Overview

The threat of cyber-attacks is always present. The rapid and widespread adoption of artificial intelligence (AI) requires organisations to reassess the cyber risks they face. The tools available to bad actors are becoming more sophisticated and capable.1

Cybersecurity risk is not only the responsibility of an organisation's IT function, but a central governance concern for the board.2 The high profile data breaches of recent years highlight the significant regulatory and reputational risks that organisations face.3

For critical infrastructure owners and operators and other large organisations, the law increasingly requires boards to ensure cyber and information security risks are identified, managed, and escalated.

Failure to do so can have significant consequences. The recent case of Australian Securities and Investments Commission v Bekier (Liability Judgment) [2026] FCA 196 (ASIC v Bekier) highlights the potential liability that senior executives and board members may have if they fail to discharge their duties. It provides a valuable reminder of the consequences of failing to do so.

Boards need to understand where their obligations sit, whether their cyber risk management programs are compliant and how cyber incidents are treated under the regulatory frameworks under which they operate.

The legal framework

The Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act) provides a framework for managing risks relating to critical infrastructure assets (CI Assets).4 It requires responsible entities5 for CI Assets to take positive steps to manage those risks as well as to comply with obligations in response to serious incidents when those risks are realised.

At the core of the positive obligations is a requirement to adopt, maintain and comply with a Critical Infrastructure Risk Management Program (CIRMP).6 The purpose of the CIRMP is to:

  1. Identify hazards where there is a material risk that the occurrence of that hazard could have a relevant impact on any of its CI Assets;
  2. Minimise or eliminate any material risk of such hazards occurring, where it is practicable to do so;
  3. Mitigate the relevant impact of such hazard, where it is practicable to do so; and
  4. Establish and maintain a process or system in its CIRMP to comply with a framework such as ISO 27001, Essential Eight or another equivalent framework.

In response to a recent review into the SOCI Act, the Government released an exposure draft of the CIRMP Rules for public consultation. The exposure draft proposes to introduce enhancements to the CIRMP requirements applicable to specific categories of CI Assets.7 These new requirements, if adopted, will require responsible entities in certain industries to adopt more mature cyber and security information frameworks and to introduce more robust cybersecurity measures, such as multi-factor authentication.

The SOCI Act also imposes mandatory reporting obligations in the event of a cybersecurity incident. These require responsible entities to report to the Australian Signals Directorate's Australian Cyber Security Centre within 12 hours or 72 hours depending on whether the incident has had, or is having, a significant impact or a relevant impact on a CI Asset. The short timeframes require a responsible entity to have established policies and procedures in place to gather the information and make appropriate assessments to meet these timeframes.

Responsible entities also may be subject to non-critical infrastructure specific regulatory obligations that imposes obligations around managing cyber risk including:

  1. Cyber Security Act 2024 (Cth) – imposing mandatory security standards to be implemented into consumer grade smart devices connected to the internet and obligations to report ransomware and cyber extortion payments;
  2. Privacy Act 1988 (Cth) – requiring APP entities to take reasonable steps to protect the personal information that they hold from misuse, interference and loss as well as unauthorised access, modification or disclosure and to destroy or de-identify such information when it is no longer required.8 Those reasonable steps include technical and organisational measures;9 and
  3. APRA Prudential Standards CPS 230 and 234 – requiring an organisational approach to the identification and management of operational and information security risks, which place the ultimate responsibility for management and oversight on the board and senior management. While it is only APRA regulated entities that are required to comply with these standards, they do provide a useful guide to other non-regulated entities as to a best practice approach to managing operational and information risk.

The board must approve a responsible entity's annual report

Where a responsible entity is required to maintain a CIRMP, it is required to submit an annual report to the regulator.10 This requires the responsible entity to report a number of matters regarding its CIRMP including:

While the failure to meet the requirements of the annual report falls on the responsible entity11, the board will need to discharge its duties to the responsible entity when approving the annual statement.

Why should directors and officers pay attention?

The duties of directors and officers are well established. The case of ASIC v Bekier is a timely reminder that Australia's regulatory environment can expose directors and officers to personal liability where those duties are not met.

This case arose from proceedings that ASIC brought against the directors of The Star Entertainment Group Limited (Star) alleging breaches of section 180(1) of the Corporations Act 2001 (Cth) (the Corporations Act). ASIC alleged they failed to exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would have exercised if they were a director or officer of Star in Star's circumstances.12

While this case is primarily concerned with anti-money laundering, it has broader significance. It provides useful guidance on governance, risk management and compliance oversight in heavily regulated businesses, including critical infrastructure operators and other organisations facing evolving statutory obligations.

Lee J's judgment highlights that:13

  1. directors must take reasonable steps to place themselves in a position to guide and monitor management;14
  2. directors may generally rely on management and other officers, unless they know or ought to know that such reliance is misplaced;15
  3. the duty of care and diligence does not require perfection — an error alone will not establish breach;16
  4. directors appointed for particular expertise must still engage with the company’s affairs more broadly;17
  5. directors must understand the fundamentals of the company’s business, operations and financial position;18
  6. the increasing volume of material provided to boards and the limited time allowed to review them does not excuse a director from its cores responsibility to analyse and understand the information provided to them;19
  7. AI may be a valuable governance tool to assist directors, provided that its use is considered, deployed and managed responsibly with full consideration of the potential risks that it poses. However, such use does not relieve a director from its core responsibility to take reasonable steps to guide and monitor the management of the company;20 and
  8. the business judgment rule is only available where a decision has actually been made — not where a director has failed to turn their mind to the issue.21

The judgment also confirms that, in assessing a possible breach of section 180(1), the Court considers what a reasonable person with the same responsibilities and knowledge would have done in the circumstances. That assessment involves balancing the foreseeable risk of harm to the company against the expected benefits of the conduct, as well as the cost, difficulty and inconvenience of taking the alternative course. Importantly, this is not confined to financial consequences, but extends to all of the corporation’s interests.22

The case is a reminder to in house counsel who are also appointed as the company secretary that they are officers of the company and subject to the same duties as other officers.

The Court ultimately found that the former managing director, Mr Bekier, and former general counsel and company secretary, Ms Martin, contravened their duty to exercise care and diligence as required by section 180(1), but that ASIC had not established that the non-executive directors similarly did so.

The Court's findings regarding the non-executive directors are limited to the specific facts and the scope of ASIC's pleading and should not be taken as a general statement about the nature of the duties owed by non-executive directors as compared to executive directors. The assessment as to whether a director has taken reasonable steps to guide and monitor the management of the company in each case depends on the context and the fact that a director is a non-executive director is but one factor.23

Practical tips for directors and officers

For directors and officers of companies that operate in complex regulatory environments, such as those that own or operate critical infrastructure, the requirement to take reasonable steps to place themselves in a position to guide and monitor the management of a company requires them to be aware of the regulatory environment in which their companies operate.

Critically assess the information that is provided to you

Directors need to critically assess the information that they are provided to satisfy themselves that management understands and manages the relevant risks.

While a director is entitled to rely on the information provided by management, a director needs to bring their own expertise and knowledge to the role and interrogate such information where the information provided raises concerns or questions for the director.

Control the information you receive

The volume of board papers and the limited time allowed to review them is not an excuse for directors not fully informing themselves of the content of the board papers.

Directors are entitled to set expectations about the form and timeliness of board papers, and they should do so.

Use of AI to digest information

Boards need to properly assess any use of AI tools by directors and ensure the tools are configured appropriately for the information that management provides, being always mindful of any obligations of confidentiality. The expectations for use of such tools should be articulated in a policy.

Executive officers must escalate issues for board consideration where appropriate – general counsel take note

Once a person is subject to directors' duties, they attach to all aspects of their role. It is not appropriate to distinguish between an officer's duties and responsibilities in their role as a general counsel as distinct from that as company secretary.24

The duty to exercise care and diligence under section 180(1) attaches to a person with the roles and responsibilities that they hold in the corporation.

If a person becomes aware of an issue that raises serious legislative issues for the company or causes reputational harm, it is important that the issue be escalated to the board for proper consideration. In ASIC v Bekier, both the managing director and general counsel were found to have failed to do so.

Exercise reasonable care to avoid a breach of a law by the company

It is important to note that even where the breach does not include personal liability on a director, the fact that a director could have taken reasonable steps to avoid the breach, but failed to do so could result in a contravention of section 180(1) and thereby attract personal liability.25

Keep records of matters discussed and key decisions made (or not made)

To attract the protection of the business judgment rule, a judgment must be made. This is particularly important if a decision is made to not do something. It is therefore important for a director to engage with and decide an issue and for the board to keep a record in the minutes to show that a course of action was discussed and that a decision was made even if it was decided to take no action.

The potential liability on directors and officers for breach of their duties can be significant. ASIC v Bekier highlights that this can occur due to failures in governance oversight regardless of intent. The Court ordered Mr Bekier to pay a $700,000 pecuniary penalty and disqualified him from managing corporations for six year and Ms Martin to pay $400,000 with a seven year disqualification.26

For more information or assistance on your organisation's cybersecurity obligations, directors' duties or other governance considerations, contact our Cybersecurity team.

References


1 The risks posed by quantum computing advances are accelerating and cannot be understated. See Post-quantum cryptography: It’s already happening: Is your organisation ready?

2 Official Australian guidance treats cybersecurity risk as an enterprise-wide governance and resilience issue, not merely an IT function. ASIC, APRA and the ACSC all emphasise that boards and senior management must oversee cyber risk, information security capability, incident preparedness and organisational resilience. See for example, Australian Signals Directorate, 'Cyber security priorities for boards in 2025-2026", first published 30 October 2025, accessed 7 June 2026 < https://www.cyber.gov.au/sites/default/files/2025-10/cyber-security-priorities-for-boards-of-directors-2025-26.pdf>.

3 The education platform Canvas suffered a cyber-attack this year impacting educational institutions around the world. In 2025, data breaches continued to impact major Australian organisations, including Sydney Tools (34 million) and Qantas (5.7 million). The implications are not limited to regulatory actions, but include remediation costs and reputational damage. See FIIG-uring out Section 912A – A judicial warning to financial services licensees who underinvest in managing cyber risk.

4 Critical infrastructure assets are assets in the following 11 sectors that meet the definitions under the SOCI Act: Communications; Financial services and markets; Data storage or processing; Defence industry​; Higher education and research; Energy; Food and grocery; Healthcare and medical; Space technology; Transport; Water and sewerage.

5 Responsible entities are specifically defined under section 12L of the SOCI Act for each critical infrastructure asset.

6 Part 2A of the SOCI Act

7 See Critical infrastructure security laws to be updated: What you need to know

8 See Privacy Act, Australian Privacy Principles 11.1 and 11.2

9 Ibid, APP 11.3

10 Section 30AG of the SOCI Act

11 A civil penalty of 150 penalty units applies

12 ASIC v Bekier at para 15.

13 Ibid, section H generally.

14 Ibid, at para 361

15 Ibid, para 363

16 Ibid, para 360

17 Ibid, para 364

18 Ibid, para 362

19 Ibid, para 395

20 Ibid, paras 394 and 396

21 Ibid, paras 419 - 421

22 Ibid, para 357

23 Ibid, para 375

24 ASIC v Bekier, paras 1523 - 1528

25 ASIC v Bekier, para 401

26 Australian Securities and Investments Commission v Bekier (Penalty Judgment) [2026] FCA 756 at paras 216 and 272