---
title: "Can Directors Be Personally Liable for a Cyber Breach? | StartCloud"
description: "ASIC treats cyber resilience as a directors' duty. How section 180 and stepping-stone liability can reach directors personally for a cyber breach, and what boards should do."
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": [
        "LocalBusiness",
        "ProfessionalService"
      ],
      "@id": "https://startcloud.au/#business",
      "name": "StartCloud",
      "legalName": "Start Technologies Pty Ltd",
      "alternateName": "StartCloud Australia",
      "identifier": {
        "@type": "PropertyValue",
        "propertyID": "ABN",
        "value": "17 676 121 449"
      },
      "slogan": "Go Beyond",
      "description": "StartCloud is Perth's cybersecurity-first AI MSP: managed IT, Essential Eight security, Microsoft 365 and cloud, networking, and practical AI for Australian businesses with 5 to 50 staff.",
      "url": "https://startcloud.au",
      "logo": "https://startcloud.au/og-image.png",
      "image": "https://startcloud.au/og-image.png",
      "telephone": "+61862850001",
      "email": "web@startcloud.com.au",
      "priceRange": "$$",
      "currenciesAccepted": "AUD",
      "paymentAccepted": "Invoice",
      "foundingDate": "2023",
      "contactPoint": {
        "@type": "ContactPoint",
        "telephone": "+61862850001",
        "contactType": "customer service",
        "areaServed": "AU",
        "availableLanguage": "English"
      },
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "Ground Floor West, 6 Gibberd Road",
        "addressLocality": "Balcatta",
        "addressRegion": "WA",
        "postalCode": "6021",
        "addressCountry": "AU"
      },
      "geo": {
        "@type": "GeoCoordinates",
        "latitude": -31.8648813,
        "longitude": 115.8095638
      },
      "openingHoursSpecification": [
        {
          "@type": "OpeningHoursSpecification",
          "dayOfWeek": [
            "Monday",
            "Tuesday",
            "Wednesday",
            "Thursday",
            "Friday"
          ],
          "opens": "07:00",
          "closes": "16:30",
          "description": "General support hours"
        },
        {
          "@type": "OpeningHoursSpecification",
          "dayOfWeek": [
            "Monday",
            "Tuesday",
            "Wednesday",
            "Thursday",
            "Friday",
            "Saturday",
            "Sunday"
          ],
          "opens": "00:00",
          "closes": "23:59",
          "description": "Security Operations Centre (SOC) with 24/7/365 threat monitoring"
        }
      ],
      "areaServed": [
        {
          "@type": "City",
          "name": "Perth"
        },
        {
          "@type": "State",
          "name": "Western Australia"
        },
        {
          "@type": "Country",
          "name": "Australia"
        }
      ],
      "serviceArea": {
        "@type": "GeoCircle",
        "geoMidpoint": {
          "@type": "GeoCoordinates",
          "latitude": -31.8648813,
          "longitude": 115.8095638
        },
        "geoRadius": "50000"
      },
      "knowsAbout": [
        "Cybersecurity",
        "Managed Security Services",
        "Essential Eight",
        "Microsoft 365",
        "Microsoft Azure",
        "IT Support",
        "Network Security",
        "Disaster Recovery",
        "Compliance Management",
        "Microsoft Copilot",
        "AI Readiness",
        "AI Governance",
        "AI Agent Development"
      ],
      "hasOfferCatalog": {
        "@type": "OfferCatalog",
        "name": "IT and Cybersecurity Services",
        "itemListElement": [
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Cybersecurity Services",
              "url": "https://startcloud.au/cybersecurity"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Managed IT Services and Support",
              "url": "https://startcloud.au/technology"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Microsoft 365 and Cloud Solutions",
              "url": "https://startcloud.au/cloud"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "Managed Networking",
              "url": "https://startcloud.au/networking"
            }
          },
          {
            "@type": "Offer",
            "itemOffered": {
              "@type": "Service",
              "name": "AI and Automation",
              "url": "https://startcloud.au/ai"
            }
          }
        ]
      },
      "sameAs": [
        "https://www.linkedin.com/company/startcloudau",
        "https://www.facebook.com/startcloudaus/",
        "https://www.cloudtango.net/providers/12375/startcloud",
        "https://clutch.co/profile/startcloud",
        "https://abr.business.gov.au/ABN/View?abn=17676121449",
        "https://www.yellowpages.com.au/balcatta-wa/bpp/startcloud-581735301",
        "https://www.truelocal.com.au/balcatta-wa/tlp/startcloud-581735301",
        "https://www.google.com/maps/place/StartCloud/@-31.8648767,115.8069889,739m/data=!3m2!1e3!4b1!4m6!3m5!1s0x2a32a5b5d9e864b5:0x9f02690968f0e50c!8m2!3d-31.8648813!4d115.8095638!16s%2Fg%2F11vzbgtytj"
      ]
    },
    [
      {
        "@context": "https://schema.org",
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://startcloud.au/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Resources",
            "item": "https://startcloud.au/resources"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Directors & Cyber Liability",
            "item": "https://startcloud.au/resources/directors-cyber-liability"
          }
        ]
      },
      {
        "@context": "https://schema.org",
        "@type": "FAQPage",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "Can a director really be held personally liable for a cyber breach?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Potentially, yes. Under section 180 of the Corporations Act, directors owe a duty of care and diligence, and ASIC's clear position is that overseeing cyber risk falls within that duty. Through what lawyers call 'stepping stone' liability, a company's cyber failure can flow through to directors who did not take reasonable steps to manage the risk. Section 180 is a civil penalty provision, with penalties for an individual running to over $1.5 million, and courts can also disqualify a person from being a director."
            }
          },
          {
            "@type": "Question",
            "name": "Does this only apply to big listed companies?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "No, and this is the part that surprises people. The section 180 duty of care applies to directors of all companies, including small private ones. What counts as 'reasonable' scales with the size and nature of the business, so no one expects a small company board to run like a bank's. But the underlying duty is the same, and the excuse that you are 'too small for this to matter' does not hold."
            }
          },
          {
            "@type": "Question",
            "name": "What did the RI Advice case actually establish?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "In ASIC v RI Advice Group (2022), the Federal Court found that the company had breached its obligations by failing to have adequate cyber risk management in place. It was the first Australian case of its kind, and it drew a firm line: managing cyber risk is a legal and regulatory obligation, not simply IT best practice. It reframed cyber from a technical issue into a governance one."
            }
          },
          {
            "@type": "Question",
            "name": "What does 'reasonable steps' look like for a director?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "You are not expected to be a security expert. You are expected to make sure the risk is genuinely being managed: that cyber is on the board agenda, that a competent person owns it, that there is an incident response plan, and that the basic controls are funded and in place. Crucially, you should be able to show you asked the questions. Evidence of active oversight is what separates a defensible position from a negligent one."
            }
          },
          {
            "@type": "Question",
            "name": "Doesn't our cyber insurance take care of this?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Not on its own. Cyber insurance can help with the costs of an incident, but it does not discharge a director's duty, and insurers increasingly require the very same controls before they will cover you or pay out. Treat it as a backstop that sits behind good governance, not a replacement for it. Our cyber insurance deep dive covers what it does and does not do."
            }
          }
        ]
      },
      {
        "@context": "https://schema.org",
        "@type": "BlogPosting",
        "headline": "Cyber security is now a directors' problem: can you be personally liable for a breach?",
        "description": "ASIC treats cyber resilience as a directors' duty. How section 180 and stepping-stone liability can reach directors personally, and what boards should do.",
        "author": {
          "@type": "Organization",
          "name": "StartCloud",
          "url": "https://startcloud.au"
        },
        "publisher": {
          "@type": "Organization",
          "name": "StartCloud",
          "url": "https://startcloud.au",
          "logo": {
            "@type": "ImageObject",
            "url": "https://startcloud.au/startcloud-logo.png"
          }
        },
        "datePublished": "2026-07-14",
        "dateModified": "2026-07-14",
        "image": "https://startcloud.au/og-image.png",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://startcloud.au/resources/directors-cyber-liability"
        }
      }
    ]
  ]
---

[![StartCloud](/assets/StartCloud-Logo-ByZE1kzP.svg "StartCloud: Cybersecurity-First Managed IT Services Perth")](/ "StartCloud | Managed IT Services Perth")

-   Cybersecurity
-   AI Solutions
-   Cloud
-   Technology
-   Networking
-   Explore

[Contact Us](/contact "Contact StartCloud, Perth IT Support")

Open menu 

Overview 

Short Version 

The Shift 

The Duty 

Personal Liability 

What to Do 

Verdict 

FAQ 

Related 

A plain-English guide for Australian company directors on whether they can be personally liable for a cyber breach. Explains how ASIC has reframed cyber resilience as a governance and directors' duty issue rather than a purely technical one, the landmark ASIC v RI Advice Group (2022) case that first established cyber risk management as a legal obligation, how the section 180 Corporations Act duty of care and 'stepping stone' liability can flow a company's cyber failure through to directors personally (with penalties over $1.5 million and possible disqualification), that this duty applies to directors of small private companies too, and the practical steps boards should take: put cyber on the agenda, make someone accountable, and fund the Essential Eight basics, tested backups and an incident response plan. General information, not legal advice.

[Home](/)[Resources](/resources)Directors & Cyber Liability 

Governance Guide

The one to forward to your board

# Cyber security is now a directors' problem 

Can a director be personally liable for a cyber breach? In Australia, that is no longer a hypothetical. The regulator has made cyber resilience a boardroom duty, and the way the law is written, a company's failure can land on the people who were meant to be overseeing it.

StartCloud 14 July 2026 8 min read 

The short version 

## The short version

**ASIC treats cyber resilience as a directors' duty, not just an IT job.** It has litigated on cyber risk management, and it has been explicit that oversight of cyber risk sits with the board.

**The duty of care under section 180 can reach directors personally.** Through 'stepping stone' liability, a company's cyber failure can flow to directors who did not take reasonable steps, with penalties over $1.5 million and possible disqualification.

**This applies to small company boards too.** You do not have to become a security expert. You do have to make sure the risk is genuinely being managed, and be able to show it.

The shift 

## How cyber became a boardroom issue

For a long time, cyber security lived firmly in the IT department. A breach was treated as a technical failure, something for the tech team to clean up. That framing is gone. Australia's corporate regulator, ASIC, has spent the last few years making the point, loudly and repeatedly, that cyber resilience is a matter of good governance, and that responsibility for it runs all the way to the board.

The turning point was ASIC v RI Advice Group in 2022. The Federal Court found the company had breached its obligations by failing to have adequate cyber risk management in place. It was the first case of its kind in Australia, and its real significance was the message: managing cyber risk is a legal obligation, and regulators will act when it is neglected. Cyber had officially become a governance question, not just a technical one.

**ASIC has been blunt about it.** Its consistent public message to boards is that cyber preparedness is a directors' responsibility, and that 'we left it to IT' will not wash as a defence when something goes wrong.

The duty 

## The duty that puts it on you

The legal hook is section 180 of the Corporations Act: the duty to act with the care and diligence a reasonable person would in your position. It is not a cyber-specific law. It is the general duty every director already has, and ASIC's position is that overseeing cyber risk sits squarely inside it.

Lawyers call the mechanism 'stepping stone' liability. The company contravenes an obligation, and the director who failed to take reasonable steps to prevent it is treated as having breached their own duty of care by exposing the company to that risk. The harm does not even have to be financial. Reputational damage, litigation and regulatory action all count. In other words, a cyber failure at the company level can become a personal one for the people who were supposed to be watching.

The exposure 

## What personal liability actually looks like

Section 180 is a civil penalty provision. For an individual, the maximum penalty runs to more than $1.5 million, and that is before the indirect costs. Courts can also disqualify a person from managing corporations, which for many directors is the more frightening outcome than the fine.

**The point is not to frighten you into paralysis.** It is that cyber risk now carries the same personal weight as financial or safety risk. You would never sign off accounts you had not scrutinised. Cyber deserves the same seriousness.

And to be clear, this is not just a big-company concern. The section 180 duty applies to directors of companies of every size, including the small private ones that make up most of the WA business landscape. What is 'reasonable' scales down for a smaller business, but the duty itself does not disappear.

The response 

## What a board should actually do

You are not expected to read firewall logs. You are expected to make sure the risk is being managed and to be able to prove you took it seriously. Three things carry most of that weight.

### Put cyber on the agenda

Cyber risk should be a standing board item, not an IT footnote. Regular, minuted discussion is part of how you show the risk was actually being overseen.

### Make someone accountable

Name who owns cyber risk and make sure they are competent, resourced, and reporting up. 'We assumed IT had it covered' is not a defence.

### Fund the basics and a plan

The Essential Eight controls, tested backups, and a written incident response plan. Being able to point to these is the difference between reasonable steps and negligence.

A practical starting point is the [Essential Eight](/cybersecurity/essential-eight-checklist), the ACSC's baseline of controls. Pair it with something that gives you real visibility, like a [monitored security operations service](/resources/deep-dives/what-is-a-soc), and you have both the substance and the evidence of oversight that the duty calls for.

Verdict 

## The takeaway

Cyber security has quietly climbed the ladder from an IT concern to a genuine directors' duty, with personal consequences attached. The regulator has said so, the courts have backed it, and the law was already written in a way that reaches individual directors. Pretending it is still someone else's job is now the risky position.

The reassuring part is that the same practical steps that protect the business also protect its directors. Getting the basics in place, monitored, and documented is exactly what our [managed security service](/cybersecurity/mssp) is built to do. If your board has never had a proper conversation about cyber, this article is the nudge to put it on the next agenda.

[Explore managed cybersecurity](/cybersecurity-perth)[See compliance & risk services](/cybersecurity/compliance)

FAQ 

## Common questions

### Can a director really be held personally liable for a cyber breach?

Potentially, yes. Under section 180 of the Corporations Act, directors owe a duty of care and diligence, and ASIC's clear position is that overseeing cyber risk falls within that duty. Through what lawyers call 'stepping stone' liability, a company's cyber failure can flow through to directors who did not take reasonable steps to manage the risk. Section 180 is a civil penalty provision, with penalties for an individual running to over $1.5 million, and courts can also disqualify a person from being a director.

### Does this only apply to big listed companies?

No, and this is the part that surprises people. The section 180 duty of care applies to directors of all companies, including small private ones. What counts as 'reasonable' scales with the size and nature of the business, so no one expects a small company board to run like a bank's. But the underlying duty is the same, and the excuse that you are 'too small for this to matter' does not hold.

### What did the RI Advice case actually establish?

In ASIC v RI Advice Group (2022), the Federal Court found that the company had breached its obligations by failing to have adequate cyber risk management in place. It was the first Australian case of its kind, and it drew a firm line: managing cyber risk is a legal and regulatory obligation, not simply IT best practice. It reframed cyber from a technical issue into a governance one.

### What does 'reasonable steps' look like for a director?

You are not expected to be a security expert. You are expected to make sure the risk is genuinely being managed: that cyber is on the board agenda, that a competent person owns it, that there is an incident response plan, and that the basic controls are funded and in place. Crucially, you should be able to show you asked the questions. Evidence of active oversight is what separates a defensible position from a negligent one.

### Doesn't our cyber insurance take care of this?

Not on its own. Cyber insurance can help with the costs of an incident, but it does not discharge a director's duty, and insurers increasingly require the very same controls before they will cover you or pay out. Treat it as a backstop that sits behind good governance, not a replacement for it. Our cyber insurance deep dive covers what it does and does not do.

This article is general information, not legal advice. For how directors' duties apply to your specific circumstances, speak to a qualified legal adviser.

Keep reading 

## Related pages

[

Deep dive 

### Cyber Insurance

A backstop behind good governance, not a substitute for it. What it covers, and what it requires.

Guide





](/resources/cyber-insurance-what-it-covers)[

Deep dive 

### What a SOC Does

The monitoring layer that gives a board real visibility, and evidence of oversight.

Guide





](/resources/deep-dives/what-is-a-soc)[

Deep dive 

### Ransomware: How It Works

The incident most likely to test your board's cyber preparedness.

Guide





](/resources/deep-dives/ransomware-how-it-works)

![StartCloud](/assets/StartCloud-Logo-ByZE1kzP.svg "StartCloud: Cybersecurity-First Managed IT Services Perth")

Cybersecurity-led IT for Australian businesses. We manage security, compliance, and modern IT environments, so risk is governed, not guessed.

Ground Floor West, 6 Gibberd Road, Balcatta WA 6021 

[08 6285 0001](tel:+61862850001 "Call StartCloud on 08 6285 0001")

Serving Perth businesses from Balcatta, Western Australia.

![Microsoft Solutions Partner - Modern Work](/assets/microsoft-solutions-partner-DqvNMv91.png "Microsoft Solutions Partner: Modern Work")

### Services

-   [Cybersecurity](/cybersecurity "Cybersecurity Services Perth | StartCloud")
-   [AI Solutions](/ai "AI & Automation Services Perth | StartCloud")
-   [Cloud](/cloud "Cloud Services Perth | StartCloud")
-   [Technology](/technology "IT Services and Support | StartCloud")
-   [Networking](/networking "Business Networking Perth | StartCloud")
-   [Packages](/packages "IT Support Packages Perth | StartCloud")

### Company

-   [About](/about "About StartCloud, Perth IT Support Team")
-   [Company Facts](/facts "StartCloud Company Facts | Perth Cybersecurity-First AI MSP")
-   [Resources](/resources "IT Resources & Guides | StartCloud Perth")
-   [Service Areas](/it-support-perth "IT Support Perth | StartCloud")
-   [Contact](/contact "Contact StartCloud, Perth IT Support")

### Locations

-   [All Service Areas](/locations "Perth IT Support Areas | StartCloud")
-   [IT Support Perth](/it-support-perth "IT Support Perth | StartCloud")
-   [Cybersecurity Perth](/cybersecurity-perth "Cybersecurity Perth | StartCloud")
-   [MSP Perth](/managed-service-provider-perth "Managed Service Provider Perth | StartCloud")
-   [Industries We Serve](/industries "IT Support by Industry Perth | StartCloud")

© 2026 Start Technologies Pty Ltd trading as StartCloud. All rights reserved.

ABN 17 676 121 449

[](https://www.linkedin.com/company/startcloudau "StartCloud on LinkedIn")[](https://www.facebook.com/startcloudaus/ "StartCloud on Facebook")[](https://www.google.com/maps/place/StartCloud/@-31.8648767,115.8069889,739m/data=!3m2!1e3!4b1!4m6!3m5!1s0x2a32a5b5d9e864b5:0x9f02690968f0e50c!8m2!3d-31.8648813!4d115.8095638!16s%2Fg%2F11vzbgtytj "StartCloud on Google")

[Terms of Service](/terms-of-service "Terms of Service | StartCloud")| [Privacy Policy](/privacy-policy "Privacy Policy | StartCloud")| [Modern Slavery Policy](/modern-slavery-policy "Modern Slavery Policy | StartCloud")| [Cookie Policy](/cookie-policy "Cookie Policy | StartCloud")

StartCloud Assistant

Online

G'day! 👋 I'm the StartCloud Assistant. How can I help you today?

Tell me about your servicesBook a discovery callI need IT support

Find Your Solution