惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threatpost
Jina AI
Jina AI
S
SegmentFault 最新的问题
博客园 - 【当耐特】
阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
The Cloudflare Blog
MyScale Blog
MyScale Blog
F
Full Disclosure
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
云风的 BLOG
云风的 BLOG
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
P
Privacy & Cybersecurity Law Blog
H
Help Net Security
A
Arctic Wolf
T
Tor Project blog
WordPress大学
WordPress大学
Cisco Talos Blog
Cisco Talos Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Project Zero
Project Zero
V2EX - 技术
V2EX - 技术
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Hacker News: Ask HN
Hacker News: Ask HN
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
S
Securelist
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
PCI Perspectives
PCI Perspectives
雷峰网
雷峰网
J
Java Code Geeks
G
GRAHAM CLULEY
D
DataBreaches.Net
C
CXSECURITY Database RSS Feed - CXSecurity.com
Attack and Defense Labs
Attack and Defense Labs
美团技术团队
Security Archives - TechRepublic
Security Archives - TechRepublic
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
D
Docker
Cloudbric
Cloudbric
L
LangChain Blog

Culture

Bad bet: TAB fined $2.7 million over spam and telemarketing breaches eSafety report finds Big Tech not adequately protecting young men from sextortion Most Australians don’t want AI data centres in their neighbourhood, survey finds AI could disrupt the economy, regardless of whether it booms or crashes Senate demands OAIC hand over details of AMEX investigation Sydney booking agent responds to AI artist claims: ‘... will never book people who use AI to generate music’ Aussie creatives pen open letter calling on government to protect artists’ rights from AI companies Australia doubles social media ban fines as eSafety gets greater powers AFP to tackle serious online harms and cyber crime at Five Eyes Law Enforcement Group meeting AISA warns Australia’s cyber workforce shortage demands urgent diversity push ‘Moderation cannot be an afterthought’: What to know before you post an AI-generated Albo meme Report: Most Australians have ‘fractured awareness’ of digital privacy FOI docs reveal information commissioner’s concerns over Age Assurance Technology Trial Social media giants face eSafety investigation over age ban compliance issues Porn shop: Aussies turn to potentially risky VPNs following introduction of age verification requirements NZ firms say staff AI misuse is a key cyber risk Kinetic IT appoints new CEO to drive national growth UK MPs reject Australia-style social media ban The industry speaks: International Women’s Day 2026 Plugged in, turned on, and exposed: How sex tech is becoming the latest cyber security frontline AI growth drives Woolworths to have separate executives for InfoSec, physical security Unpacking the challenges for women in the cyber security sector Anthropic's latest products cause stock market slump as traditional SaaS offerings questioned TikTok faces potential EU fine over platform’s addictive properties Aussie activists call on app stores to remove Grok chatbot over nudify feature
Cyber preparedness critical as brokers face rising attack risk
Daniel Croft · 2026-03-05 · via Culture

Brokers are being urged to treat cyber security as a core business priority, with a growing number of sectors being viewed as attractive targets for cyber criminals.

Cyber preparedness critical as brokers face rising attack risk

In the latest Finance Specialist podcast hosted by Cyber Daily’s sister brand Broker Daily, hosts Liam Garman and Trent Carter revisited the recent youX data breach, which has allegedly left 797 broker organisations exposed.

According to threat actors on the dark web, they have allegedly exfiltrated the personal and financial data of 444,538 borrowers, including incomes, debts, government IDs, and home addresses.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

Garman and Carter outlined what brokers should have in place before an incident occurs and what steps to take once a breach is discovered.

“It’s an increasing area of focus for cyber criminals out there, and certainly the financial markets and financial industries make a lot of sense for them to be involved with,” Carter said.

“If we had criminals walking around with hoodies, machetes and machine guns, we would have locks on our doors and bars on our windows. This is the equivalent. I would just encourage brokers to do one thing today – review the real basics they have in place.

“We’ve got to be on our toes.”

Garman said: “In the property space, this is a $12 trillion industry. And at the broker level, if you were overseeing the transactions or if you’re supporting multimillion-dollar contracts, and potentially lending up into the millions, you’re actually a very fruitful target for attackers.”

Incident response plan essential

Carter and Garman agreed that preparation is essential.

Brokers were advised to maintain a documented incident response plan, even if only a brief outline, covering internal roles, decision-making responsibilities, and key contacts such as insurers and IT providers.

“I think you can kick off with a documented response plan – a risk assessment 101,” Carter said.

“If it’s a physical risk, like a bushfire plan: where are we going to stay, where are we going to go? What do we pack, what do we grab? It’s no different. It’s a risk. And if it happens in your business, what are we going to do?

“Even if it’s only a two-page bullet point document that you’ve discussed with the other people in your business, it’s better than nothing. So have clear internal roles and responsibilities – who’s going to make the decisions, who’s going to speak to the clients, who’s going to call the insurers, what are their numbers, what are our policy details. Having all that in one accessible place will make life a little bit easier.”

Other recommended measures included:

  • Ensuring multifactor authentication (MFA) is enabled on all accounts.
  • Testing backups and restoration processes in advance.
  • Identifying a trusted IT contact to assist in the event of a breach.

If an incident occurs, brokers are advised to disconnect from the internet without immediately shutting down systems and follow their documented response process.

Communication and compliance

The discussion also examined how brokers should communicate with clients and regulators following an incident.

Carter emphasised early and transparent communication, warning against attempts to conceal breaches.

“Honesty is the best policy in these scenarios,” he said.

“The best way to do it is early information, clear communication, regular communication, and outlining what we are doing about it.”

Post-breach vigilance critical

Importantly, the episode highlighted the risk of repeat attacks. Businesses that have been breached once may be targeted again, particularly if vulnerabilities remain unaddressed.

Brokers were encouraged to conduct a full root-cause analysis after any incident, retrain staff on phishing risks, review third-party access, and reassess system protections.

“They say lightning doesn’t strike twice. It actually really does,” Garman said.

“In the world of cyber breaches and cyber attacks, lightning strikes twice very often, because you flag to the cyber crime world where the vulnerabilities are in your business.”

Carter said: “I think they need a clean sheet of paper and to start again in terms of their cyber security environment and checks. The first thing you would want to do is a full root cause analysis: where did they get in? How did they get in? Where was that vulnerability? You need to understand that.”


This story was originally published by Cyber Daily’s sister brand, Broker Daily.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.