Quick answer: CPS 234 is APRA's Prudential Standard on Information Security, in force since 1 July 2019. It makes the Board of every APRA-regulated bank, insurer and superannuation trustee ultimately responsible for information security, requires a security capability commensurate with threats, classification and control of all information assets including those managed by third parties, systematic control testing and internal audit assurance, and notification to APRA within 72 hours of a material security incident and within 10 business days of a material control weakness. Since 2025 it operates alongside CPS 230 and, for banks, the SOCI Act.
CPS 234 is seven years old, and most of the content ranking for it was written when it was new. The standard has not changed, but the world around it has: CPS 230 arrived in July 2025 and turned business continuity and third-party management into a single operational resilience regime; the Security of Critical Infrastructure Act now treats banking and finance as critical infrastructure with its own risk-management and incident-reporting duties; APRA has published the recurring weaknesses it finds in independent CPS 234 assessments; and the threat has moved decisively to the supply chain, where a vendor compromise exposes dozens of institutions at once.
This guide is for CISOs, CROs, heads of third-party risk and technology leaders in Australian banks, insurers and super funds who need a current, integrated picture: what CPS 234 requires, where APRA finds gaps, how CPS 234, CPS 230 and SOCI fit together, and how to run third-party cyber risk in 2026-2027.
What is CPS 234 and who does it apply to?
Prudential Standard CPS 234 Information Security applies to all APRA-regulated entities: authorised deposit-taking institutions, general, life and private health insurers, and RSE licensees, and extends to the information assets managed by their related parties and third parties. Its requirements, in plain terms:
- Board accountability. The Board is ultimately responsible for information security and must ensure the entity maintains it commensurate with the size and extent of threats.
- Roles and capability. Clearly defined security roles and responsibilities, and an information security capability that keeps pace with vulnerabilities and threats, including for assets managed by third parties.
- Policy framework. An information security policy framework proportionate to the entity's exposures.
- Asset identification and classification. Identify and classify information assets, including those managed by related parties and third parties, by criticality and sensitivity.
- Controls. Implement controls commensurate with the criticality and sensitivity of each asset and the threats to it, including for third-party-managed assets, and evaluate the design and effectiveness of third parties' controls.
- Incident management. Robust mechanisms to detect and respond to incidents, with response plans tested annually.
- Testing. A systematic testing programme of control effectiveness, with escalation of deficiencies that cannot be remediated promptly.
- Internal audit. Assurance over the design and operating effectiveness of information security controls, including those of third parties.
- Notification. Notify APRA as soon as possible and no later than 72 hours after becoming aware of a material information security incident, and within 10 business days of identifying a material control weakness that cannot be remediated in a timely manner.
CPG 234, the accompanying practice guide, sets out APRA's expectations in more detail. APRA has also run a programme of independent "tripartite" assessments, where an independent party assesses the entity's CPS 234 compliance and reports to both the entity and APRA.
Where APRA finds the gaps
APRA has been unusually public about the recurring weaknesses its tripartite assessments uncover. The themes, consistent across its communications since 2023:
- Incomplete asset identification and classification, particularly for information assets managed by third parties and for data in non-production and shadow environments.
- Control testing that is not systematic, is not risk-based in coverage or frequency, or does not test controls operated by third parties.
- Incident response plans that are not tested against realistic scenarios, or that omit third-party and fourth-party incidents.
- Third-party and supply chain controls evaluated by questionnaire rather than evidence.
- Internal audit assurance that is too narrow.
APRA has said cyber resilience remains a supervision priority and has shown willingness to apply additional capital requirements and conditions where weaknesses persist. The practical message: a CPS 234 programme that looked compliant in 2020 will not be judged compliant in 2027 unless it has kept pace with third-party exposure and testing depth.
How CPS 234 and CPS 230 fit together
CPS 230 Operational Risk Management (effective 1 July 2025) did not replace CPS 234; it surrounds it. The relationship:
- Object — CPS 234 Information Security: Information assets (data, systems, models, credentials) · CPS 230 Operational Risk Management: Critical operations (payments, deposits, claims, custody and the systems supporting them)
- Core question — CPS 234 Information Security: Is the asset protected commensurate with threat? · CPS 230 Operational Risk Management: Can the operation keep running within tolerance when something fails?
- Third parties — CPS 234 Information Security: Evaluate controls of third parties managing information assets · CPS 230 Operational Risk Management: Manage material service providers: register, due diligence, contract terms, fourth parties
- Testing — CPS 234 Information Security: Systematic control-effectiveness testing; incident response tested annually · CPS 230 Operational Risk Management: Business continuity plan testing and scenario analysis
- Notification — CPS 234 Information Security: 72 hours for material security incident; 10 business days for material control weakness · CPS 230 Operational Risk Management: 72 hours for material operational risk incident; 24 hours for disruption outside tolerance; 20 business days for material service provider arrangements
- Accountability — CPS 234 Information Security: Board ultimately responsible · CPS 230 Operational Risk Management: Board approves tolerance levels and oversees operational risk
A ransomware event illustrates the overlap: it is a CPS 234 incident (72-hour notification, incident response plan) and, if it disrupts payments beyond tolerance, a CPS 230 breach (24-hour notification, BCP activation). One incident, two standards, one Board. Integrated reporting lines, a single incident-classification framework and a shared asset-to-operation map are what make this manageable. Our guide to CPS 230 and AI in banking covers the CPS 230 side in depth, including how AI models become both information assets and critical-operation components.
How the SOCI Act applies to banks and insurers
The Security of Critical Infrastructure Act 2018, as amended in 2021-2022 and refined since, designates banking and finance as a critical infrastructure sector. Responsible entities for critical banking, insurance, superannuation and financial market infrastructure assets face obligations that overlap with, but are not identical to, APRA's:
- Register of critical infrastructure assets with the Cyber and Infrastructure Security Centre.
- Critical infrastructure risk management programme (CIRMP), addressing cyber and information security, personnel, supply chain and physical and natural hazards, with an annual Board-approved attestation. APRA-regulated entities can generally meet the cyber limb through CPS 234 compliance, which the rules recognise as an equivalent framework, but the personnel, supply chain and physical hazard limbs still need to be evidenced.
- Mandatory cyber incident reporting to the Australian Signals Directorate: 12 hours for incidents with a significant impact on asset availability, 72 hours for other relevant impacts.
- Government assistance and intervention powers in a serious cyber incident.
The Cyber Security Act 2024 added a ransomware payment reporting obligation (72 hours) for businesses above a turnover threshold and for critical infrastructure entities. For a CISO that means at least three clocks can start on a single incident: APRA (72 hours), ASD under SOCI (12 or 72 hours) and the ransomware payment report (72 hours), plus the Privacy Act's notifiable data breach regime and, for listed entities, ASX continuous disclosure. The incident response plan should name who starts each clock.
Third-party cyber risk: the control that matters most
Every major Australian financial services incident of the past few years that reached the public has had a supply chain dimension: a law firm, a managed service provider, a software vendor, a file-transfer tool. CPS 234 and CPS 230 between them require you to know your third parties' controls and resilience; the market reality is that questionnaires do not tell you.
A third-party cyber risk programme that satisfies both standards in 2026-2027 looks like this:
- One inventory, tiered by consequence. Every third party mapped to the information assets it touches (CPS 234) and the critical operations it supports (CPS 230), tiered by the impact of its compromise or failure, with fourth parties recorded for tier-one providers.
- Evidence-based assurance. Independent assurance reports (SOC 2 Type II, ISO/IEC 27001 certification with scope checked), penetration test summaries, and your own right-to-audit exercised for tier one. Questionnaires for lower tiers only.
- Continuous monitoring. External attack-surface and breach-intelligence monitoring for tier-one and tier-two providers, with alerts routed to the vendor owner, not just to security.
- Contractual minimums. Security obligations, incident notification windows aligned to your own 72-hour and 24-hour clocks, data location and return, sub-contractor transparency, audit rights, and exit assistance.
- Concentration and exit. Identify where many critical operations depend on one provider (cloud regions, core banking SaaS, payments gateways) and maintain tested exit and substitution plans.
- Joint testing. Include tier-one providers in incident response exercises and business continuity tests, as CPS 230 scenario analysis expects.
- Lifecycle governance. Onboarding, periodic reassessment driven by risk and events, and offboarding with access and data confirmed removed.
The same vendors increasingly embed AI; the questions about model provenance, data use and sub-processors belong in this programme too (see our note on agentic AI governance).
Operational resilience: the global context
Australian institutions with international parents or operations will recognise the pattern elsewhere: the EU's Digital Operational Resilience Act (DORA, applying from January 2025) with its ICT third-party oversight regime; the UK PRA and FCA operational resilience rules with impact tolerances for important business services (fully in force from March 2025); and MAS's Technology Risk Management Guidelines and outsourcing requirements in Singapore. The vocabulary differs, but the architecture is the same one APRA has built with CPS 234 and CPS 230: identify what matters, set tolerances, know your providers, test, and report quickly. Global groups can and should run one framework mapped to all of them.
Baseline controls regulators expect to see
Neither CPS 234 nor CPS 230 prescribes specific technical controls, but APRA, ASD and the market have converged on a baseline that assessors look for: the ASD Essential Eight at a maturity level appropriate to the threat (application control, patching of applications and operating systems, Microsoft Office macro settings, user application hardening, restriction of administrative privileges, multi-factor authentication and regular backups); privileged access management; network segmentation; immutable and tested backups; logging and detection coverage across cloud and on-premises estates; and secure software development practices. Where a control is operated by a third party, the expectation is that you can evidence its effectiveness, not just its existence.
Key takeaways
- CPS 234 has not changed since 2019, but APRA's expectations of depth have: asset classification, control testing and third-party assurance are where assessments fail.
- CPS 230 surrounds CPS 234; run one incident-classification framework and one asset-to-operation map for both.
- The SOCI Act and the Cyber Security Act add separate reporting clocks (12 hours, 72 hours) and a Board-attested risk management programme; name who starts each clock.
- Third-party cyber risk is the control that matters most: tier by consequence, demand evidence not questionnaires, monitor continuously, and test with your providers.
- Global groups can map CPS 234/230 to DORA, the UK operational resilience regime and MAS TRM as a single framework.
Join your peers at the Clutch Cyber in FSI Summits 2027
Clutch Events runs free-to-attend, invite-curated, practitioner-led Cyber in FSI summits for CISOs, CROs and technology risk leaders at Australian banks, insurers and super funds:
- Sydney Cyber in FSI Summit 2027 — 8 September 2027
- Melbourne Cyber in FSI Summit 2027 — 6 October 2027
See all upcoming Clutch events · More guides on Clutch Events Insights