Theft of policyholder data
Insurers hold personal, financial and often health information. If it is stolen and serious harm is likely, that is an eligible data breach under the NDB scheme.
Cyber security and compliance for general, life and private health insurers, under APRA CPS 234, CPS 230 and the Privacy Act.
APRA regulates general insurers, life insurance companies and private health insurers. That brings two of its standards: CPS 234 for information security and CPS 230 for operational risk. Under both, the Board is ultimately responsible. Most insurers are also covered by the Privacy Act and the Notifiable Data Breaches scheme, which protect the personal information they hold about policyholders. Our clients include insurance companies. We began our card security work in 2004, and in 2006 we became the first Australian company certified as a QSA Company. Our penetration testing draws on our work with banks, insurers and payment environments.
Under CPS 234, the Board owns information security.
The Board of an entity that APRA regulates must make sure the business can stand up to security incidents.
CPS 234 asks you to keep your security in step with the threats you face. CPS 230 asks you to keep critical operations running through a disruption, including a cyber attack.
Both apply to general, life and private health insurers. We assess where you stand against each one and help you close the gaps.
Set out who is responsible for information security, from the Board and senior managers down. (CPS 234)
Protect your information assets, test the controls on a regular plan and act on what the tests find. (CPS 234)
Tell APRA within 72 hours of a security incident that has, or could have, a material impact. (CPS 234)
Name the operations that matter most to policyholders and set Board-approved limits on disruption. (CPS 230)
Keep a register of providers, check them before you rely on them and manage their risk. (CPS 230)
Most insurers are covered by the Privacy Act. Australian Privacy Principle 11 asks you to take reasonable steps to protect personal information from misuse, loss and unauthorised access.
If a breach does happen, the Notifiable Data Breaches scheme sets out what you must do and by when.
If you suspect a data breach, you have 30 days to assess whether it is likely to cause serious harm.
Once you believe an eligible breach has happened, tell the people affected and the OAIC.
Acting fast to contain a breach and reduce the harm may mean you don’t need to notify at all.
Insurers hold personal, financial and often health information. If it is stolen and serious harm is likely, that is an eligible data breach under the NDB scheme.
An attack that locks policy, claims or payment systems stops you serving policyholders. CPS 230 treats that as operational risk the Board must plan and test for.
Insurers rely on outside providers for systems and data. CPS 234 covers information assets that third parties manage for you, and CPS 230 requires you to manage those providers.
An email that tricks a staff member into giving up a password can give an attacker a way into policy and customer systems.
APRA CPS 234 (Information Security)
APRA CPS 230 (Operational Risk Management)
Privacy Act and Australian Privacy Principles (APPs)
OAIC Notifiable Data Breaches scheme
PCI DSS, for insurers that accept card payments
Senior security leadership that sets governance, ranks risk and reports clearly to your Board.
A monthly security report for your team, managers and Board.
24×7 monitoring, triage and response from our security operations centre in Australia.
Pre-booked response hours, on call 24/7, for when an incident needs fast action.
Tests shaped by our work with banks, insurers and payment environments.
Assessments by Australia’s first QSA Company, for firms that store, process or send card data.
A CPS 234 assessment against each area of the standard, with the gaps shown
A risk management plan that ranks the fixes, and help to carry them out
Ongoing checks, so your controls keep pace as the business and the threats change
Board reporting that explains security risk in business terms
PCI DSS assessments from Australia’s first QSA Company
Yes, if APRA regulates you. That includes general insurers, life insurance companies and private health insurers. The Board is responsible for making sure the business can stand up to security incidents.
CPS 234 covers information security. CPS 230 covers operational risk more widely, and a cyber incident counts as operational risk. You must identify your critical operations, set Board-approved limits on how much disruption you can accept, and test them against severe but plausible scenarios. You must also manage the risk in your service providers. CPS 230 took effect on 1 July 2025.
Under CPS 234, you must tell APRA within 72 hours of a security incident that has, or could have, a material impact. Under the NDB scheme, you have 30 days to assess a suspected data breach. Once you have reasonable grounds to believe an eligible breach has happened, you must promptly notify the people affected and the OAIC.
Any business that stores, processes or sends payment card data must comply with PCI DSS, so it applies if you accept card payments. We began our card security work in 2004 and became Australia’s first QSA Company in 2006.
Speak to us about your cyber governance and compliance requirements.