Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America and Asia-Pacific: 1,833 cases from 37 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
€1.48mTotal of monetary amounts
€1.48mLargest single case: FIIG Securities Limited
€1.48mMedian per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Federal Court of Australia (auf Antrag der Australian Securities and Investments Commission, ASIC) 1 case 100 % · €1.48m

What for?

by topic
  1. Security measures and risk management 1 case 100 % · €1.48m

Who?

by sector

All sectors

  1. Financial services and insurance 1 case 100 % · €1.48m

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20250–
Q4 20250–
Q1 20261€1.48m
Q2 20260–
Q3 20260–
Q4 20260–

1 case

9 Feb 2026 FIIG Securities LimitedFIIG Securities: 2.5 million AUD for inadequate cyber security ahead of data theft AustraliaSecurity measures and risk management €1.48m

The Federal Court of Australia, on application by the Australian Securities and Investments Commission (ASIC, Australia's corporate, markets and financial services regulator), imposed a penalty of 2.5 million AUD on the fixed-income specialist because between March 2019 and June 2023 it lacked adequate cyber security measures, resources and risk management systems – among other things, there was no multi-factor authentication for remote access, no regular penetration testing and no mandatory security awareness training. In a 2023 attack around 385 GB of confidential data were stolen and some 18,000 clients were notified; the court also ordered a compliance programme with an independent expert.

What organisations can take from it

For licensed financial services firms, cyber security is part of their licence obligations: basic measures such as MFA, patching, monitoring, training and a tested incident response plan must be funded and actually implemented.

Relevance to training and awareness

Cyber security basics: multi-factor authentication, patch management, security awareness training, tested incident response plan

Missing or inadequate training played a role in the decision.

Authority / court
Federal Court of Australia (auf Antrag der Australian Securities and Investments Commission, ASIC)
Area of law
Information security and cyber · Security measures and risk management
Legal basis
Corporations Act 2001 (Cth) s 912A(1)(a), (d) und (h) i. V. m. s 912A(5A)
Action
Fine
Status of proceedings
unknown
Sector
Financial services and insurance
Repeat case
no
Mitigating circumstances
Full cooperation, admissions and an agreed statement of facts; no previous contraventions; the known financial losses (remediation costs of around 1.5 million AUD) were largely borne by the company itself.
Published
9 Feb 2026

Original amount 2,500,000 AUD, converted at the ECB reference rate of 9 Feb 2026.

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial