Executive Summary
APRA CPS 234 (Prudential Standard CPS 234) is the Australian financial regulator’s mandatory cyber security rule for all APRA-regulated entities3. Introduced in July 2019, CPS 234 compels banks, insurers, superannuation trustees, and other APRA-regulated financial institutions to maintain strong information security postures or face regulatory scrutiny4 5. The standard’s core objective is to ensure these critical financial firms are resilient against cyber threats, thereby safeguarding Australia’s financial system.
Key requirements at a glance:
- Board Accountability: CPS 234 holds the board and senior management ultimately responsible for information security6. Cyber security is not just an IT issue – APRA expects leadership to own and oversee it as part of corporate governance.
- Information Security Capability: Entities must have an information security capability commensurate with their size and the evolving threat landscape7. In practice, this means dedicating sufficient resources, staff expertise, and technology to meet security challenges.
- Controls & Testing: Entities must implement controls to protect information assets in line with those assets’ criticality and sensitivity8. And crucially, they must systematically test and assure the effectiveness of these controls (e.g., through regular security audits, penetration tests, and independent reviews)9.
- Incident Management & Notification: APRA-regulated firms must have robust incident response plans and report material cyber incidents to APRA within 72 hours of detection10 11. They also need to notify APRA of significant control weaknesses discovered (generally within 10 days, as per APRA guidance).
- Alignment with Best Practices: APRA doesn’t specify exact technical controls, but it encourages aligned frameworks – e.g., adopting the ACSC Essential Eight mitigations to bolster technical defences, and using standards like ISO/IEC 27001 to structure an enterprise security program12 13. Many APRA-regulated entities leverage these to satisfy CPS 234, ensuring no gaps in their security management.
Why CPS 234 matters: In a sector handling billions of dollars and personal data, failing to protect information is a prudential risk. APRA can impose enforceable undertakings, licence conditions, or other regulatory sanctions on non-compliant entities. More broadly, CPS 234 has raised the bar for cyber security across the finance industry, pushing firms to formalise security governance and invest in resilience. It also signals to partners, investors, and the public that cyber security is a non-negotiable priority for APRA-regulated businesses.
(Note: This guide provides general guidance on CPS 234 compliance for informational purposes – it is not legal advice. APRA’s official standard and prudential practice guides should be consulted for precise requirements [APRA].)
What is APRA CPS 234 and Why Does it Matter?
Cyber insurance (cyber-liability insurance) is a specialised insurance policy designed to financially protect businesses against losses from cyber incidents. It functions much like other types of business insurance: in exchange for a premium, the insurer agrees to cover certain costs if the insured company experiences a covered cyber event. These events can range from malicious attacks (like hacking, malware, ransomware) to non-malicious failures (like accidental data leaks).
Why Australian businesses should care: Cyber incidents are increasingly common and costly for organisations of all sizes. A serious data breach or ransomware attack can impose massive expenses – including technical recovery, legal liabilities, regulatory fines, public relations efforts, and business downtime. For example, one study estimated the average cost of a serious cyber attack on an Australian mid-sized business exceeds $270,000, with an average downtime of over 200 hours (several weeks). Even smaller breaches can inflict tens of thousands of dollars in damages. Yet, many companies are either uninsured or underinsured against these losses.
Cyber insurance is important because it transfers some of this financial risk to an insurer. It won’t prevent an incident from happening (and it cannot guarantee to make you whole in every scenario), but it provides a safety net that can be the difference between recovery and business failure after a major cyber event.
Australian context: In Australia, cyber insurance is not mandatory. However, it’s increasingly viewed as essential for prudent risk management, given rising threats and the regulatory environment (companies must, for instance, comply with the Privacy Act’s breach notification rules, which themselves incur costs). The Insurance Council of Australia has noted that while uptake is growing, only about one in five SMEs currently have cyber insurance – leaving a majority exposed. Larger enterprises are more likely to have coverage (around 70% have a policy), but even they face rapidly evolving cyber risks that can test the limits of traditional policies.
In sum, any business with an internet connection and digital assets should consider cyber insurance as part of its resilience plan. Cyber attacks are increasingly “when” not “if” events, and having a financial backstop in place can be a lifesaver if a catastrophe strikes.
What is APRA CPS 234 and Why Does it Matter?
APRA CPS 234 is a prudential standard on information security issued by the Australian Prudential Regulation Authority (APRA)14. It came into effect on 1 July 2019 and applies to all APRA-regulated entities, which broadly includes authorised deposit-taking institutions, general insurers, life insurers, private health insurers, and superannuation trustees (and extends to their relevant service providers).
Purpose: CPS 234 aims to strengthen the cyber resilience of Australia’s financial system by ensuring each regulated entity maintains robust information security. APRA recognised that cyber attacks on one institution can ripple through the sector, so CPS 234 sets a baseline of security every regulated entity must meet15. The focus is both preventative (controls) and responsive (incident management), with an overarching emphasis on governance and accountability.
Key requirements of CPS 234:
(APRA summarises these as follows16)
- Board and Senior Management Responsibility: The Board is ultimately accountable for information security17. They must ensure the company has an adequate security strategy, resources, and oversight. Senior management must implement and monitor the security program. In short, APRA wants cyber risk elevated to a board-level issue with clear governance – an IT manager alone cannot carry the can.
- Information Security Capability: Entities must maintain an information security capability commensurate with their threats and vulnerabilities18. This means understanding the threat environment (e.g., frequent phishing, advanced malware aimed at financial systems) and having the people, processes, and technology in place to deal with it. A small credit union might justify a leaner setup than a big four bank, but both must take cyber risk seriously and allocate resources accordingly.
- Policy Framework & Roles: CPS 234 requires clear roles and responsibilities for security across the organisation19. It also expects documented security policies and standards. In practice, APRA-regulated firms often formalise an information security policy, assign a CISO (or equivalent role), and define responsibilities from the board down to technical teams, fulfilling this requirement.
- Protection Controls for Information Assets: Entities must identify their information assets (data, systems, services) and implement controls proportionate to the criticality and sensitivity of those assets20. For example, a core banking system or customer database should have stricter controls (like encryption, access restrictions, multi-factor authentication) compared to less sensitive systems. This approach aligns with classifying assets (perhaps by sensitivity levels) and applying stronger safeguards to the “crown jewels”. APRA expects that third-party providers holding a regulated entity’s data are also covered by these controls – the regulated entity remains responsible for ensuring vendors meet security standards.
- Testing and Assurance: CPS 234 explicitly mandates regular testing of security controls and assurance of their effectiveness21. This typically entails penetration testing, vulnerability scanning, control audits, and scenario testing (simulated cyber drills). Where appropriate, APRA encourages involving independent experts or auditors to verify that controls are working as intended. By embedding frequent testing, APRA intends that organisations discover and remediate weaknesses proactively. Notably, APRA launched a tripartite (APRA, institution, independent auditor) review program for CPS 234, indicating how seriously it takes control assurance.
- Incident Response and Notification: CPS 234 requires robust incident management plans to promptly respond to and recover from security incidents22. Crucially, APRA demands that entities notify APRA of material information security incidents within 72 hours of detection23, ensuring the regulator is kept aware of significant breaches or events. Additionally, APRA expects notification within 10 days of discovering any material security control weaknesses that cannot be remedied in a timely manner. These reporting obligations mean APRA-regulated firms must have internal processes to identify when an incident or weakness crosses the “material” threshold and quickly escalate it to regulators.
Why it matters: Failing to comply with CPS 234 can have serious consequences. APRA has authority to take action ranging from increased supervisory scrutiny and additional capital requirements to, in extreme cases, fines or restrictions on a business’s operations (APRA’s mandate is to protect financial system stability). Also, under Australia’s “BEAR” and upcoming “FAR” accountability regimes, senior executives and board members could face personal consequences if prudential obligations like CPS 234 are neglected. In essence, CPS 234 isn’t a box-ticking exercise: it’s about truly embedding cyber security into the fabric of APRA-regulated organisations, reducing the chance of devastating breaches that could compromise Australians’ financial data or disrupt critical services.
(Reference: CPS 234 is codified by APRA in its prudential standards, with APRA’s guidance emphasising board accountability, proportional controls, regular testing, and timely breach reporting [APRA].)
CPS 234 Key Requirements (High Level) and Alignment with Frameworks
Summary of CPS 234 Requirements: APRA’s CPS 234 mandates that regulated entities:
- Establish clear security roles & accountability – Board and executives must own security oversight.
- Maintain appropriate security capabilities – resource and staff security teams to match threat levels.
- Identify & classify information assets – know what needs protecting, and its criticality.
- Implement protective controls – apply proportionate controls based on asset sensitivity (e.g., encryption for highly sensitive data, strict access control for core systems).
- Conduct regular security testing & assurance – e.g., routine pen tests, audits, scenario drills (often at least annually, plus after significant changes).
- Timely incident notification to APRA – notify APRA within 72 hours of a material incident (e.g., a system breach or data theft that could be significant), and within 10 days of finding a critical security control weakness that isn’t quickly fixed.
- Alignment with ACSC Essential Eight: The Essential Eight controls (application whitelisting, patching, MFA, etc.) map closely to the kinds of preventive controls CPS 234 expects. For example, implementing all eight strategies to a high maturity level addresses many of the technical vulnerabilities APRA wants closed (e.g., patching addresses vulnerabilities, backups and user access controls limit impact). Many APRA-regulated firms either already use the Essential Eight as part of their security baseline or have equivalent measures. In fact, APRA participated in developing cross-industry cyber guidelines emphasising the Essential Eight as a baseline for all industries. By achieving strong Essential Eight implementation, APRA-regulated entities can demonstrate they have taken serious action on the “Protect” side of CPS 234.
Alignment with ISO/IEC 27001: ISO 27001 is a natural companion to CPS 234. Where CPS 234 sets the what (outcomes APRA needs, like board oversight, adequate controls, etc.), ISO 27001 provides the how – a systematic method to manage and document those outcomes via an ISMS. Many APRA-regulated entities pursue ISO 27001 certification to underpin their CPS 234 compliance. For instance:
- Roles & governance: ISO 27001 requires top management involvement and defined security roles, aligning with CPS 234’s board accountability requirement.
- Risk-based controls: ISO 27001’s risk assessment process helps prioritise and select controls, meeting CPS 234’s mandate to protect information assets based on their criticality.
- Continuous improvement & audits: ISO 27001 demands ongoing monitoring, internal audits, and management reviews, which dovetail with CPS 234’s call for systematic testing and assurance of controls.
- Certification and evidence: An ISO 27001 certificate can serve as independent validation of your security program’s rigour. While APRA doesn’t accept that in lieu of compliance, it certainly simplifies demonstrating compliance. Many controls required by CPS 234 are either identical or very similar to ISO 27001 Annex A controls (e.g., access management, incident management, vendor security), so “if you’ve done ISO, you likely cover a lot of CPS 234” [APRA].
Bottom line: implementing Essential Eight and ISO 27001 significantly strengthens an organisation’s readiness for CPS 234. APRA itself has implied as much – it expects its regulated entities to align with industry best practices (APRA has referenced using ISO 27001 and ASD’s Essential Eight as benchmarks in some of its communications) [APRA][ASD/ACSC]. Ultimately, CPS 234 is outcome-focused: APRA doesn’t micromanage how you meet the standard, as long as you can prove you have robust, effective security in line with your risk profile. Leveraging well-known frameworks is an efficient way to meet those outcomes and give your board and APRA comfort that nothing critical is overlooked.
Practical Steps to Achieve CPS 234 Compliance
Implementing CPS 234 is a multi-faceted effort requiring both organisational and technical measures. Here we break down practical steps to reach and maintain compliance, with tailored guidance for leadership and security teams:
For Executives & Board Members
- Establish Governance & Oversight: Ensure that the Board formally recognises cyber security as part of its risk oversight responsibilities. This may involve creating a board sub-committee or adding cyber risk to an existing risk committee’s remit. Set a clear information security policy approved by the Board, and require management to report regularly on compliance with CPS 234 (covering metrics like number of incidents, results of security tests, etc.).
- Set the Tone & Resource Appropriately: Create a culture of security from the top. Allocate sufficient budget and skilled personnel to your security function (CPS 234 implicitly requires “adequate capability”)24. Designate a senior executive (like a CISO or CIO) accountable for day-to-day info security, but keep the Board engaged via routine briefings. Make it known that security is a strategic priority – this not only helps compliance but also assures APRA you’re taking CPS 234 seriously.
- Integrate with Enterprise Risk Management: Cyber risk management under CPS 234 should dovetail with broader enterprise risk frameworks (e.g., APRA’s CPS 220 Risk Management). Incorporate information security risks into your enterprise risk register and ensure they have owners and mitigation plans. This aligns with APRA’s expectation that information security is treated as part of overall operational risk (CPS 234 supports APRA’s general risk management standards).
- Incident Readiness & Reporting: Make sure the company has a documented, tested incident response plan that specifically includes regulatory notification procedures. APRA’s 72-hour breach notification rule means the clock ticks fast in a crisis25 – have a clear internal trigger for when an incident is considered material and who contacts APRA. Include APRA contact steps in the plan and test the scenario in tabletop exercises. Be aware that APRA also expects notification of critical control weaknesses, so incorporate processes for escalating internal audit findings or security test results that reveal serious deficiencies. The Board should be aware of these obligations.
- Leverage External Assurance: Consider engaging independent audits or reviews specifically targeting CPS 234 compliance (often done as part of APRA’s tripartite review approach). Getting a third-party to assess your security controls and CPS 234 readiness not only helps fix gaps proactively, but also provides evidence of due diligence to APRA. Many boards commission an annual CPS 234 compliance review by their internal audit (with input from an external firm) to satisfy themselves and APRA that the entity remains on track.
(Related internal resources: You may find our Cyber Security Governance for Boards guide useful for more ideas on how boards can oversee cyber risk effectively [AICD].)
For IT & Security Leaders
- Understand CPS 234 Requirements Thoroughly: Read APRA’s Prudential Standard CPS 234 and any associated APRA guidance (Prudential Practice Guides) to ensure you know what’s expected (the main requirements were summarised above). This provides clarity on the outcomes you must achieve (e.g. “effective control testing”, “72-hour incident notifications”) so you can map them to concrete tasks.
- Perform a Gap Analysis: Evaluate your current security setup against CPS 234 needs. Often this means asking: Do we have an inventory of all critical information assets? Are our controls and monitoring for these assets adequate? Have we assigned clear security roles? How quickly can we detect and respond to incidents? Engaging in a formal gap analysis (maybe using frameworks like ISO 27001 or NIST CSF to structure it) can highlight where more work is needed for full CPS 234 compliance.
- Strengthen Baseline Controls (Essential Eight): Implement or enhance fundamental security controls across your environment. ACSC’s Essential Eight is an ideal reference point for what APRA would consider “minimum defensive controls”26. For example:
- Patch management: Ensure prompt patching of systems (with a formal process).
- Access management: Use multi-factor authentication and strict privileged access controls.
- Backups and recovery: Maintain offline backups of critical data and test them regularly, linking to your resilience obligations under CPS 234.
- User training: Conduct regular phishing and security awareness training, as human error can undermine technical controls.
- These actions both reduce risk and satisfy APRA that you’re proactively defending critical information assets.
- Formalise InfoSec Governance & ISMS: If your organisation hasn’t already, establish an information security management system (ISMS) – essentially, a structured set of policies and processes (aligned with a standard like ISO 27001) that covers risk assessment, control selection, continuous monitoring and improvement. This supports CPS 234’s requirement for a considered, risk-based approach to security27. As part of this, create or update key documentation: an information security policy, asset classification standard, incident response plan, third-party security policy, etc.
- Enhance Monitoring & Incident Response: APRA expects that institutions can promptly identify and respond to incidents. Invest in enhancing your threat detection capabilities – e.g., a Security Operations Centre (SOC), 24/7 monitoring, SIEM tools – appropriate to your size. Similarly, improve incident response readiness: ensure runbooks are in place for likely scenarios (e.g., ransomware on core systems, customer data breach) and that staff know their roles. Simulate incidents to test both technical response and the 72-hour APRA notification process.
- Plan for APRA Notification & Reporting: Working with legal/Risk, define what constitutes a “material incident” in your context (APRA doesn’t give an exact definition, but it typically means an incident that materially affects customers, financial position, or operations). Set up internal triggers to escalate such incidents to senior management quickly, so APRA can be informed within 72 hours28. Keep documentation for incidents and control tests – APRA can request evidence or conduct supervisory visits to ensure you’re following CPS 234, so thorough record-keeping will simplify proving compliance.
- Align with ISO 27001 or Others: Map your existing controls and processes to ISO 27001 or NIST CSF and see where they intersect with CPS 234. Many technical control requirements from APRA (like having appropriate access controls, secure configurations, vendor oversight) are explicitly covered in ISO’s control set29. Using a framework for mapping ensures you don’t miss any area. For instance, ISO’s Annex A includes “Cryptography”, “Supplier Security” etc. which align with CPS 234 expectations. If you are already ISO 27001 certified, double-check additional specifics of CPS 234 (like APRA breach notification) and fold them into your ISMS. If you are not ISO certified, consider working towards it – it demonstrates externally that you meet an international benchmark which covers much of CPS 234’s scope [ISO].
(Need expert help? We offer an compliance assessment – our team can perform a gap analysis against CPS 234 and help you implement aligned controls and governance. We also assist with ISO 27001 integration to satisfy CPS 234. Contact us to learn more.)
Frequently Asked Questions
What is APRA CPS 234 and who does it apply to?
APRA CPS 234 (Information Security) is a prudential standard issued by the Australian Prudential Regulation Authority (APRA). It applies to all APRA-regulated entities, which broadly includes banks, insurance companies, superannuation (pension) trustees, licensed non-bank lenders, and other financial institutions that APRA supervises. In effect since 1 July 2019, CPS 234 sets out the minimum information security requirements these organisations must meet to ensure strong cyber resilience in the financial sector. [APRA]
What are the key requirements of CPS 234?
CPS 234 requires APRA-regulated companies to: (1) clearly define information security roles and responsibilities (with board-level accountability); (2) maintain an appropriate information security capability relative to their threats; (3) implement controls and safeguards to protect critical or sensitive information assets; (4) conduct regular testing and assurance of those controls’ effectiveness; and (5) notify APRA within 72 hours of a material security incident (and promptly report significant control weaknesses). In essence, it’s about having robust, proactive security and involving senior leadership in managing cyber risk. [APRA]
How does CPS 234 align with ACSC’s Essential Eight controls?
Very closely. The Essential Eight are a recommended baseline of technical controls by the Australian Cyber Security Centre (ACSC). Implementing them helps satisfy parts of CPS 234’s requirement to protect information assets with commensurate controls. For example, patching (one of the Essential Eight) addresses vulnerabilities in line with CPS 234’s expectations, and restricting admin privileges and using MFA (also Essential Eight strategies) demonstrate strong access control – something APRA expects for protecting critical systems. While CPS 234 doesn’t explicitly mandate the Essential Eight, APRA has indicated support for these strategies, and many APRA-regulated firms use them as part of meeting CPS 234. [ASD/ACSC]
Is ISO 27001 certification required to comply with CPS 234?
No, ISO/IEC 27001 certification is not required to comply with CPS 234. However, ISO 27001 can be very helpful. CPS 234 and ISO 27001 have a lot of synergy – ISO 27001 provides a structured global framework for managing security which covers many of CPS 234’s bases. Aligning with ISO 27001 (and optionally seeking certification) can make CPS 234 compliance easier, since ISO 27001 ensures you have a comprehensive set of controls, risk assessments, and governance in place. Some APRA-regulated firms choose to get ISO 27001 certified as a way to give themselves and APRA confidence in their security program, but it’s not an official requirement of CPS 234. [APRA] [ISO]
How does APRA enforce CPS 234?
APRA expects continuous compliance with CPS 234. It can enforce the standard through its supervisory activities and powers. For example, APRA may conduct thematic reviews or audits focusing on CPS 234, and it has required “tripartite” reviews (involving APRA, the entity, and an external auditor) to assess compliance at some entities. If serious deficiencies are found or incidents aren’t reported, APRA can use its regulatory tools – these might include requiring remedial action, issuing enforcement directions, imposing capital penalties, or in extreme cases, pursuing fines or disqualifications under the Banking or Insurance Acts. Essentially, non-compliance with CPS 234 is treated like any other breach of APRA’s prudential standards, with potentially significant regulatory consequences. [APRA]
What steps can we take to comply with CPS 234?
First, assess your current state: perform a gap analysis against CPS 234’s requirements. Next, ensure you have Board-approved security policies and a clear governance structure with defined roles (e.g., a CISO overseeing an enterprise security team). Then, focus on key controls and processes: maintain a current information asset inventory (so you know what to protect), implement baseline security controls (e.g., patching, access controls, backups – align with the Essential Eight), and set up continuous security monitoring and incident response. Also, conduct regular security testing and independent reviews of controls to find and fix gaps. Finally, make sure you have a plan to notify APRA of serious incidents within 72 hours. Essentially, treat CPS 234 compliance as an on-going process of risk management, not a one-time project [APRA]
Does CPS 234 require us to include third-party providers and subsidiaries?
Yes. The scope of CPS 234 covers not only your own internal systems but also information assets managed by related parties or third parties on your behalf. APRA expects you to ensure that material service providers (like cloud providers, IT outsourcing firms, etc.) meet your security standards – often through contractual arrangements and periodic assurance (e.g., reviewing their SOC reports or performing audits). Essentially, if you outsource a critical function, you cannot outsource the risk: you must manage and oversee the provider’s security to remain CPS 234 compliant.
How often do we need to report to APRA under CPS 234?
Unlike some prudential standards that require regular reporting, CPS 234’s reporting is event-driven. You need to report to APRA within 72 hours after experiencing a material information security incident, and within 10 business days after identifying a material weakness in your security controls if that weakness might take time to remediate. There’s no routine periodic CPS 234 report to lodge (unless APRA specifically asks for updates or includes it in broader risk management reporting), but you should maintain readiness to notify APRA quickly whenever required. Frequent internal reporting (to your board and risk management committees) is advisable so that any notifiable incident or issue is caught and escalated promptly to APRA by management when needed.
Next Steps
With a solid grasp of CPS 234 and commitment from the top, APRA-regulated entities can build a strong defence against cyber threats while satisfying regulatory expectations. If you have any questions or need support aligning your security program with CPS 234 – from board briefings to technical compliance assessments – our team at KMTech is here to help. Being proactive about CPS 234 compliance not only keeps APRA happy, but importantly, it strengthens your organisation’s cyber resilience in a rapidly evolving threat environment. Let’s make sure your security is as robust and dependable as the financial services you provide.





