ASIC v RI Advice: the Federal Court found that a licensee's inadequate cyber risk management breached its financial services licence obligations. Regulators now treat cyber risk management as a board-level responsibility.
Director Liability & Cyber Governance
Your board pack says green. ASIC doesn't care about your dashboard.
Directors' duties under section 180 of the Corporations Act require active, informed oversight, and cyber risk now sits squarely inside them. ASIC's action against RI Advice showed the regulator will pursue inadequate cyber risk management as a breach of licence obligations. The Cyber Security Act 2024 added mandatory ransomware payment reporting to the obligations a board must be able to evidence. Passive acceptance of management reporting is a weak position to defend.
The Systemic Problem
Green on the outside, red underneath.
The board sees compliance completion metrics: percentage complete. The attacker sees defensive capability gaps: percentage effective under attack. This gap exists because GRC frameworks measure control implementation, not independent stress testing.
| Control | Board Report Says | Actual Reality |
|---|---|---|
| Multi-factor authentication | Implemented, 100%, compliant | Token binding: none |
| Session invalidation | Audit status: compliant | Failing |
| Tested against token theft | Coverage target: 100% | Never |
The ASIC Litmus Test
"What specific questions did you ask to validate those assurances?"
A CISO reporting green across the board is not evidence. These metrics measure activity, not outcome. On the most critical risks, ransomware preparedness and SOCI compliance among them, a board relying only on the report may be flying blind.
Directors are entitled to rely on management, but only where that reliance is reasonable and informed. If an incident occurred today, the question would be whether your reliance on management's assurances was reasonable and informed. That is the standard section 180 applies, and the evidentiary record supporting it is built before the incident, not after.
Advisory Engagements
From exposure to governed assurance
Independent, unvarnished truth for the audit and risk committee.
01
The Shadow Board Pack Review
Fixed fee, scoped on the call
Send the last three board cyber reports. Vyfority annotates them: what is being hidden, what is watermelon reporting, and which critical risks are not being disclosed.
- · Annotated board reports (independent review)
- · Identification of vanity metrics
- · Personal two-page liability briefing for the director
02
Governance Framework Uplift
~$40,000 · Scoped project
A complete redesign of the board-level cyber governance architecture, moving from passive reporting to active, outcome-based oversight.
- · Revised board cyber charter
- · Updated risk appetite statement (tolerances)
- · Outcome-based board reporting
- · Director's due diligence framework
03
The Independent Board Advisor
$5,000–8,000 / mo · Retainer
Dean attends risk committee meetings as an independent cyber expert: translating technical reporting into governance language, asking the hard questions, and providing an independent opinion on management's assurances.
- · Risk committee attendance and advisory
- · Translation of technical metrics
- · Validation of management assurances
The Independent Board Advisor retainer is board-facing: it attends the risk committee, challenges management's assurances, and provides an independent opinion to directors. Vyfority's fractional cyber leadership retainer, Virtual CISO →, is management-facing: it owns the risk register, runs the program, and reports to the board. Different products, priced in a similar range; ask which one your organisation actually needs.
Board-Ready Resource
The Director's Cyber Governance Question Card
A printable, wallet-sized card with five hard questions a director should ask at the next board meeting to demonstrate cyber governance due diligence. Honest answers from management will reveal the true capability gaps.
Download the question card →Independent Cyber Lens
Book an advisory scoping briefing

Dean Kastelic
Former Enterprise CISO & KPMG Director
Dean operates as an independent cyber lens for mid-market boards across Australia, bridging the gap between technical security failure and director liability, and giving directors the evidentiary record required to demonstrate active, informed oversight.
"The next director facing enforcement will not be able to point to green dashboards as a defence. We build the record of oversight before the incident occurs."
Or send the brief directly
General governance information for directors, not legal advice. Directors should seek their own counsel on how these duties apply to their circumstances.