Skip to main content

Cyber Security

APRA CPS 234 Compliance Guide for Australian Financial Services

Logical Systems··9 min read

APRA CPS 234 (Information Security) is the Australian Prudential Regulation Authority's mandatory information security standard for APRA-regulated entities — banks, insurers, superannuation funds and their third-party service providers. Non-compliance can result in regulatory action, mandatory remediation and reputational damage.

Who does APRA CPS 234 apply to?

CPS 234 applies directly to APRA-regulated entities: ADIs (banks, credit unions, building societies), general and life insurers, private health insurers, and superannuation funds. Critically, it also extends to third-party service providers — IT companies, cloud providers, payroll providers and other suppliers — who manage information assets on behalf of regulated entities.

CPS 234 key requirements

1. Information security capability

APRA-regulated entities must maintain an information security capability commensurate with the size and extent of their information assets. This requires documented security roles, responsibilities and governance — not just technical controls.

2. Information asset identification and classification

All information assets — including those managed by third parties — must be identified and classified. This is the foundation of a CPS 234 program: you cannot protect what you haven't mapped.

3. Implementation of controls

Controls must be implemented to protect information assets commensurate with their criticality and sensitivity. This includes access control, encryption, vulnerability management, network segmentation and incident response capability.

4. Incident management and notification

Material information security incidents must be notified to APRA within 72 hours. An information security incident response plan must be documented and tested — including third-party notification requirements.

5. Testing of controls

Information security controls must be tested at least annually — more frequently for systems with higher criticality or where significant changes have occurred. Testing results must be reported to the board.

Common CPS 234 gaps for Australian financial services businesses

  • Third-party supplier risk not formally assessed or documented
  • Information asset register incomplete or not maintained
  • Incident response plan documented but not tested
  • Security controls tested annually but gaps not formally remediated
  • Board-level reporting on information security absent or infrequent

CPS 234 and the Essential Eight

The Essential Eight and CPS 234 overlap significantly — MFA, patch management, backup management and application control address core CPS 234 control requirements. APRA-regulated entities implementing Essential Eight Maturity Level 2 or higher typically satisfy most CPS 234 technical control requirements.

Ready to take the next step?

Talk to a senior Logical Systems engineer — no sales deck, no pressure.

Get a CPS 234 gap assessment for your business

Ready to run technology logically?

Book a no-obligation conversation with a senior engineer — not a salesperson. We'll tell you honestly whether we're the right fit.