• Contact
  • Feedback
Banking Day
ConfidentiallySpeaking.com.au Logo
High-impact negotiation masterclass | July 9 & 16, 2025 | 5:00pm - 8:30pm
This high-impact negotiation masterclass teaches practical strategies to help you succeed in challenging negotiations.
Register Now
  • News
  • Topics
    • All Topics
    • Briefs
    • Major Banks
    • Authorised deposit-taking institutions
    • Insurance, funds and super
    • Payments, mobile & wallets
    • Consumer lending
    • Mortgages
    • Business lending
    • Finance regulation
    • Debt capital markets
    • Ratings agencies
    • Equity capital markets
    • Professional services
    • Work & career
    • Foreign news
    • Other topics
  • Free Trial
  • Subscribe
  • Resources
    • Industry events
  • About us
    • About Banking Day
    • Advertise
    • Feedback
    • Contact Banking Day
  • Search
  • Login
  • My account
    • Account settings
    • User Admin
    • Logout

Login or request a free trial

APRA 'running out of patience' with industry response to information security and cyber risks

29 August 2023 5:45AM

The Australian Prudential Regulation Authority has challenged banks and other financial institutions to stop thinking about information security and cyber risk as technology issues and elevate them to the level of “overall business risks”. The regulator has called on regulated entities to “build a new mindset” to overcome compliance failings in meeting the current information security standard and prepare to meet the requirements of a new operational risk management standard. In July, APRA released the findings of an assessment of compliance with prudential standard CPS 234 Information Security, which has been in force since 2019. It found that “control gaps” were common, including incomplete identification and classification of critical and sensitive information assets; limited assessment of third-party information security capability; and inadequate definition and execution of control testing programs. Other shortcomings include limited internal audit of security controls, inconsistent reporting of incidents and a failure to review or test incident response plans. The regulator said these gaps were “concerning” and that it had intensified its supervisory oversight. In a speech last week, APRA member Therese McCarthy Hockey set out to explain why, in APRA’s view, banks and other financial institutions are struggling to meet the standard’s requirements. McCarthy Hockey said: “There is a range of answers: the evolving nature of cyber threats means organisations are constantly firing at moving targets; increasing reliance on multiple services providers creates complex webs of interconnectivity, which makes oversight harder; and we know that many of our entities have laboured to migrate legacy systems to new, more secure platforms. “APRA has also observed a long period of insufficient investment in both cyber security technology and personnel with the necessary skills and experience, especially among smaller organisations that lack the deep pockets of the industry giants. “But if we were to identify a root cause it would be that information security has too often been seen by boards as a technology risk and not an overall business risk. Rather than leaving cyber resilience to the IT and cyber security departments, boards need to become much more tech savvy and alert to how the threats have changed, in particular for the data they collect and manage.” McCarthy Hockey said APRA was running out of patience with the slow pace of change. The regulator will put more pressure on banks and other financial institutions in the lead up to the introduction of a new operational risk standard in 2025. Prudential Standard CPS 230 Operational Rick Management, which was released in July, includes requirements to address identified weaknesses in existing controls and improves business continuity planning to deal with severe disruptions. The new standard also includes rules that enhance third-party risk management, so that risks from service providers are appropriately managed.  For the purposes of business continuity planning, the standard defines critical operations are processes undertaken by a regulated entity or its service provider which, if disrupted beyond tolerance levels, would have a material adverse impact on depositors, policy holders, beneficiaries or other customers, or its role in the financial system. An authorised deposit-taking institution must classify payments, deposit-taking and management, custody, settlement

I'm a returning subscriber

*
Password reset *
Login

Request a free trial

  • Emailing you the news at 7am.
  • Covering core lending and funding issues, strategy, payments, regulation, risk management, IT, marketing and more.
  • Original news and summaries of major stories from other media – ditch your newspaper subscriptions.
  • Focused on banking and finance, saving you the time spent wading through newspapers and other services.
  • With reporting from former editors and senior writers from the AFR and The Australian.
  • Configured for your phone, laptop and PC.
Free trial Banking Day
ConfidentiallySpeaking.com.au Logo
High-impact negotiation masterclass | July 9 & 16, 2025 | 5:00pm - 8:30pm
This high-impact negotiation masterclass teaches practical strategies to help you succeed in challenging negotiations.
Register Now

Consumer lending

  • Latitude, Harvey Norman liable for interest free GO card con

Copyright © WorkDay Media 2003-2025.

Banking Day is a WorkDay Media publication

WorkDay Media Unit Trust

  • Privacy policy
  • Terms of access and use