASIC)
  3. Corporations Act 2001 (Cth) s 180 — care and diligence (AustLII)
  4. OAIC takes civil penalty action against Medibank (June 2024)
  5. Federal Court finds cyber risk management is a critical obligation — Allens
About the author

Cameron McCollum — Director & Founder, RIPOSTE. He spent two decades in Australian Army intelligence — serving as Head of Intelligence on operations across the Asia-Pacific and Afghanistan — before building and leading the cyber-risk program at Lexon Insurance. He holds Master's degrees in Cyber Security Operations and Business (UNSW) and is an ISO/IEC 27001 Lead Implementer.

RIPOSTE helps organisations turn analysis like this into action.

Talk to us