Skip to main content

IT Start

How to meet APRA cybersecurity requirements in 2026

Man reviewing cybersecurity compliance document at desk


TL;DR:

  • APRA CPS 234 mandates Australian financial entities to implement proportional security controls, conduct systematic testing, and notify incidents promptly. Compliance requires board accountability, a complete asset inventory, continuous control monitoring, and detailed incident response plans. Emerging risks like AI threats and third-party vulnerabilities demand ongoing assessments and updated control frameworks for 2026.

APRA CPS 234 is the mandatory information security standard that every APRA-regulated entity in Australia must comply with, effective since 1 july 2019. Meeting APRA cybersecurity requirements means maintaining an information security capability that is proportional to the threats your organisation faces, with systematic control testing, timely incident notification, and board-level accountability baked in. The standard applies to banks, insurers, and superannuation funds as well as related holding and operating companies. Since 2019, the compliance bar has risen sharply. The Financial Accountability Regime (FAR) and the Cyber Security Act 2024 have added new layers of obligation that many compliance officers are still catching up with.

Infographic illustrating APRA cybersecurity compliance steps

How to meet APRA cybersecurity requirements: roles and accountability

Board-level accountability is the foundation of CPS 234 compliance. The Board holds ultimate responsibility for information security, and APRA expects that responsibility to be documented, not just assumed. Under FAR, named Accountable Persons must be assigned to discrete control areas, which means you cannot spread accountability so thinly that no one owns anything.

Senior management translates board direction into operational controls. That means defining who escalates incidents, who signs off on vendor assessments, and who reports to the Board when a control fails. APRA’s regulatory letters make clear that vague role descriptions do not satisfy this requirement.

Compliance officers should maintain a living accountability register. This document maps each CPS 234 obligation to a named individual, their deputy, and the escalation path if they are unavailable. Auditors and APRA reviewers look for this document first.

  • Assign a named Accountable Person for each major control domain (access management, incident response, vendor risk, asset classification).
  • Document escalation paths for incidents, including out-of-hours contacts.
  • Review and update the accountability register at least annually, or after any significant organisational change.
  • Confirm the Board receives a formal cybersecurity update at least quarterly.

Pro Tip: If your accountability register only exists as a paragraph in a policy document, it will not survive an APRA review. Build it as a table with names, roles, and review dates.

How do you identify and protect critical information assets under CPS 234?

Asset identification is where most organisations fall behind. CPS 234 requires a comprehensive inventory of all information assets, including assets managed by third parties on your behalf. We see this a lot: organisations have a partial list of internal systems but no visibility over what their cloud providers or outsourced processors actually hold.

Hands typing near notes and devices for asset audit

Classification drives everything downstream. Each asset must be assessed against its confidentiality, integrity, and availability impact. A payroll database and a marketing email list are both “data,” but they carry very different risk profiles and require very different controls.

Once classified, controls must match the asset’s risk level and lifecycle stage. A decommissioned server that still holds customer records is not a low-risk asset just because it is switched off. Controls apply until data is formally destroyed and that destruction is documented.

Steps to build a compliant asset inventory

  1. List every system, database, and data store, including those hosted by third parties or in cloud environments.
  2. Classify each asset by confidentiality, integrity, and availability impact using a consistent scoring method.
  3. Map controls to each classification tier and document the rationale for any gaps.
  4. Record the lifecycle stage of each asset, from active to archived to decommissioned.
  5. Review the inventory at least annually and after any material change to your environment.
Asset classification Example assets Minimum control requirements
Critical Core banking systems, customer PII databases MFA, encryption at rest and in transit, quarterly testing
High Internal HR systems, financial reporting tools MFA, access logging, annual penetration testing
Medium Internal collaboration tools, non-sensitive file shares Role-based access, annual review
Low Publicly available marketing content Basic access controls, periodic review

A cybersecurity assessment is the fastest way to identify gaps in your current asset inventory before an APRA review surfaces them.

What security controls and testing programs does APRA expect?

Annual penetration testing and quarterly control sampling are not enough. APRA expects continuous control monitoring (CCM) to demonstrate that controls are working year-round, not just at the point of a scheduled test. This is a significant shift from how most SMBs and mid-sized regulated entities have historically approached compliance.

The mandatory control categories under CPS 234 include access management, encryption, patch management, and vendor control assessments. Each of these must be tested systematically, with results documented and reviewed by internal audit. The documentation linking risks, controls, and test results must be communicated to the Board, not just filed away.

Continuous controls monitoring requires tooling and processes that run between formal testing cycles. Think automated access reviews, real-time patch compliance dashboards, and alert-based anomaly detection. These are not optional extras. APRA’s expectation is that you can demonstrate control effectiveness at any point in time, not just the week before an audit.

  • Access management: Review user access rights quarterly. Remove stale accounts within 24 hours of staff departure.
  • Encryption: Confirm encryption is applied to all critical and high-classification assets, both at rest and in transit.
  • Patch management: Apply critical patches within vendor-recommended timeframes. Document exceptions with a risk acceptance sign-off.
  • Vendor control assessments: Questionnaires alone do not satisfy APRA. Independent assurance and ongoing monitoring are required.
  • Penetration testing: Conduct testing at a frequency that reflects your risk exposure. High-risk environments need more than annual testing.

Pro Tip: Set up a simple monthly control health report that pulls data from your patch management, access review, and monitoring tools. It takes an hour to build and gives you evidence of continuous monitoring without needing a specialist audit every quarter.

A cyber security audit against CPS 234 requirements will tell you exactly which controls are missing or under-tested before APRA does.

How should you handle incident response and notification under APRA?

Incident response under CPS 234 is not just about fixing the problem. It is about detecting it fast, escalating it correctly, and notifying APRA within strict timeframes. Material information security incidents must be reported to APRA within 72 hours. Control weaknesses that could affect your security posture must be reported within 10 business days of discovery.

These deadlines create real pressure. The most common failure we see is not a lack of technical capability. It is a broken internal escalation path. Someone in IT knows about the incident, but the compliance officer does not find out until day three, and by then the 72-hour clock has already expired.

Materiality assessments under time pressure are often inconsistent, causing notification delays. APRA expects entities to have pre-defined materiality criteria so that the decision to notify is not made under pressure for the first time during an active incident. Incident response plans must be regularly reviewed, tested, and include escalation criteria to comply with CPS 234 incident management requirements.

Your incident response plan must also account for overlapping reporting obligations. The Notifiable Data Breach scheme, the Cyber Security Act 2024 ransomware payment reporting requirements, and APRA notification all run in parallel. A single incident can trigger all three.

Building a compliant incident response process

  1. Define materiality criteria in writing before an incident occurs. Include examples of what does and does not meet the threshold.
  2. Document the escalation path from first detection to compliance officer to Board notification, with time targets at each step.
  3. Test the plan at least annually with a tabletop exercise that includes a realistic scenario and a timed notification drill.
  4. Map your APRA notification obligations against the Notifiable Data Breach scheme and the Cyber Security Act 2024 to identify where obligations overlap.
  5. Assign a single owner for each notification obligation so that parallel reporting does not fall through the cracks.

What are the emerging compliance challenges for APRA-regulated entities in 2026?

The compliance bar has risen significantly since 2019, and 2026 brings new pressure from multiple directions. The Cyber Security Act 2024 and FAR have both expanded individual accountability and reporting obligations. Organisations that built their compliance programmes around the original CPS 234 requirements are now operating with gaps they may not have identified yet.

AI adoption increases cyber threats by enabling faster attack cycles and new attack vectors, including agentic workflows and AI-generated malicious code. APRA has written directly to industry on this point. Security teams using AI for threat hunting face a parallel challenge: remediating vulnerabilities at the speed that AI-assisted attackers can exploit them.

Third-party risk is the other major pressure point. CPS 230 and CPS 234 together require vendor capability assessments and contract controls that go well beyond a standard questionnaire. Independent assurance and ongoing monitoring are the expectation. If a critical supplier suffers a breach, APRA will ask what you knew about their security posture and when you knew it.

Emerging risk area APRA expectation Common gap
AI-driven threats Controls addressing AI-specific attack vectors and agentic workflows No AI risk assessment in existing frameworks
Third-party risk Independent assurance, not just vendor questionnaires Reliance on annual self-assessments from suppliers
Continuous monitoring Year-round control effectiveness evidence Periodic testing only, no CCM tooling
FAR accountability Named individuals for each control domain Shared or undefined accountability structures
  • Conduct an AI risk assessment and document how existing controls address AI-specific threats.
  • Review all critical vendor contracts against CPS 230 requirements and identify gaps in assurance coverage.
  • Implement at least one continuous monitoring tool that generates evidence between formal testing cycles.
  • Confirm your accountability register reflects FAR obligations, not just CPS 234 roles.

Risk identification practices for third-party and AI-related threats need to be built into your annual review cycle, not treated as a one-off project.

Key takeaways

Meeting APRA CPS 234 cybersecurity requirements demands board-level accountability, a complete asset inventory, continuous control monitoring, and pre-defined incident notification processes that can operate under time pressure.

Point Details
Board accountability is mandatory Name Accountable Persons for each control domain and document escalation paths formally.
Asset inventories must include third parties Incomplete inventories are the most common CPS 234 gap found during APRA reviews.
Annual testing is not enough Continuous controls monitoring is now the expected standard for demonstrating control effectiveness.
Notification deadlines are strict Material incidents require APRA notification within 72 hours; control weaknesses within 10 business days.
Emerging risks need active management AI-driven threats and third-party risk require updated assessments, not just existing control frameworks.

What I have learned from watching businesses fail APRA reviews

Honestly, the pattern is almost always the same. The organisation has a policy document, a penetration test from 18 months ago, and a vague sense that someone in IT is “handling it.” When an APRA review or a real incident hits, the gaps become obvious fast.

The two things that consistently undermine compliance are outdated asset inventories and broken escalation paths. A business can have excellent technical controls and still fail because no one can produce evidence that those controls were tested last quarter, or because the compliance officer found out about an incident four days after IT did.

What actually works is embedding accountability into daily operations, not just annual reviews. Monthly control health checks, a living asset register, and a tested incident response plan with named owners. These are not glamorous. They are the difference between passing an APRA review and spending six months in remediation.

If you are a compliance officer at an APRA-regulated entity, the cybersecurity essentials for finance firms are worth reviewing as a baseline before your next internal audit.

— Matt

How IT Start supports APRA compliance for Australian businesses

IT Start works with APRA-regulated businesses across Brisbane and Queensland to build and maintain CPS 234-aligned security programmes. The team manages access controls, patch management, continuous monitoring, and incident response processes that meet APRA’s current expectations, not just the 2019 baseline. IT Start holds SMB 1001 Gold certification, which reflects the same control rigour that APRA expects from regulated entities. For businesses that need a clear picture of where they stand, IT Start offers a compliance readiness assessment that maps your current posture against CPS 234 obligations. Explore IT Start’s cybersecurity services or cloud services to see how these fit your compliance requirements.

FAQ

What is APRA CPS 234?

APRA CPS 234 is the mandatory information security standard for all APRA-regulated entities in Australia, effective since 1 july 2019. It requires proportional security controls, systematic testing, and timely incident notification.

Who does CPS 234 apply to?

CPS 234 applies to banks, insurers, superannuation funds, and related holding or operating companies under Australian jurisdiction, including their third-party service providers who manage critical information assets.

What are the notification timeframes under CPS 234?

Material information security incidents must be reported to APRA within 72 hours of discovery. Control weaknesses that could affect security posture must be reported within 10 business days.

Is annual penetration testing enough for APRA compliance?

Annual penetration testing alone does not satisfy APRA’s current expectations. Continuous controls monitoring is now the standard, requiring year-round evidence of control effectiveness rather than periodic snapshots.

How does the Cyber Security Act 2024 affect APRA compliance?

The Cyber Security Act 2024 adds ransomware payment reporting obligations that run alongside APRA notification requirements. A single incident can trigger both, so your response plan must address both obligations simultaneously.

Related Posts