Australian Securities and Investments Commission lawyers pressed Fortnum Private Wealth in the New South Wales Supreme Court this week over alleged gaps in cyber security governance across its authorised-representative network, in a case that tests how financial services licensees must supervise hundreds of third-party advisers. The hearing follows ASIC’s May open letter demanding urgent cyber uplift as generative artificial intelligence accelerates phishing and fraud.

What ASIC alleges

ASIC filed the civil suit in July 2025, alleging Fortnum failed to maintain adequate policies, frameworks and controls to manage cyber risk across its AR network. The regulator contends Fortnum did not require minimum cyber training for ARs, did not adequately monitor their risk frameworks, lacked in-house cyber specialists and operated without a group-wide risk system that identified and escalated incidents. Court listings show a hearing on 2 October 2026 after multiple timetable shifts.

Riley Paterson, security correspondent for InfoHandle, said the case matters because many mid-tier licensees rely on AR models to scale advice while centralising compliance only on paper. ASIC’s concise statement argues Fortnum exposed clients to unacceptable harm risk even after issuing a cyber policy in 2021 that was not updated until May 2023 without interim controls.

Broader enforcement context

ASIC won a $2.5 million penalty against FIIG Securities earlier in 2026 for cyber failures spanning more than four years, with orders for an independent compliance programme. That judgment is now cited in regulator letters telling Australian financial services licensees that cyber resilience is a core licensing obligation, not an IT side project. Commissioner Simone Constant’s May letter urged prompt patching, tested incident-response plans and board-level assurance as AI lowers the bar for attackers.

Why AR networks are in focus

Authorised representatives often maintain their own email systems, laptops and file shares while trading on a licensee’s Australian financial services licence. A phishing compromise at a suburban practice can spill client identity documents and statement downloads into criminal marketplaces. ASIC alleges Fortnum could not demonstrate consistent supervision or escalation paths when ARs faced suspicious activity.

Fortnum has not publicly detailed its defence; licensees typically argue they took reasonable steps proportional to risk. The court will decide whether policies on paper satisfied sections 912A of the Corporations Act requiring efficiency, honesty and adequate resources.

Practical impact for advice firms

Compliance consultants reported a rush of gap assessments after the FIIG outcome. Licensees are mapping which ARs host client data offshore, whether multi-factor authentication is mandatory, and how quickly patches deploy on ageing Windows estates still common in small practices.

ASIC encourages use of the government’s free Cyber Health Check and Australian Signals Directorate alerts. For Fortnum-sized networks, the cost of centralised security operations centres may be lower than court-ordered remediation plus reputational damage.

AI-enabled threats

Regulators warn that generative tools fake invoices, voice clones and fraudulent licence claims targeting consumers. Licensees must defend both client-facing channels and adviser desktops. ASIC’s open letter says frontier AI does not change fundamentals—patching, backups and tested playbooks—but speeds exploitation.

What happens next

Depending on the hearing outcome, the court could impose declarations, penalties or mandated programmes similar to FIIG. Even a settled case would signal expectations for AR oversight. Advice executives should read the Fortnum concise statement as a checklist: training minima, specialist expertise, monitoring and incident escalation are no longer optional extras.

Client takeaway

Investors should verify adviser firms on ASIC’s Financial Advisers Register and ask how cyber incidents are reported. Friday’s proceedings remind the industry that scaling advice through AR networks without scaling security is a licensing risk the regulator will litigate, not just lecture about.