How to Hire a CPS 234 Compliance Consultant in Australia
Alexander Sverdlov
Security Analyst

Hiring a CPS 234 consultant is one of those decisions where the wrong choice costs you twice: once in fees, and again when your APRA assessment surfaces the gaps the consultant was supposed to close. I have spent more than a decade running security assessments for regulated and unregulated organisations across 14 countries, and I have been brought in more than once to clean up after a compliance engagement that produced a thick binder and very little actual security. This is a practical guide to hiring well: what a good CPS 234 consultant does, how to tell competence from theatre, what it should cost, and the questions that separate the two.
Why the Right Consultant Matters for CPS 234
CPS 234, APRA's Prudential Standard on Information Security, has applied to APRA-regulated entities since 1 July 2019. It covers authorised deposit-taking institutions, general and life insurers, private health insurers, and superannuation licensees, and it reaches the information assets held by their third parties. The standard is principles-based, not a checklist, which is precisely why the quality of your consultant matters so much. There is no template that turns you compliant. Someone has to exercise judgement about what "commensurate with the threat" means for your specific systems, and be able to defend that judgement to an auditor.
A strong consultant does three things a weak one cannot: they interpret the standard for your context, they build controls and evidence that survive scrutiny, and they leave your team able to maintain compliance after they walk out the door. A weak one hands you a gap report you cannot act on and a set of policies nobody follows.
What a CPS 234 Consultant Should Actually Do
Before you compare candidates, be clear on the scope of work a competent engagement covers. The main components are:
Gap assessment against the standard. A structured review of your controls, governance, and evidence versus each CPS 234 requirement, with residual risk stated plainly.
Information asset classification. Identifying and classifying your information assets, including those managed by related parties and third parties, by criticality and sensitivity.
Control design and remediation planning. A prioritised roadmap with owners and dates, not a wish list.
Governance and board reporting. Helping define roles, risk appetite, and the reporting that proves board engagement.
Testing and assurance. Establishing a systematic control-testing programme, and often running technical testing such as vulnerability assessment or penetration testing to prove controls resist attack.
Incident notification readiness. Making sure you can meet APRA's 72-hour material-incident notification and the 10-business-day control-weakness notification.
Evidence assembly. Building the evidence pack your internal or external auditor will actually review.
Notice how much of this is judgement and communication rather than tool operation. That is the skill you are hiring for.
The Skills That Actually Matter
When I assess whether someone can do this work, I look for a specific mix:
Genuine CPS 234 and CPG 234 fluency. Not general "cyber compliance," but the specific standard and its practice guide, and how APRA thinks about materiality and assurance.
Hands-on technical depth. Someone who can look at your cloud configuration, identity setup, and network segmentation and tell you whether the control is real. Compliance-only consultants who cannot read a system architecture will miss the gaps that matter.
Evidence discipline. The ability to turn "we do MFA" into a documented, testable, auditable control.
Board-level communication. They will have to brief directors and stand in front of an auditor. If they cannot explain risk without jargon, they will not carry the governance requirements.
Knowledge transfer. A good consultant makes your team more capable. A bad one makes you dependent.
In-House, Consultant, or Virtual CISO?
Hiring a consultant is not the only model, and it is worth choosing deliberately.
Model | Best for | Watch out for |
|---|---|---|
Project consultant | A defined gap assessment and remediation push toward a specific assessment | Work ends when the invoice is paid; maintenance falls back on you |
Virtual / part-time CISO | Ongoing leadership, board reporting, and sustained compliance without a full-time hire | Needs enough allocated time to be more than a figurehead |
Full-time internal hire | Large entities with continuous, complex obligations | Cost and the difficulty of finding CPS 234-experienced talent |
For many mid-sized regulated entities the sweet spot is a project consultant to get through the gap and remediation phase, then a virtual CISO or part-time CISO to keep the programme alive between assessments. CPS 234 is not a one-off event; the testing and assurance obligations continue, so plan for who owns them after the project ends. Fintech and payments businesses, which carry heavy third-party and cloud exposure, often benefit from a fintech-focused virtual CISO who already understands that risk profile.
What CPS 234 Consulting Should Cost
I will not quote you invented dollar figures, because credible pricing depends entirely on your size, the complexity of your environment, and the state of your existing controls. What I can give you is how to think about it so you can judge a quote as reasonable or not.
Cost is driven by:
Scope. A gap assessment alone is a fraction of a full remediation and evidence programme.
Environment complexity. Multiple cloud tenancies, legacy on-prem systems, and a long list of third parties all add effort.
Current maturity. If your controls and documentation are already decent, you are paying to validate and fill gaps. If you are starting near zero, you are paying to build.
Technical testing. Vulnerability assessment and penetration testing are usually separate line items, priced by scope.
Insist on a fixed scope of work and clear deliverables before you sign. The most expensive consultant is the cheap one whose work does not survive the assessment and has to be redone. Be especially wary of a flat fixed fee quoted before anyone has looked at your environment; that usually means the scope is being guessed, and guessed scope leads to change orders or corners cut. A short, paid scoping exercise up front nearly always pays for itself.
Questions to Ask Before You Sign
These are the questions I would ask if I were hiring on the other side of the table. The answers tell you more than any brochure.
Have you delivered CPS 234 specifically, not just generic compliance? Ask them to describe the shape of the work without breaching confidentiality. Vague answers are a warning sign.
Who actually does the work? Sometimes a senior name wins the deal and a junior does the delivery. Confirm who is on your engagement.
How do you handle third-party and cloud assets? This is where most entities lose points, so the answer needs to be specific.
What evidence will I be left with? You want an evidence pack mapped to requirements, not just a slide deck.
Will my team be able to maintain this? Ask how they transfer knowledge and what ongoing support looks like.
How do you approach the 72-hour notification obligation? A good consultant will talk about materiality criteria, decision ownership, and rehearsal, not just a policy document.
If you want to sanity-check a consultant's technical claims, an independent IT security audit or a scoped penetration test from a separate provider is a reasonable cross-check. Independence between whoever builds your controls and whoever tests them is healthy, not paranoid.
Red Flags to Walk Away From
Over the years I have learned to spot the patterns that predict a disappointing engagement:
Guaranteed outcomes. No honest consultant guarantees you will pass. They can materially improve your odds and your security; certainty is a sales tactic.
Compliance without technical validation. If nobody looks at your actual systems and only reviews documents, the controls are unverified.
Templates presented as tailored work. A generic policy set with your logo dropped in is not a CPS 234 programme.
No plan for the day after. If the engagement has no answer for who maintains compliance afterward, you are buying a temporary fix.
Fixed price before scoping. As above, this signals guessed effort.
Frequently Asked Questions
Do I legally need a consultant for CPS 234?
No. CPS 234 does not require you to hire anyone. Entities with capable internal security leadership can prepare in-house. A consultant is worth it when you lack the specific expertise, want an independent view before your auditor forms one, or need to move faster than your internal capacity allows.
What is the difference between a CPS 234 consultant and a virtual CISO?
A project consultant is typically engaged for a defined piece of work, such as a gap assessment and remediation, and the relationship ends when the project does. A virtual or part-time CISO provides ongoing security leadership, board reporting, and sustained compliance management. Many entities use a consultant to get compliant and a virtual CISO to stay that way.
How do I verify a consultant really knows CPS 234?
Ask them to walk you through how they would handle a tricky requirement, such as classifying third-party information assets or making the materiality call for the 72-hour notification. Genuine experience shows in specifics. Also confirm who does the actual delivery, and ask for references you can speak to directly.
Should the same firm build and test my controls?
There is value in independence. A consultant can build your controls and prepare your evidence, but having technical testing such as penetration testing done by a separate party gives you and your auditor more confidence that the controls actually work. It also avoids the conflict of a firm grading its own homework.
How long does a CPS 234 engagement take?
A gap assessment can take a few weeks. A full programme through remediation, testing, and evidence assembly typically runs three to six months depending on your starting maturity and the complexity of your environment. Ongoing maintenance is continuous, because the testing and assurance obligations do not stop.
Can a smaller regulated entity afford good CPS 234 support?
Yes, by scoping tightly. A focused gap assessment plus a part-time virtual CISO arrangement gives smaller entities senior expertise without the cost of a full-time hire or an open-ended project. The key is matching the model to your actual risk and size rather than buying the largest package on offer.
Hire for Judgement, Not for a Binder
The best CPS 234 consultants make your organisation genuinely more secure and leave your team able to hold the line without them. They interpret the standard for your context, validate controls against real systems, build evidence that survives an auditor, and are honest about what they can and cannot guarantee. Hire for that, and the fee is an investment. Hire for a reassuring binder, and you will pay for the work twice.
Atlant Security provides CPS 234 gap assessments, remediation support, and ongoing virtual CISO leadership for APRA-regulated entities, with the technical depth to validate controls rather than just document them. Contact us to discuss what your organisation actually needs before you commit to a scope.

Alexander Sverdlov
Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.