CPS 234 changed the governance of information security for every bank, insurer and superannuation trustee in Australia by doing one decisive thing: it placed ultimate accountability on the board. Cyber is no longer something the board hears about occasionally from the IT function. It is a board-level prudential obligation, and directors who do not understand their specific duties are exposed both personally and as a governing body.
The accountability the board cannot delegate
CPS 234 states that the board of an APRA-regulated entity is ultimately responsible for ensuring the entity maintains its information security. This is a deliberate and significant choice of language. Management runs security day to day, specialists operate the controls, and third parties may host critical systems, but the buck stops with the board.
What this means in practice is that the board cannot treat information security as fully delegated. It can and must delegate execution, but it retains the duty to ensure the entity is actually protected, to oversee how management discharges its responsibilities, and to satisfy itself that the obligations of CPS 234 are being met. Accountability without engagement is not accountability at all.
What boards are not expected to do
It is worth being clear about the limits, because fear of the technical detail can paralyse boards. Directors are not expected to be cryptographers, network engineers or incident responders. They are not expected to approve firewall rules or read penetration test output line by line. CPS 234 is a governance obligation, not a technical one. The board’s job is oversight, challenge and assurance, exercised through the right structures, reporting and questions.
The board’s core oversight duties
In practical terms, discharging board accountability under CPS 234 involves a consistent set of activities:
- Ensuring capability is commensurate. The board must satisfy itself that the entity’s information security capability matches the threats it faces and the criticality and sensitivity of its information assets.
- Defining roles and responsibilities. The board oversees the clear allocation of information security responsibilities across the entity, including the senior leadership accountable for the program.
- Overseeing the risk position. The board must understand the entity’s material information security risks and whether they sit within agreed appetite.
- Reviewing testing and assurance. The board receives and interrogates the results of independent testing and internal audit reviews of control effectiveness.
- Overseeing incidents and notifications. The board must be confident the entity can detect, respond to and notify incidents to APRA within the required timeframes.
Reporting the board should demand
Good oversight depends on good information. The most common failure is a board receiving either too little or the wrong kind of reporting, often a wall of green dashboards that conceal more than they reveal. Boards should insist on reporting that covers:
- The information asset and risk posture, including how critical and sensitive assets are protected.
- Results of independent testing and internal audit, with honest reporting of weaknesses, not just successes.
- Remediation status, showing whether known issues are being closed on time.
- Incidents and any notifications made to APRA or other regulators.
- Third-party and related-party risk, given how much depends on outsourced providers.
- Overall maturity and trajectory, so the board can see whether the program is improving.
Crucially, this reporting must be framed in business and risk language the board can challenge, not raw technical metrics. A trend showing overdue remediation on critical assets tells a director far more than a count of patched servers.
Questions a board should be asking
Effective directors test the program through pointed questions. A capable management team will welcome them; an evasive answer is itself a finding. Useful questions include:
- Do we know what our most critical and sensitive information assets are, and are they protected accordingly?
- When did we last independently test our most important controls, and what did we find?
- Could we recognise a material incident and notify APRA within 72 hours? When did we last rehearse that?
- Which critical functions depend on third parties, and how do we assure ourselves their controls work?
- What are our most significant unremediated weaknesses, and why are they still open?
These questions map directly to the obligations in our CPS 234 explained guide and give the board a defensible record of genuine oversight.
Outsourcing does not transfer the duty
Many APRA-regulated entities, superannuation funds in particular, rely heavily on outsourced administration and cloud platforms. CPS 234 applies regardless. The board remains accountable for information assets managed by third and related parties, and must oversee the assurance that confirms those outsourced controls are effective. A board that assumes a vendor’s certification ends the matter has misunderstood the standard. The right posture is to oversee robust third-party risk management that produces evidence the board can rely on.
The board’s role across the CPS 234 lifecycle
It helps directors to see how their oversight maps onto the entity’s annual rhythm rather than being a single conversation. Across a typical year the board should expect to engage with information security at several points:
- Strategy and appetite — confirming the information security risk appetite and that investment is sufficient to keep capability commensurate with the threat.
- Posture review — periodically reviewing the asset and risk picture, including changes from new systems, acquisitions or vendor shifts.
- Assurance — receiving and challenging the results of independent testing and internal audit, and tracking remediation of weaknesses.
- Incident oversight — being informed of material incidents and notifications, and reviewing lessons learned.
- Maturity — assessing whether the program is improving over time and whether known gaps are closing.
Treating these as recurring touchpoints, rather than a once-a-year compliance tick, is what converts formal accountability into real oversight.
Avoiding the false comfort trap
The most dangerous position for a board is unfounded confidence. This happens when reporting is uniformly positive, when management presents only successes, or when a stack of vendor certifications is treated as proof that nothing can go wrong. Directors should be wary of reporting that never contains bad news, because no real security program is without weaknesses. A board that hears only good news is not being reassured; it is being under-informed. Insist on honest reporting of the most significant unremediated issues and on independent input that can corroborate or challenge what management says. Healthy discomfort is a sign of genuine oversight.
Building board capability
Boards strengthen their oversight by investing in their own capability. Practical steps include periodic cyber education for directors pitched at the governance level, considering relevant expertise when refreshing the board, and using independent advice to pressure-test what management reports. An external perspective, such as a Virtual CISO, can give directors an honest second opinion on whether the program genuinely meets CPS 234 or merely looks compliant on paper. This approach mirrors the governance discipline we describe for AI governance, where board oversight of a fast-moving risk is equally critical.
Documenting board oversight
Accountability under CPS 234 is not only about doing the right things; it is about being able to show that you did. Board and committee minutes should record that information security was considered, what reporting the board received, what questions were asked and what decisions or directions followed. If APRA or an external review later examines the entity’s governance, contemporaneous records of genuine board engagement are powerful evidence that the board discharged its duty. Equally, a minute book that mentions cyber only fleetingly, or only after an incident, tells its own story. Directors should satisfy themselves that the rhythm of oversight described above is visible in the record, not just in practice.
Getting board oversight right
CPS 234 makes information security a test of board effectiveness, not just IT competence. Directors who understand their accountability, demand the right reporting and ask sharp questions turn a regulatory obligation into genuine resilience. Those who delegate and disengage carry real exposure.
CISO Advisory works directly with boards and executives of APRA-regulated entities to clarify CPS 234 accountability, sharpen reporting and provide independent assurance. To strengthen your board’s oversight, call 07 2112 8502 or explore our CPS 234 advisory services.
Frequently asked questions
Is the board really accountable for information security under CPS 234?
Yes. CPS 234 places ultimate responsibility for the information security of an APRA-regulated entity squarely with its board. The board cannot delegate that accountability, even though it delegates day-to-day execution to management and may outsource controls to third parties.
Does the board need to be technical?
No. Boards are not expected to be security engineers. They are expected to ensure the entity maintains information security commensurate with its threats, to oversee management, to receive adequate reporting and to ask informed questions that test whether obligations are genuinely being met.
How often should the board review information security?
Regularly enough to maintain genuine oversight, typically as a standing agenda item, with deeper reviews tied to material change, significant incidents, testing results and the annual risk cycle. Once-a-year attention is rarely sufficient for a material risk like cyber.
What reporting should the board receive on CPS 234?
Reporting on the information asset and risk posture, testing and assurance results, remediation status, incidents and notifications, third-party risk and the entity's overall information security maturity, presented in business terms the board can interrogate, not raw technical metrics.
Can the board rely on outsourcing to discharge its duty?
No. CPS 234 applies even where information assets are managed by third or related parties. The board remains accountable for ensuring those assets are protected and must oversee the assurance that confirms outsourced controls are effective.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.