Back to Blog
Insights10 min read

Steps to Implement CPS 234 Cybersecurity Requirements for Australian Financial Firms

A

Alexander Sverdlov

Security Analyst

7/20/2026
Steps to Implement CPS 234 Cybersecurity Requirements for Australian Financial Firms

CPS 234 is not a framework you adopt because it looks good in a sales deck. It is a binding prudential standard that APRA has enforced since 1 July 2019, and if you are an APRA-regulated entity, a bank, credit union, general or life insurer, private health insurer, or superannuation trustee, you are already required to comply. The question is never whether to implement it. The question is how to implement it so that it holds up under APRA scrutiny, survives a real incident, and does not consume more of your team than it needs to.

I have run security assessments and compliance programmes across 14 countries since 2013, and the mistakes I see with CPS 234 are almost always the same: treating it as a documentation exercise, bolting controls on without testing them, and forgetting that the standard reaches into your third-party providers. This is a practical, step-by-step guide to implementing CPS 234 properly, written for the CEO, CTO, or risk lead who has to make it actually happen.

What CPS 234 actually requires

Before the steps, be clear on what the standard demands. CPS 234's objective is that an APRA-regulated entity maintains an information security capability commensurate with the size and extent of the threats to its information assets. Stripped to its core obligations, that means:

What this guide covers: What CPS 234 actually requires, Step 1: Establish governance and accountability, Step 2: Classify your informa
  • Clear roles and responsibilities. The board is ultimately accountable for information security. Roles must be defined across the board, senior management, governing bodies, and individuals.
  • Information security capability maintained in line with the size and nature of threats, and kept current as technology and threats evolve.
  • A defined information security policy framework commensurate with your exposures.
  • Classification of information assets by criticality and sensitivity, including those managed by third parties.
  • Implementation of controls to protect information assets, plus timely detection and response.
  • Systematic testing of control effectiveness, with the testing programme itself reviewed.
  • Internal audit review of the design and operating effectiveness of information security controls.
  • Mandatory notification to APRA: within 72 hours of a material information security incident, and within 10 business days of identifying a material information security control weakness that cannot be remediated in a timely manner.

Notice what is not on that list: dollar figures, specific products, or a checklist of tools. CPS 234 is deliberately outcome-based. That is a feature, not a gap, and it is why lifting someone else's control list wholesale rarely satisfies an APRA reviewer. Your controls have to match your threats.

Step 1: Establish governance and accountability

Governance is where CPS 234 starts, because the standard makes the board ultimately accountable. That accountability cannot be delegated away. In practice, implementation here means:

  • Documenting who owns information security at board level, at senior management level, and operationally. Vague ownership is the single most common finding I see.
  • Ensuring the board receives information security reporting it can actually understand and challenge, not a wall of green traffic lights.
  • Defining a policy framework that covers access control, data protection, change management, incident response, and third-party management, and that is proportionate to your size and risk.
  • Setting a cadence, quarterly is sensible, for reviewing the framework as threats and systems change.

If your organisation lacks a full-time security leader, this is exactly where a fintech virtual CISO or part-time CISO earns their keep. APRA expects an accountable, competent person driving the programme. An experienced external CISO can fill that role and report to the board without the cost of a full-time hire.

Step 2: Classify your information assets, including those held by third parties

You cannot protect what you have not identified. CPS 234 explicitly requires you to classify information assets by criticality and sensitivity, and it extends that obligation to assets managed by related parties and third parties. This is the step most firms underinvest in, and it is the step that makes every later control decision defensible.

Checklist: Step 1: Establish governance and accountability
  1. Build an inventory of information assets: customer data, core banking or policy systems, authentication systems, backups, and the platforms your business runs on.
  2. Classify each by how sensitive it is and how critical it is to operations.
  3. Map which assets live with third parties, cloud providers, SaaS platforms, outsourced processors, and note who is responsible for securing each.
  4. Use the classification to drive where you concentrate controls. Not everything deserves the same protection, and pretending it does wastes budget.

The third-party dimension is where CPS 234 catches people out. A material chunk of your information assets probably sits outside your walls. APRA still holds you accountable for them, so your vendor assessments and contracts have to reflect that.

Step 3: Implement controls proportionate to your threats

Only after classification does control implementation make sense. CPS 234 requires controls to protect information assets and to enable timely detection of, and response to, incidents. The controls that matter for almost every regulated entity include:

  • Strong identity and access management, including multi-factor authentication and least-privilege access, reviewed regularly.
  • Encryption of sensitive data in transit and at rest.
  • Timely patching and vulnerability management, so known weaknesses do not linger.
  • Logging, monitoring, and alerting capable of detecting an incident quickly rather than months later.
  • Endpoint and network protection appropriate to your environment.
  • Hardened configurations across cloud and on-premise systems.

The word that governs all of this is "commensurate." A small mutual with a handful of systems does not need the control stack of a major bank, and a reviewer will expect your controls to be justified by your risk, not copied from a larger peer. A structured IT security audit is the fastest way to see, honestly, where your current controls stand against the threats you actually face. If your infrastructure runs on public cloud, our cloud security consulting work focuses on exactly the misconfigurations that turn into APRA-reportable weaknesses.

Step 4: Test your controls, and test your testing

This is the step that separates real compliance from paperwork. CPS 234 requires you to test the effectiveness of your controls through a systematic testing programme, and it requires that the testing programme itself be reviewed for adequacy. A policy that says you have MFA is worthless if nobody has verified that MFA is actually enforced everywhere it should be.

Checklist: Step 2: Classify your information assets, including those held by third parties
  • Run regular penetration testing against your externally exposed and internally critical systems. Real attacker simulation finds the gaps that scanners miss.
  • Maintain ongoing vulnerability assessment so new weaknesses surface between deeper tests.
  • Test detection and response, not just prevention. Can your team actually see an incident and act on it within a timeframe you would be comfortable defending to APRA?
  • Adjust the frequency and depth of testing to the sensitivity of the assets and the rate at which your systems change. Static annual testing on a rapidly changing platform is not "systematic."

Document every test, its findings, and how you remediated them. That documentation is what internal audit and APRA will want to see.

Step 5: Build and rehearse incident response, including APRA notification

CPS 234's notification obligations are specific and time-bound, and they are frequently the part firms fail on under pressure. You must notify APRA:

  • Within 72 hours of becoming aware of a material information security incident, defined broadly enough to include incidents that have materially affected, or had the potential to materially affect, the entity or its depositors, policyholders, or members.
  • Within 10 business days of identifying a material information security control weakness that you cannot remediate in a timely manner.

Meeting those windows is impossible if your incident response plan lives in a document nobody has opened. Build a plan that names decision-makers, defines what "material" means for your business, and includes the APRA notification path explicitly. Then rehearse it with tabletop exercises simulating ransomware, credential compromise, and third-party breaches. The goal is that when a real incident hits, the 72-hour clock is something you manage calmly, not a deadline you discover you have already missed.

Step 6: Internal audit review

CPS 234 requires that internal audit reviews the design and operating effectiveness of your information security controls, including those maintained by third parties. This is an independence requirement: the people who built the controls should not be the only ones assessing them.

14 countries: I have run security assessments and compliance programmes across 14 countries since 2013
  • Schedule internal audit reviews on a defined cycle, not only when APRA comes knocking.
  • Ensure reviewers have genuine information security competence, or bring in an independent assessor if internal audit lacks the depth.
  • Feed findings back into the control and testing programme so the cycle actually improves your posture rather than just recording gaps.

Implementation at a glance

StepCPS 234 obligation it satisfiesMost common failure
Governance and accountabilityBoard-level responsibility, policy frameworkOwnership undefined or delegated away from the board
Asset classificationIdentify and classify assets, including third-partyThird-party assets left out of scope
Control implementationControls commensurate with threatsControls copied from a larger peer, not justified by risk
TestingSystematic testing of control effectivenessDocumentation exists but controls never verified
Incident response and notification72-hour and 10-day APRA notificationPlan not rehearsed, deadlines missed under pressure
Internal auditIndependent review of control effectivenessReviewers lack security competence

How CPS 234 relates to CPS 230 and other standards

CPS 234 does not sit alone. APRA's CPS 230 on operational risk management came into effect on 1 July 2025 and raises the bar on operational resilience and third-party risk, overlapping meaningfully with CPS 234's information security requirements. If you handle personal information you are also subject to the Privacy Act and the Notifiable Data Breaches scheme, and many regulated entities pursue ISO 27001 as a way to structure the underlying controls. The efficient path is to build one control set and map it across all of these obligations rather than running parallel programmes. Our ISO 27001 readiness work is frequently combined with CPS 234 implementation for exactly this reason.

72 hours: You must notify APRA within 72 hours of becoming aware of a material information security incident

Getting it done

CPS 234 rewards organisations that treat it as a genuine security programme and punishes those that treat it as a compliance checkbox, because the difference shows the moment a real incident occurs or an APRA reviewer asks to see your test results. If you want an experienced hand to run the implementation, from governance through testing to APRA-ready documentation, that is the core of our virtual CISO service. I have personally led over 200 assessments, and I would rather help you build something that holds up than sell you a binder that does not. Book a call and we will scope a CPS 234 programme that fits your size and risk.

Frequently Asked Questions

Who has to comply with CPS 234?

All APRA-regulated entities: authorised deposit-taking institutions such as banks and credit unions, general and life insurers, private health insurers, and registrable superannuation entity licensees. It has been in force since 1 July 2019 and is a binding prudential standard, not an optional framework.

What CPS 234 actually requires - key points

What are the CPS 234 incident notification timeframes?

You must notify APRA within 72 hours of becoming aware of a material information security incident, and within 10 business days of identifying a material information security control weakness that you cannot remediate in a timely manner. Rehearsing your incident response plan is the only reliable way to meet the 72-hour window.

Does CPS 234 cover third-party and cloud providers?

Yes. The standard explicitly requires you to classify and protect information assets managed by related parties and third parties, and internal audit must review the effectiveness of controls maintained by those providers. A large share of your regulated information assets probably sits outside your own walls, and APRA still holds you accountable for them.

How long does CPS 234 implementation take?

It depends on your starting point. An entity with mature IT controls may need a few months to formalise governance, testing, and documentation. One starting from informal controls should expect a longer programme. Because CPS 234 has been mandatory since 2019, most firms are refining and evidencing rather than starting from zero.

Do we need a CISO to comply with CPS 234?

You need clear, competent accountability for information security, with the board ultimately responsible. That does not require a full-time CISO. Many smaller regulated entities meet the expectation with a part-time or virtual CISO who drives the programme and reports to the board.

How does CPS 234 differ from CPS 230?

CPS 234 is specifically about information security. CPS 230, effective from 1 July 2025, is about operational risk management and resilience more broadly, including service provider management. They overlap on third-party risk and controls, so it is efficient to align both under one programme rather than treating them separately.

Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.