
When Noosa Shire Council lost $2.3 million to scammers, the blame initially fell on sophisticated, AI-driven social engineering.
A year later, the council’s own review admitted a different truth: it was actually caused by human error and ignored internal safety rules. As Councillor Amelia Lorentson bluntly put it, the money was lost because internal safeguards “were not followed”.
Following a near-identical $2.78 million scam at Gold Coast City Council, this shift highlights the real story for Australian leaders. AI tech makes attacks highly sophisticated, but regulators are now focusing heavily on whether business owners left known, preventable gaps wide open.
For Australian businesses, this turns cybersecurity from a distant IT problem into a question of personal executive liability. This blog walks through your legal duties under the Corporations Act, new compliance reporting rules, and what “reasonable governance” looks like in practice.
A Duty That Already Existed, Now Under New Pressure
Section 180 of the Corporations Act has required directors to exercise care and diligence for decades. ASIC confirmed a while back that this duty covers cyber resilience too, and the case that proved it, ASIC v RI Advice Group, ended with a financial services licensee found liable for failing to manage its cyber risk properly. It was Australia’s first ruling of its kind.
The lesson wasn’t subtle. Directors need to show they understood the risk and acted on it. A breach that never happened isn’t proof of good governance, it’s often just luck.
Noosa’s case fits that pattern well. Blaming an overseas syndicate sounds plausible, right up until an audit finds the controls needed to stop the fraud were already sitting on a shelf somewhere, unused. A payment approval process that exists in a policy document but not in daily practice offers no real protection, and auditors tend to know exactly where to look for that gap.
Australia’s Top Scam Losses in 2025
| Scam Type | Reported Losses | Trend |
|---|---|---|
| Investment scams | $837.7 million | Largest category overall |
| Payment redirection scams | $166.8 million | Up 9.3% on 2024 |
| Romance scams | $139.9 million | Third largest category |
| Phishing scams | $97.6 million | Fourth largest |
| Remote access scams | $69.9 million | Fifth largest category |
Source: ACCC National Anti-Scam Centre, Targeting Scams Report 2025
What the Law Now Requires
| Requirement | Applies To | Timeframe | Penalty |
|---|---|---|---|
| Ransomware payment reporting | Businesses with turnover of $3 million or more | Report to the ASD within 72 hours | Civil penalty up to $19,800 |
| Cybersecurity risk oversight | Directors under s180 Corporations Act 2001 | Ongoing, not incident based | Possible personal liability, civil penalties, or ASIC/regulatory action |
Note: The $19,800 figure reflects 60 penalty units. For companies, the maximum may be higher, potentially up to $99,000, due to the corporate penalty multiplier.
The Cyber Security Act 2024 brought in mandatory ransomware reporting, active since May 2025. From January 2026, the Department of Home Affairs stopped treating this as an education exercise. Miss the 72-hour window now and there’s a real penalty attached, not a phone call reminding you to do better.
Which is why director liability and cyber security have stopped being two separate conversations for Australian boards. ASIC expects directors to ask direct questions about incident response themselves, rather than handing the whole subject to whoever manages the servers and hoping it’s covered.
What Reasonable Governance Actually Looks Like
Nobody’s asking a director to configure a firewall personally, that’s not the point. What matters is being able to show reasonable steps were genuinely taken, not just written into a document nobody reopened.
Two controls from the Australian Signals Directorate’s Essential Eight do a lot of the heavy lifting here:
- Restricting administrative privileges, so a single stolen login can’t move money on its own.
- Multi factor authentication across finance systems and banking portals, closing the door a stolen password would otherwise walk through.
Cyber security compliance for small business isn’t something to look during a renewal season anymore. It’s fast becoming the benchmark insurers and regulators measure director conduct against, whether the business has twelve staff or twelve hundred.
A response plan nobody’s rehearsed tends to fall apart in the first hour of a real incident, right when everyone’s more worried about how it looks than what actually happened. Naming who calls the bank, who calls the ASD, and who briefs the board matters just as much as any firewall setting ever will.
Most businesses don’t have the internal bandwidth to run this kind of oversight alone, which is usually where a managed IT provider like TechEngine comes in, turning regulatory language into something that actually happens day to day rather than sitting in a policy binder.
The Price of Complacency
The Noosa and Gold Coast City Council cases are a warning the private sector shouldn’t shrug off. AI-driven fraud isn’t a hypothetical IT problem anymore, it’s an active test of how a business actually governs itself day to day.
If a government body with dedicated compliance teams can lose millions to a broken internal process, a private business can too, and there’s no taxpayer safety net waiting on the other side. When regulators come knocking, “we didn’t know” or “the AI was convincing” won’t hold up as a defence. Your legal duties under the Corporations Act put digital security on the same footing as financial auditing, whether you’ve thought about it that way or not.
The real test isn’t whether a business has a policy document somewhere with the right words in it. It’s whether the people using the finance system that day actually follow it. Tech Engine Australia, has seen that gap play out often enough that MFA enforcement and rehearsed incident response plans tend to separate the businesses that walk away from an attempted fraud from the ones that end up explaining themselves to a regulator.
After all, in the AI era, the ultimate vulnerability isn’t not the software but the oversight.
Sources
- Noosa Today, $1.9m Fraud Preventable, noosatoday.com.au
- Noosa Today, Call For More Details On Council Fraud, noosatoday.com.au
- Insurance Business Australia, AI-Powered Scam Leaves Councils Reeling, insurancebusinessmag.com.au
- Queensland Audit Office, Interim Audit Report, qao.qld.gov.au
- ASIC, Cyber Risk: Be Prepared, asic.gov.au
- Department of Home Affairs, Ransomware Payment Reporting Factsheet, homeaffairs.gov.au
- ACCC, Targeting Scams Report 2025, accc.gov.au
- Australian Signals Directorate, Essential Eight Maturity Model, cyber.gov.au
