Skip to content

Compliance

Directors on the Hook for Cyber: What the Section 180 Position Actually Is in 2024

Cyber risk is now inside a director's duty of care under section 180. What that asks of a board at a 20 to 250 staff Australian company in 2024.

8 min read
Jump to section
  1. 01 Does ASIC treat cyber risk as the board’s problem?
  2. 02 What stepping-stone liability means for cyber risk
  3. 03 What “reasonable steps” looks like in a mid-size company
  4. 04 When personal exposure is highest for a director
  5. 05 What changed between 2022 and 2024?
  6. 06 What CCP does on director-level cyber governance
  7. 07 Primary sources

This is an IT operator’s view of how cyber risk management meets directors’ duties under the Corporations Act in 2024. It isn’t legal advice, a directors-duties opinion, or a position statement from the Australian Securities and Investments Commission (ASIC). Whether any particular governance arrangement satisfies section 180 in a specific circumstance is your corporate lawyer’s call. We implement the technical controls the board has decided on. The lawyer advises whether that decision discharges the directors’ duty.

Two and a bit years after the Federal Court decided ASIC v RI Advice, the position is settled. Cyber risk is now squarely inside the duty of care that directors owe under section 180 of the Corporations Act. ASIC has said so publicly on multiple occasions since. If you run an Australian company of 20 to 250 staff, unlisted, with the founders or a small board doing governance, that exposure is yours. It is a risk class that was not in your mental model five years ago.

The exposure is real, the standard is reasonable, and the controls required to discharge it are not exotic. But across incident work and board conversations, we see directors find out about their exposure after the fact. An insurer’s questionnaire finds the gap, or a near-miss breach makes someone ask who was supposed to be watching. By then, the board is answering whether it did enough after the event. That is a much harder question than asking it in advance.

Does ASIC treat cyber risk as the board’s problem?

Yes. ASIC has stated publicly since 2022 that cyber risk management is a top priority for all boards, and it has backed the position with enforcement. In 2022, the ASIC v RI Advice decision found an Australian Financial Services Licence (AFSL) holder in breach of the Corporations Act for cybersecurity-related failures. It was the first Australian case to do so. Through 2023 and 2024, ASIC has kept signalling that it will use the stepping-stone approach. That approach applies a company’s cyber failure to directors’ section 180 obligations, where the facts warrant.

The position is not that directors have to be cyber experts. They have to give cyber risk the same care and diligence they give any other material operational risk. The Corporations Act test under section 180 is objective; a director is held to the standard of a reasonable person in the same position. A reasonable director now understands that cyber risk is a material risk. That applies to any company that handles personal information, or that depends on IT systems to operate. It also means taking reasonable steps to make sure the risk is being managed.

What “reasonable steps” means depends on the size and complexity of the business. A firm of 20 to 250 staff does not need a separate risk-management department. It needs controls that actually work, oversight at board level, and a direct conversation about where the gaps are.

What stepping-stone liability means for cyber risk

Stepping-stone liability is an enforcement approach ASIC has used in other contexts, including financial services breaches and continuous disclosure failures. The company’s contravention of the Corporations Act is the first step. The director’s failure to prevent or address it is the second. Directors breach the section 180 duty when they expose the company to a foreseeable risk of harm. That happens when they fail to act with the care and diligence a reasonable director would.

Applied to cyber, the logic goes like this. The company fails to manage a cyber risk. A consequence follows: a breach, a regulatory investigation, a prosecution, a class action, or reputation damage. The director who had the opportunity and capacity to prevent that consequence is then in breach of section 180. The harm does not have to be financial. Reputational damage, prosecution exposure, and civil litigation all count.

So a cyber incident at the company level can become a directors’ duty issue. That can happen even where the directors did nothing wrong actively, if the failure was to ensure adequate oversight. That is harder to defend than a conscious decision that turned out badly.

What ASIC expects directors to actually do

ASIC has not published a prescriptive list. It has published indicative guidance, and Information Sheet 259 on cyber resilience is the one most cited here. It has repeatedly referenced the Australian Institute of Company Directors (AICD) Cyber Security Governance Principles as a reasonable baseline for board-level cyber governance. The AICD principles are not law but they are what ASIC would reasonably expect a well-informed director to have read.

The indicative expectation is roughly this. A board:

  • Understands the cyber risks that are material to the business.
  • Assigns management accountability for those risks.
  • Receives regular reporting, and challenges it.
  • Resources the work adequately.
  • Ensures an incident response plan exists and has been tested.

None of this requires directors to become technical experts. It requires directors to apply governance discipline to cyber the same way they apply it to financial controls or workplace safety.

What “reasonable steps” looks like in a mid-size company

For a company of 20 to 250 staff, a defensible board-level cyber governance posture in 2024 looks roughly like this.

  • One named senior executive who owns cyber risk: the CEO, the COO, or a delegated officer.
  • A current cyber risk register, reviewed at least semi-annually at a board or audit-committee meeting.
  • Baseline controls covering the Essential Eight, the Australian Cyber Security Centre’s canonical control set, or a credible equivalent.
  • A documented incident-response plan, tested within the last 12 months.
  • Cyber insurance in force with an insurer that asked real diligence questions before writing the policy.
  • An external perspective at least annually, from a managed service provider, a consultancy, or an internal audit function.

Most of the work is in the first two items. A business that knows its material cyber risks, and has assigned accountability for each one, tends to close the rest of the gap naturally. Where neither has ever been written down, the rest of the conversation is hard to hold together.

What if we outsource IT entirely?

Outsourcing IT does not discharge the directors’ duty. ASIC has been explicit that third-party risk (including outsourced IT providers) falls within directors’ cyber oversight obligations. The board still needs three answers. What is the provider contractually responsible for? Where are the gaps between that contract and the real risk? And how does the board know the provider is doing what it said it would? We have been on both sides of that conversation. The provider who can produce evidence on demand is the one that holds up to scrutiny.

The trap we see starts with a cyber insurance questionnaire asking the directors to attest to controls. The board turns to the managed service provider to answer it. The provider returns evidence that is generic rather than specific to that company. The attestation is the director’s, not the provider’s. A provider that cannot produce company-specific evidence leaves the director exposed.

When personal exposure is highest for a director

Across incident work and board conversations, we see personal exposure show up in three predictable situations. First, after a serious breach, when the post-incident review finds the board’s cyber oversight was thin or nominal. The breach itself is the company’s problem; the board’s role in letting it happen becomes the director’s problem. Second, when a cyber insurance claim is declined because the insured did not have the controls attested to in the application. The director signed that application. Third, when ASIC is conducting a broader investigation for unrelated reasons and finds cyber governance gaps as a secondary issue.

A standing cyber governance posture reduces exposure across all three. A reactive posture heightens it.

What changed between 2022 and 2024?

Three things. ASIC’s enforcement posture has firmed up. It has moved from “we will pay attention to cyber” to “we are actively looking for cases to run”.

The Albanese government’s cybersecurity strategy (2023) and the Cyber Security Legislative Package currently before Parliament (expected to pass later in 2024) signal a broader regulatory posture. It treats cyber as a first-class compliance area rather than an IT concern.

Cyber insurance underwriting has also tightened dramatically. Questionnaires now look more like regulatory diligence than insurance forms.

So a board that was comfortable with its cyber posture in 2021 should not assume that same posture is defensible in 2024. The bar has moved. Directors who haven’t asked what changed since the RI Advice decision are probably underestimating the current expectation.

What CCP does on director-level cyber governance

We don’t write board papers. We make sure the IT environment behind the governance posture can actually back up what the board is being told.

For a client with an engaged board, our part is usually the evidence. We produce what management reports up from.

  • A current risk register against the Essential Eight.
  • Evidence that the incident-response plan has been tested, with the test written up.
  • Patching and identity metrics management can present to the board without fabrication.
  • Outputs shaped like a report, so a director is not reading raw technical data.

Where the board has questions management cannot answer credibly from inside, we come into the room and answer them.

The director-duties interpretation, the board-paper drafting, the decisions about what gets escalated when, remain with the company’s legal advisors, company secretary, and chair. Our boundary is explicit. We provide the evidence. They make the governance judgement.

If you want to understand your actual exposure without committing to an engagement, start with our Essential Eight self-assessment. It produces a written report suitable for a first board conversation. That conversation is usually worth having before the insurer’s questionnaire arrives, not after.

Primary sources

Tags compliancedirector-dutiessection-180asiccyber-governance
Share LinkedIn Email
See if we're a fit