All insights
APRA & Financial Services June 4, 2026 6 min read

APRA CPS 234 Explained: Cyber Obligations for Regulated Entities

APRA’s Prudential Standard CPS 234 Information Security has been in force since 1 July 2019 and remains the cornerstone of cyber regulation for Australia’s financial sector. It applies to authorised deposit-taking institutions, insurers and superannuation trustees, and it is deliberately principles-based: rather than prescribing technologies, it sets outcomes that boards and management must achieve and be able to evidence.

This guide explains the core obligations of CPS 234 in plain terms, where regulated entities commonly fall short, and the practical steps that demonstrate genuine compliance rather than paperwork. The aim is a security posture that holds up under both an APRA review and a real attack.

What CPS 234 actually requires

The standard’s stated objective is to ensure that an APRA-regulated entity maintains an information security capability commensurate with the size and extent of threats to its information assets, so it can remain resilient against information security incidents. In practice, CPS 234 imposes a set of interlocking obligations.

  • Roles and responsibilities – the board has ultimate responsibility for information security. Roles and responsibilities of the board, senior management, governing bodies and individuals must be clearly defined.
  • Information security capability – the entity must maintain a capability commensurate with the threats it faces, including the capability of any related parties or third parties that manage its information assets.
  • Policy framework – an information security policy framework commensurate with exposures and vulnerabilities must be maintained.
  • Asset classification – information assets must be classified by criticality and sensitivity, which then drives the strength of controls applied.
  • Controls – controls must be implemented to protect information assets, and they must be tested for effectiveness through a systematic programme.
  • Incident management – the entity must have robust mechanisms to detect and respond to incidents in a timely manner.
  • Internal audit – internal audit must review the design and operating effectiveness of information security controls, including those maintained by third parties.
  • Notification – material incidents and control weaknesses must be reported to APRA within defined timeframes.

Information asset classification: the foundation

Everything in CPS 234 flows from knowing what you hold and how much it matters. The standard requires entities to classify information assets – including those managed by third parties – by criticality and sensitivity. This is not a one-off mapping exercise. Classification should be a maintained register that records what the asset is, where it lives, who owns it, who has access, and what controls protect it.

Where this commonly breaks down is shadow IT, ageing systems and the long tail of SaaS tools that business units adopt without registering. An asset you have not classified is an asset you cannot protect proportionately. A disciplined classification process, refreshed at least annually and on material change, is the single most useful piece of evidence you can put in front of an APRA reviewer. Our guide to APRA CPS 234 services covers how to stand this up quickly.

Controls and control testing

CPS 234 requires controls commensurate with the criticality and sensitivity of the asset, the stage at which assets are within their life cycle, and the potential consequences of an incident. Crucially, it requires those controls to be tested. APRA expects a documented, risk-based testing programme that specifies the nature and frequency of testing and that escalates results.

Testing is where many entities under-invest. Penetration testing once a year on a single application is not a programme. A credible approach blends vulnerability scanning, configuration reviews, control self-assessment, red-team exercises and independent penetration testing, with frequency scaled to asset criticality. The ASD Essential Eight provides a practical, measurable baseline of technical controls that maps neatly to CPS 234 expectations, and maturity-level scoring gives you a defensible metric to report to the board.

Two failure modes recur. First, testing that is never independently validated – CPS 234 explicitly requires internal audit to review the design and operating effectiveness of controls. Second, findings that are logged but never remediated. Unremediated material weaknesses are themselves notifiable to APRA, so a closed-loop remediation tracker is essential.

Incident detection, response and the 72-hour clock

CPS 234 requires mechanisms to detect and respond to incidents in a timely manner, and it sets hard notification deadlines. An entity must notify APRA as soon as possible and no later than 72 hours after becoming aware of an information security incident that materially affected, or had the potential to materially affect, the entity or the interests of its depositors, policyholders or beneficiaries. Separately, material information security control weaknesses that cannot be remediated in a timely manner must be notified within 10 business days.

The 72-hour clock starts at awareness, not at confirmation of impact, so the practical challenge is making a notification call early and on incomplete information. This is one reason a tested incident response plan matters: it pre-defines who decides, who notifies APRA, and how parallel obligations – such as the Notifiable Data Breaches scheme administered by the OAIC – are handled. Our guidance on building an incident response plan and on mandatory data breach notification walks through how to align these timelines so one event does not trigger conflicting workflows.

Board accountability and internal audit

CPS 234 places ultimate responsibility for information security with the board. That means directors must be able to demonstrate active oversight: regular reporting on the threat environment, control testing outcomes, open remediation items and incident trends. Boards that treat cyber as a quarterly slide are exposed; APRA increasingly expects evidence of genuine challenge and informed decision-making at board and committee level.

Internal audit plays a defined assurance role. It must review the design and operating effectiveness of information security controls – including controls operated by third parties – and report to the board or audit committee. Where in-house cyber expertise is thin, a virtual CISO can provide the independent, board-grade perspective APRA looks for, owning the control framework and translating technical risk into language directors can act on.

Third parties are squarely in scope

One of the most misunderstood aspects of CPS 234 is that it follows your data into your supply chain. Where a third party manages your information assets, you must be satisfied their information security capability is commensurate with the criticality and sensitivity of those assets, and you must evaluate the design and operating effectiveness of their controls. Outsourcing the processing does not outsource the obligation. This is significant enough that we cover it in a dedicated piece on CPS 234 and third-party service providers.

Practical next steps

If you are reviewing your CPS 234 posture, prioritise in this order:

  1. Refresh your information asset register and classification, including third-party-held assets.
  2. Map controls to asset criticality and identify gaps against a recognised baseline such as the Essential Eight or ISO 27001.
  3. Stand up a documented, risk-based control testing programme with closed-loop remediation.
  4. Pressure-test your incident response plan against the 72-hour notification deadline.
  5. Confirm internal audit independently reviews control effectiveness and reports to the board.

CPS 234 rewards substance over documentation. An entity that can show a live asset register, evidence of recent testing, tracked remediation and a rehearsed incident process is in a far stronger position than one with thick policies and no proof of operation.

CISO Advisory Australia helps banks, insurers and superannuation funds build and evidence CPS 234 compliance, from asset classification through to board reporting and incident readiness. For a confidential discussion, get in touch or call 07 2112 8502.

Frequently asked questions

Who must comply with APRA CPS 234?

CPS 234 applies to all APRA-regulated entities, including authorised deposit-taking institutions (banks, credit unions, building societies), general and life insurers, private health insurers, and registrable superannuation entity licensees. It also reaches related entities and, indirectly, the third-party service providers that manage information assets on a regulated entity's behalf.

When must a breach be notified to APRA under CPS 234?

A regulated entity must notify APRA no later than 72 hours after becoming aware of an information security incident that materially affected, or had the potential to materially affect, the entity or the interests of depositors, policyholders or beneficiaries. Material control weaknesses must be notified within 10 business days.

Does CPS 234 require a specific cyber framework?

No. CPS 234 is principles-based and does not mandate a particular framework. Entities commonly map controls to ISO 27001, the NIST Cybersecurity Framework or the ASD Essential Eight, but APRA expects controls to be commensurate with the size and sensitivity of the information assets and the threats they face.

How does CPS 234 relate to CPS 230?

CPS 234 governs information security specifically, while CPS 230 (effective 1 July 2025) governs broader operational risk management, business continuity and service provider management. The two are complementary: a cyber incident is an operational risk event, so a strong CPS 234 posture directly supports CPS 230 obligations.

What evidence does APRA expect for CPS 234 control testing?

APRA expects a documented, risk-based testing programme covering the systematic and frequency of testing, results, remediation tracking and review by internal audit. Testing must reflect changes in threats, technology and the business, and the board must be informed of material testing outcomes and unremediated weaknesses.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act