Key Steps to Achieve CPS 234 Compliance in Australia
Alexander Sverdlov
Security Analyst

CPS 234 is APRA's information security prudential standard, and it applies to the entities APRA regulates: banks and other authorised deposit-taking institutions, general and life insurers, private health insurers, and superannuation trustees. If you are a regulated entity, or a service provider to one, CPS 234 is not optional and it is not a checkbox. It sets out obligations your board is accountable for, and APRA has been explicit that it expects boards to treat information security as a core business risk.
I have run security assessments and readiness programs across regulated financial services, and the pattern with CPS 234 is consistent: the standard itself is short and readable, but the evidence and testing it demands catch teams off guard. This guide walks through what the standard actually requires and the concrete steps to meet it, without the marketing gloss.
What CPS 234 Requires
CPS 234 came into force on 1 July 2019. Its objective is to ensure regulated entities maintain information security capability commensurate with the threats they face. The standard is built around a handful of core obligations:
- Board accountability: the board is ultimately responsible for the entity's information security.
- Clear roles and responsibilities: information security roles must be defined for the board, senior management, governing bodies, and individuals.
- Information security capability: capability must be sized to the threats, the criticality and sensitivity of assets, and the entity's size and complexity.
- Policy framework: a documented information security policy framework that supports secure operation.
- Asset identification and classification: information assets, including those managed by third parties, must be classified by criticality and sensitivity.
- Controls: implement controls to protect assets, and test their effectiveness through a systematic program.
- Incident management: mechanisms to detect and respond to incidents in a timely way.
- Testing: regular, systematic testing of control effectiveness, with results reviewed by appropriately skilled people.
- Internal audit: assurance over the design and operating effectiveness of controls, including those maintained by related parties and third parties.
- APRA notification: notify APRA within 72 hours of a material information security incident, and within 10 business days of identifying a material control weakness you cannot remediate in a timely way.
Those notification timeframes are hard obligations. The 72-hour incident window in particular is where I see entities scramble, because they have no pre-agreed definition of "material" and no runbook for who decides and who files.
Step 1: Establish Board Accountability and Clear Roles
CPS 234 makes the board accountable, so start there. The board does not need to run security operations, but it must be able to demonstrate oversight: regular reporting on the security posture, informed decisions on risk appetite, and a clear line of responsibility down to the people who operate controls.
Concrete actions:
- Document who holds information security responsibilities at each level, from board to operational staff.
- Define and formally approve the entity's information security risk appetite.
- Establish a regular reporting cadence so the board sees posture, incidents, and testing results, not just green dashboards.
- Ensure whoever advises the board on security is genuinely qualified to do so.
Many mid-sized regulated entities lack a full-time security executive to own this. A fintech virtual CISO or virtual CISO can hold that accountability layer and produce board-ready reporting without the cost of a permanent chief information security officer.
Step 2: Identify and Classify Your Information Assets
You cannot protect what you have not catalogued, and CPS 234 explicitly requires classification by criticality and sensitivity. This includes assets managed by third parties, which is the part most teams underestimate. If a service provider hosts or processes your regulated data, those assets are in scope.
Build an inventory that records, for each asset: what it is, where it lives, who owns it, its criticality (impact if unavailable), and its sensitivity (impact if disclosed). This inventory drives everything downstream. Controls are sized to asset classification, testing frequency follows criticality, and incident materiality is judged against the assets affected.
Step 3: Implement Controls Sized to the Threat
CPS 234 does not prescribe a specific control list. It requires controls commensurate with the threats and the classification of your assets. In practice, regulated financial entities are expected to have a mature baseline:
- Strong identity and access management, with multi-factor authentication on privileged and remote access.
- Least-privilege access with documented joiner, mover, and leaver processes.
- Encryption of sensitive data in transit and at rest.
- Network segmentation between corporate, production, and sensitive environments.
- Timely vulnerability management and patching, prioritised by risk.
- Logging, monitoring, and alerting sufficient to detect security incidents.
- Hardened configuration of systems and cloud services.
- Secure management of the software development and change lifecycle.
A control baseline is only credible if you know it is actually in place. An independent IT security audit or penetration test gives you evidence of where controls hold and where they do not, which is precisely what APRA and your internal audit function will want to see.
Step 4: Manage Third-Party and Related-Party Risk
CPS 234 extends your obligations to information assets managed by others. If a vendor holds your data, you remain accountable for its security. This is reinforced by APRA's broader outsourcing and operational risk standards, so third-party governance sits at the centre of compliance, not the edge.
Steps that hold up under scrutiny:
- Maintain a register of third parties that handle your information assets, with the classification of the data involved.
- Obtain assurance over their controls: independent reports, certifications, or your own right-to-audit.
- Ensure contracts require the provider to notify you of incidents fast enough that you can meet your own 72-hour obligation to APRA.
- Include material third-party controls in your testing and internal audit scope.
Step 5: Build Incident Detection and the 72-Hour Response
The notification clock is the sharpest edge of CPS 234. To meet a 72-hour window, you need the machinery in place before anything happens, not assembled during a crisis. That means:
- A pre-agreed definition of what makes an incident "material" for your entity, so nobody is debating it at 2am.
- Detection and alerting good enough to know an incident is underway in the first place.
- A response plan naming who leads, who decides on notification, and who files with APRA.
- Contact details and the notification process documented and accessible.
- Rehearsals. Run a tabletop exercise against a realistic scenario and time yourselves against the 72-hour target.
The 10-business-day obligation for material control weaknesses is easy to forget. If you identify a weakness you cannot remediate promptly, that itself is notifiable. Build the trigger into your risk management process so it is not missed.
Step 6: Test Control Effectiveness Systematically
CPS 234 requires a systematic testing program, with frequency driven by how quickly the threat and control environment changes, and by asset criticality. Testing must be conducted by people with appropriate skills and independence, and material weaknesses must be remediated.
A defensible testing program blends several methods:
- Regular vulnerability assessment across your estate.
- Periodic penetration testing of critical and internet-facing systems.
- Configuration and control reviews of key platforms, including cloud.
- Review of third-party control effectiveness for material providers.
The output that matters is not the test itself but the loop: findings tracked, prioritised, remediated, and re-tested, with results visible to the people accountable. A one-off scan with no follow-through will not satisfy the standard. A structured vulnerability assessment program gives you that recurring cadence rather than a single snapshot.
Step 7: Provide Internal Audit Assurance
Internal audit must review the design and operating effectiveness of your information security controls, including those maintained by third and related parties. This is an independent line of assurance separate from the operational testing in Step 6. For smaller entities without a mature internal audit function, this often means engaging external specialists to provide that independent view.
CPS 234 Obligations Summary
| Obligation | What It Means in Practice | Timeframe |
|---|---|---|
| Board accountability | Documented oversight, approved risk appetite, regular reporting | Ongoing |
| Asset classification | Inventory of assets by criticality and sensitivity, including third-party held | Maintained continuously |
| Control testing | Systematic program by skilled, independent testers | Frequency scaled to risk |
| Internal audit | Independent assurance over control design and operation | Periodic |
| Incident notification | Notify APRA of a material incident | Within 72 hours |
| Control weakness notification | Notify APRA of a material weakness you cannot promptly fix | Within 10 business days |
Where Programs Fall Down
- No materiality definition: without an agreed threshold, the 72-hour clock becomes an argument instead of an action.
- Third parties out of scope: forgetting that vendor-held assets and their controls fall under your obligations.
- Testing without remediation: producing reports nobody acts on, which the standard does not accept.
- Board reporting theatre: dashboards that show only good news and hide real posture.
- Stale asset inventory: a classification exercise done once and never updated.
If your systems run in the cloud, a cloud security review is one of the highest-value steps you can take, because misconfigured cloud services are a leading cause of the exact control weaknesses CPS 234 asks you to detect and report.
Frequently Asked Questions
Who does CPS 234 apply to?
CPS 234 applies to APRA-regulated entities: authorised deposit-taking institutions such as banks, general and life insurers, private health insurers, and superannuation trustees. It also reaches the information assets and controls managed on their behalf by third parties, so service providers to these entities are affected in practice.
What is the 72-hour notification rule?
Regulated entities must notify APRA within 72 hours of becoming aware of a material information security incident. Separately, they must notify APRA within 10 business days of identifying a material information security control weakness they cannot remediate in a timely manner. Both timeframes require pre-built processes to meet reliably.
Does CPS 234 prescribe specific security controls?
No. CPS 234 is outcome-focused. It requires controls commensurate with the threats you face and the criticality and sensitivity of your assets, rather than a fixed checklist. In practice, regulated financial entities are expected to maintain a mature baseline covering access control, encryption, monitoring, patching, and segmentation.
How often do we need to test controls?
The standard requires systematic testing at a frequency driven by the rate of change in your threat and control environment and by asset criticality. There is no single mandated interval. Critical and internet-facing systems typically warrant more frequent testing, supported by ongoing vulnerability assessment and periodic penetration testing.
Are third-party providers covered by CPS 234?
Yes. Your obligations extend to information assets managed by third and related parties. You remain accountable for the security of your data even when a vendor holds it, so you need assurance over their controls, incident notification terms in contracts, and their inclusion in your testing and internal audit scope.
What happens if we do not comply?
CPS 234 is an enforceable prudential standard. APRA can take supervisory and enforcement action against non-compliant entities, and boards are held accountable. Beyond regulatory consequences, weak information security exposes the entity to breaches, operational disruption, and reputational damage with customers and members.
Need to close the gap to CPS 234? Atlant Security helps regulated financial entities assess controls, run systematic testing, and build the incident and reporting machinery the standard demands, led personally by a former Microsoft security consultant with 200+ assessments across 14 countries. Explore our fintech vCISO service or book a strategy call for a fixed-price proposal.

Alexander Sverdlov
Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.