Back to Blog
Insights11 min read

Best Practices for CPS 234 Compliance in Australia

A

Alexander Sverdlov

Security Analyst

7/20/2026
Best Practices for CPS 234 Compliance in Australia

CPS 234 is not a checkbox exercise, and treating it like one is how regulated entities end up with a remediation plan they never asked for. APRA introduced the Prudential Standard CPS 234 to force banks, insurers, and superannuation funds to take information security seriously at the board level, not just in the IT department. I have run security assessments for financial institutions across 14 countries since 2013, and the pattern is always the same: the organisations that struggle with prudential standards like CPS 234 are the ones that documented a policy and then never operated it. This guide walks through what APRA actually expects, where entities usually fall short, and the practices that hold up under scrutiny.

What CPS 234 Actually Requires

CPS 234 applies to APRA-regulated entities and, importantly, extends to the information assets managed by third parties and related parties on your behalf. The standard is short compared to frameworks like ISO 27001, but every clause is enforceable. The core obligations break down into a handful of themes:

  • Board accountability. The board is ultimately responsible for information security. This cannot be delegated away to a vendor or an outsourced IT provider.
  • Clearly defined roles. Responsibilities for information security must be assigned across the board, senior management, governance bodies, and individuals.
  • Information security capability. Your controls must be sized to the threats you actually face and to the criticality and sensitivity of the assets you hold.
  • Control implementation and testing. Controls must be implemented and their effectiveness tested through a systematic testing programme.
  • Incident notification. APRA must be notified of material information security incidents, generally within 72 hours, and of material control weaknesses within 10 business days.

That last point is where a lot of entities get caught. CPS 234 is not only about preventing incidents. It is about being able to detect them, classify their materiality, and report them on APRA's timeline. If you cannot tell whether an incident is material, you have already failed the notification obligation.

Best Practice 1: Put Real Governance Behind the Policy

Governance under CPS 234 means the board can demonstrate it understands the entity's information security risk and is actively overseeing it. Not that a board member signed a policy once. In practice this means the board receives regular, meaningful reporting: control test results, open remediation items, incident summaries, and third-party risk status. Vague green-amber-red dashboards with no underlying evidence do not survive an APRA review.

What strong governance looks like in the entities I have assessed:

  • A named executive owns information security and reports to the board on a defined cadence, not only when something breaks.
  • The risk appetite for information security is written down in language the business understands, and control decisions trace back to it.
  • Roles are documented in a way that removes ambiguity between the entity, its IT provider, and any related party.
  • Governance is reviewed at least annually and whenever the threat environment or the business materially changes.

If your governance model relies entirely on an outsourced IT partner, you still own the accountability. APRA has been explicit that entities cannot outsource responsibility for CPS 234, only the operational work. A virtual CISO engagement is one way smaller entities get board-grade security leadership without hiring a full-time chief information security officer.

Best Practice 2: Classify Assets Before You Assess Risk

You cannot size controls to criticality and sensitivity if you have not classified your information assets. This is the step most entities skip, and it undermines everything downstream. A risk assessment that treats a test database and a production payments system as equal is not a risk assessment. It is a spreadsheet.

Build and maintain an inventory of information assets, including those held by third parties, and classify each by criticality and sensitivity. Then run risk assessments that reflect real threats: credential theft, ransomware, cloud misconfiguration, insider misuse, and supply chain compromise. Use recognised tooling for vulnerability discovery, but understand that a scanner output is an input to a risk assessment, not the assessment itself. A structured vulnerability assessment tells you what is exploitable; the classification tells you what it would cost you.

CPS 234 ObligationWhat Weak Looks LikeWhat Strong Looks Like
Roles and responsibilitiesPolicy names "IT" genericallyNamed owners across board, management, and vendors
Asset classificationNo inventory, or one that is years staleLive inventory rated by criticality and sensitivity
Control testingAnnual pen test, filed and forgottenRisk-based testing programme with tracked remediation
Incident responsePlan exists, never rehearsedRehearsed playbooks with materiality and APRA notification steps
Third-party assuranceTrust the vendor's wordContractual controls plus independent evidence

Best Practice 3: Implement Controls Sized to the Threat

CPS 234 requires controls commensurate with the threats and vulnerabilities you face. There is no fixed control list, which trips up teams that want a checklist. The expectation is that you can justify why your controls are adequate for your risk profile. The baseline I look for in any regulated financial entity:

  • Multi-factor authentication on all remote access, administrative accounts, and email. Weak or absent MFA remains the single most common finding in my assessments.
  • Encryption of sensitive data at rest and in transit, with key management that is actually controlled rather than left at provider defaults.
  • Privileged access management so administrative rights are granted least-privilege, time-bound, and logged.
  • Endpoint detection and response across servers and workstations, monitored rather than merely installed.
  • Timely patching with defined service levels for critical vulnerabilities, especially on internet-facing systems.

Cloud environments deserve specific attention. Most of the serious exposures I find in Australian financial entities are not exotic attacks; they are misconfigured storage, over-permissioned identities, and public endpoints that should never have been public. If your platform runs on AWS or Azure, dedicated cloud security consulting usually pays for itself in a single engagement by closing the gaps a generic audit misses.

Best Practice 4: Test Controls Systematically, Not Once a Year

The systematic testing programme is where CPS 234 has teeth. APRA expects testing frequency and depth to reflect the rate of change in your environment and the criticality of the assets. A single annual penetration test satisfies almost no one who reads the standard carefully. The testing programme should include:

  • Regular vulnerability scanning with defined remediation timelines.
  • Penetration testing of critical and internet-facing systems, with retesting to confirm fixes hold.
  • Configuration and control reviews after significant changes.
  • Independent assurance where the person testing is not the person who built the control.

The independence point matters. If your IT team both implements and tests its own controls, APRA will question the objectivity of the results. This is exactly why entities bring in an external IT security audit: to get evidence a regulator will accept rather than a self-assessment.

Best Practice 5: Build Incident Response Around the Notification Clock

CPS 234's notification obligations are specific. Material information security incidents must be reported to APRA within 72 hours, and material information security control weaknesses within 10 business days. To meet those timelines you need three things working before an incident happens: detection that surfaces incidents quickly, a materiality assessment process that lets you classify severity under pressure, and a response plan that includes the regulatory notification step, not just technical containment.

Run tabletop exercises against realistic scenarios. Rehearse the decision of whether an incident is material, because that judgement call, made at 2am during a live event, is what the whole obligation hinges on. Document who declares materiality, who drafts the APRA notification, and who signs it off. Plans that have never been exercised fail exactly when they are needed.

Best Practice 6: Extend CPS 234 to Third and Related Parties

One of the most misunderstood parts of CPS 234 is that it covers information assets managed by third parties. If you outsource IT, hosting, or software development, those providers are in scope. You need to evaluate the information security capability of the parties that manage your assets and gain assurance that their controls are adequate. That means contractual security requirements, the right to review or receive independent assurance, and a clear understanding of who does what during an incident. Taking a vendor's marketing claims at face value is not assurance.

How to Choose a CPS 234 Partner

If you bring in outside help, the questions that actually matter are simple. Does the partner understand APRA's expectations specifically, not just generic security? Will they give you evidence and remediation guidance rather than a pile of raw scanner output? Do they distinguish between what the standard requires and what is merely nice to have? And can they work with your board so accountability is real rather than performative?

At Atlant Security I run fixed-scope engagements led personally, drawing on more than 200 security assessments. The deliverable is a readiness report you can act on and show a regulator, not a sales funnel for tools you do not need. Whether you need a full readiness review, ongoing security leadership through a part-time CISO, or targeted testing, the goal is the same: controls that operate, and evidence that proves it.

Common CPS 234 Mistakes I See

  • Policy without operation. A documented control that nobody runs is a finding waiting to happen.
  • No asset classification. Without it, you cannot justify that controls are sized to criticality.
  • Self-tested controls. The same team implementing and assuring its own work undermines credibility.
  • Ignoring third parties. Outsourced does not mean out of scope.
  • Untested incident plans. The notification clock does not wait for you to figure out your process.

Frequently Asked Questions

Who does CPS 234 apply to?

CPS 234 applies to APRA-regulated entities, including authorised deposit-taking institutions, general and life insurers, private health insurers, and registrable superannuation entity licensees. It also reaches the information assets those entities manage through third parties and related parties.

What is the CPS 234 incident notification timeline?

Material information security incidents must be notified to APRA as soon as possible and generally within 72 hours. Material information security control weaknesses that cannot be remediated in a timely manner must be notified within 10 business days. Building the materiality assessment into your incident response process is essential to meeting these deadlines.

Does CPS 234 require a specific security framework?

No. CPS 234 is outcomes-based and does not mandate a particular framework. Many entities map their controls to ISO 27001 or the ACSC Essential Eight to demonstrate a structured approach, but the standard only requires that controls be sized to your threats and tested systematically. An ISO 27001 readiness effort often provides a useful backbone for CPS 234 evidence.

Can we outsource CPS 234 compliance to our IT provider?

You can outsource the operational work, but not the accountability. CPS 234 makes the board ultimately responsible for information security. Even where a third party manages your systems, you must gain assurance over their controls and remain answerable to APRA for the outcome.

How often should we test our controls?

Testing frequency should reflect how quickly your environment changes and how critical the assets are. Critical and internet-facing systems warrant more frequent and deeper testing than static internal systems. A single annual test is rarely sufficient to satisfy the systematic testing expectation.

What is the fastest way to find our CPS 234 gaps?

A focused gap assessment against the standard's clauses, combined with technical testing of your key systems, will surface the material issues quickly. If you want an outside view sized to APRA's expectations, get in touch and we can scope a readiness review.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

CPS 234 Compliance Best Practices (Australia) | Atlant Security