Regulated industry

Insurance

Cyber security and compliance for general, life and private health insurers, under APRA CPS 234, CPS 230 and the Privacy Act.

Security and compliance for insurers that APRA regulates.

APRA regulates general insurers, life insurance companies and private health insurers. That brings two of its standards: CPS 234 for information security and CPS 230 for operational risk. Under both, the Board is ultimately responsible. Most insurers are also covered by the Privacy Act and the Notifiable Data Breaches scheme, which protect the personal information they hold about policyholders. Our clients include insurance companies. We began our card security work in 2004, and in 2006 we became the first Australian company certified as a QSA Company. Our penetration testing draws on our work with banks, insurers and payment environments.

Insurance

Under CPS 234, the Board owns information security.

The Board of an entity that APRA regulates must make sure the business can stand up to security incidents.

Two APRA standards, one accountable Board.

CPS 234 asks you to keep your security in step with the threats you face. CPS 230 asks you to keep critical operations running through a disruption, including a cyber attack.

Both apply to general, life and private health insurers. We assess where you stand against each one and help you close the gaps.

  • Clear roles

    Set out who is responsible for information security, from the Board and senior managers down. (CPS 234)

  • Tested controls

    Protect your information assets, test the controls on a regular plan and act on what the tests find. (CPS 234)

  • APRA notice in 72 hours

    Tell APRA within 72 hours of a security incident that has, or could have, a material impact. (CPS 234)

  • Critical operations

    Name the operations that matter most to policyholders and set Board-approved limits on disruption. (CPS 230)

  • Service providers

    Keep a register of providers, check them before you rely on them and manage their risk. (CPS 230)

Policyholder data brings privacy duties too.

Most insurers are covered by the Privacy Act. Australian Privacy Principle 11 asks you to take reasonable steps to protect personal information from misuse, loss and unauthorised access.

If a breach does happen, the Notifiable Data Breaches scheme sets out what you must do and by when.

  • Assess within 30 days

    If you suspect a data breach, you have 30 days to assess whether it is likely to cause serious harm.

  • Notify promptly

    Once you believe an eligible breach has happened, tell the people affected and the OAIC.

  • Contain it early

    Acting fast to contain a breach and reduce the harm may mean you don’t need to notify at all.

72 hrs
To notify APRA of a material incident (CPS 234)
5
Frameworks we map to for this sector
CREST
Accredited penetration testing
2001
Operating in Australia

Cyber risks insurers need to manage.

Theft of policyholder data

Insurers hold personal, financial and often health information. If it is stolen and serious harm is likely, that is an eligible data breach under the NDB scheme.

Ransomware on core systems

An attack that locks policy, claims or payment systems stops you serving policyholders. CPS 230 treats that as operational risk the Board must plan and test for.

Service-provider risk

Insurers rely on outside providers for systems and data. CPS 234 covers information assets that third parties manage for you, and CPS 230 requires you to manage those providers.

Phishing and stolen logins

An email that tricks a staff member into giving up a password can give an attacker a way into policy and customer systems.

Rules we help insurers meet.

  • APRA CPS 234 (Information Security)

  • APRA CPS 230 (Operational Risk Management)

  • Privacy Act and Australian Privacy Principles (APPs)

  • OAIC Notifiable Data Breaches scheme

  • PCI DSS, for insurers that accept card payments

What insurers get from working with Vectra.

  • A CPS 234 assessment against each area of the standard, with the gaps shown

  • A risk management plan that ranks the fixes, and help to carry them out

  • Ongoing checks, so your controls keep pace as the business and the threats change

  • Board reporting that explains security risk in business terms

  • PCI DSS assessments from Australia’s first QSA Company

Questions insurers ask first.

Does CPS 234 apply to our business?

Yes, if APRA regulates you. That includes general insurers, life insurance companies and private health insurers. The Board is responsible for making sure the business can stand up to security incidents.

What does CPS 230 add to CPS 234?

CPS 234 covers information security. CPS 230 covers operational risk more widely, and a cyber incident counts as operational risk. You must identify your critical operations, set Board-approved limits on how much disruption you can accept, and test them against severe but plausible scenarios. You must also manage the risk in your service providers. CPS 230 took effect on 1 July 2025.

How quickly must we report a cyber incident?

Under CPS 234, you must tell APRA within 72 hours of a security incident that has, or could have, a material impact. Under the NDB scheme, you have 30 days to assess a suspected data breach. Once you have reasonable grounds to believe an eligible breach has happened, you must promptly notify the people affected and the OAIC.

Do insurers need to comply with PCI DSS?

Any business that stores, processes or sends payment card data must comply with PCI DSS, so it applies if you accept card payments. We began our card security work in 2004 and became Australia’s first QSA Company in 2006.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.