top of page

Why Cybersecurity Matters for SMSFs

Sep 7
3 min read

Updated: Sep 8

security in smsfs matters

Cybersecurity in SMSFs comes in all shapes and sizes. Tech-savvy SMSF trustees will have multi-factor authentication (“MFA”) enabled for all their investments, while others will happily rely on a sock drawer to store passwords.


While we have seen cyberattacks on APRA-regulated funds, it would be naïve to assume cybercriminals would ignore SMSFs that hold over $1 trillion in total assets.


Key statistics from the National Anti-Scam Centre show over $2.1 billion in losses between 1 January and 31 December 2025. Most importantly, people aged 65 and over accounted for 26.5% of those losses.


With 44% of all SMSF members in retirement as of March 2026, SMSFs remain vulnerable to hackers who would readily take advantage of the technologically challenged in this cohort.


As a result, SMSFs remain high on the ATO and ASIC's watchlist to ensure they stay protected.


SIS Regulations

While SIS is silent on security technology, the operating standards under s52 SIS charge trustees to perform their “duties and exercise powers in the best financial interests of the beneficiaries”.


The rules also say trustees should use the level of care, skill, and diligence a careful and responsible trustee would use for fund investments.


Where trustees are not employing security measures to their fullest extent, are they acting in the best interests of the members?


Could this open the door to potential litigation under section 55 SIS if the fund incurred a financial loss and there was a dispute, divorce, or disagreement?


SMSF Cybersecurity

The Australian Cyber Security Centre (ACSC) recommends using multi-factor authentication (“MFA”) because it defends against most password-related cyberattacks.


MFA requires a combination of two or more factors to access an account, such as a PIN, facial recognition, or an authenticator app.


Using more factors distinguishes legitimate users from hackers, making it harder for attackers to impersonate legitimate users or use brute-force methods.


Are SMSFs Cyber Resilient?

SMSFs have two components to cyber resilience: direct and indirect risk management.


Trustees have direct control over investment accounts they can access, such as bank and brokerage accounts. Enabling MFA ensures maximum security and serves as the first line of defence against hackers.


In a B2B context, partnering with SMSF professionals who use best-practice control technologies when storing member information is the second line of defence.


Critical measures such as firewalls, malware filters, MFA for login, and protocols such as penetration testing, automated security monitoring, and alerts should be standard cybersecurity practice.


SMSF Investments

Because some high-risk investments are more prone to fraud than others, trustees should implement sophisticated security measures to ensure the recoverability and safety of their members’ retirement savings.


Cryptocurrency and digital assets attract criminal activity because they are not classified as financial products. SMSFs can be exploited through illegal operations resulting in phishing scams, theft and collapsed crypto trading platforms.


Best practice is for an SMSF to use a crypto exchange with an AFSL licence that complies with AUSTRAC-regulated AML/CTF legislation and has a sound reputation, a new requirement of Australia's Digital Asset Framework.


Other investments, such as overseas assets, unlisted entities, and property, also come with their share of problems.


ASIC Activity

ASIC continues to wind up companies that may have facilitated scam activities and warns all consumers to remain vigilant.


The companies were associated with websites and apps that tricked consumers into investing in phony foreign exchanges, digital assets, or commodities trading.


Unfortunately, ASIC has said that these scams are like hydras; when one is shut down, two more take its place.


Shield and First Guardian are excellent reminders to all stakeholders to undertake due diligence.


SMSF Security Tips

The following security measures are crucial to protect SMSFs:


  • Avoid clicking on account sign-in hyperlinks received from SMS or emails

  • Do not share MFA codes or approve unknown sign-in attempts

  • Use MFA whenever possible

  • Select strong passwords

  • Regularly update computer software

  • Research websites before making any online payments

  • Review email addresses, bank statements and recipients of money beforehand


Conclusion:

Cyber resilience is most effective as a shared responsibility between all parties.


SMSF professionals should educate their trustee clients on adopting robust security measures to safeguard fund investments and personal data. Partnering with SMSF experts who use best-practice control technologies is the other step.


Constant vigilance is crucial to safeguard SMSFs from cyberattacks and preserve the integrity of the SMSF industry by implementing stringent security measures like MFA, rather than relying on simple solutions like sock drawers.


🎁Bonus Reading

In our next article, The Cybercrime Threat Facing SMSFs, we explore the most common cybercrime risks targeting the sector and the practical steps that can help reduce the likelihood of an attack.



Comments


bottom of page