Powered by MOMENTUM MEDIA
lawyers weekly logo
Advertisement
Appointments
01 July 2025

Evidentia Group names new exec leadership team

The managed account provider has announced the appointment of its inaugural executive leadership, formally signalling its launch. The freshly ...
icon

CC Capital Partners edges closer to making binding bid for Insignia Financial

The private equity firm is actively working towards making a binding bid for Insignia Financial and will soon finalise ...

icon

Economic uncertainty to impact private credit in short-term: IFM Investors

Uncertainty around tariffs and subdued growth may lead to some short-term constraints in relation to the private credit ...

icon

Markets are increasingly desensitised to Middle East risks, says economist

Markets have largely shrugged off the recent escalation in the Middle East, reinforcing a view that investors are now ...

icon

State Street rebrands US$4.6tn SSGA investment division

State Street has rebranded its State Street Global Advisors arm, which has US$4.6 trillion in assets under management, ...

icon

VanEck reports investor uptake as ASX bitcoin ETF grows to $290m

Australia’s first bitcoin ETF has marked its first anniversary on the ASX, reflecting a broader rise in investor ...

VIEW ALL

FSS' privacy breach response endorsed

  •  
By
  •  
3 minute read

First State Super and Pillar responded appropriately to security breach, privacy commissioner says.

First State Super (FSS) responded appropriately to a breach of its data security last year, a report by privacy commissioner Timothy Pilgrim found.

The commissioner concluded that the fund and its administrator Pillar had breached National Privacy Principle 4.1, which states that an organisation must take reasonable steps to protect the personal information it holds from misuse and loss and from unauthorised access, modification or disclosure.

But the commissioner also said the organisations had taken appropriate measures once they became aware of the problem.

"The commissioner acknowledges that upon becoming aware of this matter, FSS's administrative manager, Pillar and FSS itself acted immediately to contain the incident, commenced an internal investigation of the incident, reviewed data security practices and sought external advice on how to handle the situation," Pilgrim said.

"Consequently, the commissioner ceased his own motion investigation into this matter, on the basis that the response to this incident appears adequate in the circumstances."

The commissioner has closed the case.

In September 2011, security specialist and OSI Security principal consultant Patrick Webster, and former FSS member, was able to access the details of 568 other members.

But the report published yesterday revealed that the super fund's security systems were successful in identifying an issue with its server before FSS was contacted by Webster.

"Specifically, Pillar's website monitoring system did detect an abnormality in its server logs on the morning of the incident," Pilgrim said.

Commenting on the report's findings, FSS chief executive Michael Dwyer said: "We acknowledge the commissioner's finding that our data security at the time was inadequate, but it is important to understand that at no time was there any opportunity for fraudulent transactions to occur."

But Dwyer also said the incident was not taken lightly by the fund.

"Clearly the breach was not insignificant," he said.

"We have apologised to our members and they can have every confidence that their personal information and their accounts are subject to stringent security protocols including regular ongoing security testing and reporting by highly regarded, independent specialist IT security consultants."