HomeRisk Management

Risk Management

ASIC’s cash settlement review puts home insurance conduct practices on notice

ASIC’s review of IAG, AAI, QBE, Allianz and Sure found extensive use of cash settlements, heavy reliance on single preferred-supplier quotes and inconsistent vulnerability support. The General Insurance Code of Practice reinforces the need to explain how cash settlements work and how decisions are made.

Why Moving Beyond Vulnerability Management is Central to Building True Operational Resilience

The US GAO’s Equifax findings show how a missed vulnerability becomes a business crisis when identification, detection, segmentation and data governance also fail. ASD, CISA, NIST, NCSC and APRA guidance show why leaders must connect continuous vulnerability assessment to critical services, accountable decisions and tested recovery.

Widespread AI Security Failures in UK Retail Demand Sharper Cyber Risk Ownership

RiverSafe’s Censuswide survey of 200 senior security leaders at large UK retailers reported AI-related incidents, unapproved tools and incomplete security reviews. The UK Government’s Cyber Security Breaches Survey and NCSC secure-AI guidance show how boards can convert that warning into access, supplier, monitoring and incident controls.

APRA’s quarterly life insurance statistics are a useful board signal

APRA’s 27 August 2026 life-insurance statistics cover industry performance, financial position, capital adequacy and product groups through June 2026. APRA’s revision and comparability warnings show why boards should challenge data lineage and management interpretation before acting on a trend.

Balancing Security and Privacy: Lessons from Facial Recognition Tests

Coles and Woolworths have described limited facial-recognition testing while emphasising that no deployment decision has been made. OAIC guidance and the Bunnings tribunal outcome show that necessity, proportionality, notice and documented privacy assessment must come before rollout.

Cross-Border Financial Crime Exposes Control and Governance Gaps

NSW Crime Commission Operation Ragamuffin and NSW Police Strike Force Danberta allege deleted sales records, interstate cash movement and restrained assets linked to pork-industry businesses. AUSTRAC’s 2026 risk material shows why cash-intensive operations and opaque structures require integrated financial-crime controls.