Back to Blog
Insights11 min read

How to Build a CPS 234 Compliance Program in Australia

A

Alexander Sverdlov

Security Analyst

7/20/2026
How to Build a CPS 234 Compliance Program in Australia

There is a version of CPS 234 compliance that is all binder and no defence: a policy set downloaded from a template, a risk register that has not changed in two years, and a board attestation signed on faith. It survives right up until an incident or an APRA review, and then it does not. Building a real CPS 234 program means building something that would actually hold under an attacker and under scrutiny. That is a different job, and this is how I approach it.

I am Alexander Sverdlov, founder of Atlant Security and a former Microsoft security consultant. Since 2013 I have run more than 200 security assessments across 14 countries, including for APRA-regulated entities. What follows is the program I build for a bank, insurer, or superannuation fund that has to comply with the Prudential Standard CPS 234 and wants the outcome to be genuine security, not a paperwork performance.

Start From the Standard, Not a Template

CPS 234 has applied to every APRA-regulated entity since 1 July 2019: authorised deposit-taking institutions, general and life insurers, private health insurers, and RSE (superannuation) licensees. It is deliberately principles-based. It does not hand you a control catalogue. It tells you the outcomes you must be able to demonstrate, and leaves the how to you. A program that copies another entity's controls without mapping them to your own assets and threats will have gaps exactly where your risk sits.

Read CPS 234 alongside the practice guide CPG 234, and build your program around its core obligations: clear roles and board accountability, information security capability commensurate with your threats, a policy framework, asset identification and classification, controls implementation, incident detection and response, systematic control testing, internal audit, and APRA notification within 72 hours of a material incident or 10 business days of a material control weakness you cannot promptly remediate.

One more thing to get right early: APRA is a prudential regulator. The exposure for getting this wrong is not a tidy fine, it is enforceable undertakings, additional capital requirements, licence conditions, intensified supervision, and the reputational damage of a public failure. Frame the program to the board in those terms, because that is what makes it a board priority.

Step 1: Fix Governance and Accountability First

CPS 234 puts ultimate accountability for information security on the board. A program that does not make that real is built on sand. Before any tooling, establish the human structure:

  • Define roles for the board, senior management, and the security function, with named individuals and real authority, not just an org chart box.

  • Give the board reporting that includes control test results and material risks, not only project status and a green dashboard. Oversight the board cannot exercise is not oversight.

  • Build a policy framework that is version-controlled, reviewed on a defined cycle, and mapped to the assets and threats it addresses.

If you do not have the seniority in-house to lead this, that is common and fixable. A virtual CISO or part-time CISO gives smaller entities genuine security leadership and satisfies the capability obligation without pretending a junior hire covers a board-level responsibility.

Step 2: Build a Living Information Asset Register

Every downstream obligation - classification, control selection, testing scope, incident response - depends on knowing what you have and where it is. The register is the foundation, and it is the thing most entities get wrong because they build it once and let it rot.

  • Identify information assets across on-premise, cloud, SaaS, and third-party systems. CPS 234 explicitly covers assets managed by related parties and service providers, including offshore administrators.

  • Classify each asset by criticality and sensitivity, and assign a real owner who is accountable for it.

  • Reconcile the register periodically against cloud billing, SSO application logs, and the CMDB so shadow IT surfaces before an auditor or an attacker finds it.

Step 3: Implement Controls Commensurate With Risk

CPS 234 requires controls commensurate with the criticality and sensitivity of the assets they protect. The word commensurate matters: over-controlling low-value systems while under-protecting the crown jewels is a common and expensive mistake. Concentrate effort where the regulated data lives.

  • Identity and access. Enforce MFA on every privileged and remote path, with phishing-resistant factors for administrators. Tight joiner-mover-leaver processes. Least privilege that is actually reviewed.

  • Vulnerability and patch management. Continuous scanning tied to the asset register, with remediation SLAs by severity that you can evidence, not just assert.

  • Segmentation. Separate critical systems from the general corporate network so one compromised laptop does not reach the core.

  • Logging and detection. Critical systems feeding a SIEM, with alerts someone would actually see and act on out of hours.

For most entities the ACSC Essential Eight is a sensible baseline to build on, because it maps well to the threats Australian organisations actually face. Our guide to the ACSC Essential Eight covers how to use it as a control foundation under CPS 234.

Step 4: Build Incident Response Around the APRA Clock

The two notification obligations - 72 hours for a material incident, 10 business days for a material control weakness - are where programs fail under pressure. The failure is almost never technical. It is that nobody decided the incident was material in time, and nobody was clearly authorised to start the clock.

  • Pre-define materiality thresholds so the "is this reportable" question is answered before an incident, not during one.

  • Name the person authorised to notify APRA and make sure they know the reporting channel.

  • Write response plans that name real people, account for third parties who hold your data, and loop in legal and communications on the same timeline.

  • Rehearse with tabletop exercises at least annually, ideally with a scenario built around your own critical systems.

For a deeper treatment specific to this standard, see our guide to CPS 234 incident response best practices.

Step 5: Test Control Effectiveness Systematically

A control you have never tested is a hypothesis. CPS 234 requires a systematic testing program that evaluates control effectiveness and escalates results to the board and senior management. Build testing into the program from day one:

  • Schedule vulnerability assessments for breadth and penetration testing for depth, so you learn whether controls stop a capable attacker rather than whether they exist on paper.

  • Test more frequently after material changes to systems, threats, or third parties.

  • Track remediation to closure and report the results upward, because untracked findings are how the same weakness shows up in three consecutive reviews.

Step 6: Make Internal Audit Independent and Competent

CPS 234 requires internal audit to review the design and operating effectiveness of information security controls, including those of third parties. Two conditions make this real: the reviewers must be independent of the people who built and run the controls, and they must have genuine security competence. A generalist auditor with a checklist will miss the findings that matter. Co-sourcing to specialists is expected practice and is contemplated by CPG 234.

A Program Build Sequence That Works

Phase

Focus

CPS 234 obligation addressed

1. Foundation

Governance, roles, board reporting, policy framework

Roles and responsibilities, policy framework

2. Visibility

Living asset register, classification, third-party mapping

Asset identification and classification

3. Protection

Identity, patching, segmentation, logging

Controls implementation

4. Response

IR plans, materiality thresholds, APRA notification drill

Incident management, notification

5. Assurance

Systematic testing, pen testing, independent internal audit

Testing effectiveness, internal audit

Mistakes That Turn a Program Into Theatre

  • Buying tools before defining the program. A SIEM nobody watches and an MFA rollout that skips admin accounts add cost, not assurance.

  • Ignoring third and fourth parties. Your obligations follow your data. A critical vendor breach is your incident.

  • Static documentation. A register and risk assessment that never change signal that the program is not being run.

  • Building CPS 234 in isolation. CPS 230 (operational risk management, effective 1 July 2025) raises expectations on operational resilience and third-party risk. Design the two together so you assess each critical vendor once, not twice.

If budgeting is your next question, our breakdown of CPS 234 compliance cost sets realistic expectations for entities of different sizes.

Frequently Asked Questions

How long does it take to build a CPS 234 compliance program?

A credible program for a mid-sized entity typically takes three to six months to stand up the foundations, with control maturity and testing continuing beyond that. Anyone promising full compliance in a few weeks is selling documentation, not security.

Do we need a full-time CISO to comply with CPS 234?

Not necessarily. CPS 234 requires capability commensurate with your size and threat exposure. Many smaller insurers and RSE licensees meet the leadership and capability obligation with a fractional or virtual CISO supported by specialist assessors, which is a recognised and defensible model.

Where should a new program start?

With governance and the asset register. You cannot select controls, scope testing, or run incident response without knowing who is accountable and what assets you are protecting. Tooling comes after that foundation, not before.

Are cloud and outsourced providers covered by our CPS 234 program?

Yes. The standard extends to information assets managed by related parties and third parties, including offshore. Your program must identify those assets, assess the controls protecting them, and include them in testing and internal audit.

How does CPS 234 relate to CPS 230?

CPS 234 governs information security specifically, while CPS 230 (effective 1 July 2025) covers operational risk management, business continuity, and service provider management more broadly. They overlap heavily on third-party risk, so build them as one coordinated program rather than two parallel projects.

Build It So It Holds

A CPS 234 program is only worth the effort if it would survive both an attacker and an APRA review. If you are starting from a template and want to build something real - or want an independent read on the program you already have - we help APRA-regulated entities design and test CPS 234 programs that stand up under pressure. Talk to Atlant Security about scoping yours.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.