Advisory

APRA CPS 234 Assessments

Independent assessments of your information security against APRA's CPS 234, with clear findings for the board and a plan to close the gaps.

Evidence your board can rely on.

CPS 234 makes the board of every APRA-regulated entity ultimately responsible for information security, so directors need independent evidence that controls are in place and operating effectively. Vectra assesses your entity against each part of the standard, tests how well your controls work, sets out the gaps in plain terms and helps you remediate them. Our team holds the specialist certifications this work needs, and we are based in Australia.

APRA CPS 234 Assessments

Where CPS 234 assessments often find gaps.

Under its 2020-2024 cyber strategy, APRA required banks, insurers and super trustees to appoint independent auditors to assess them against CPS 234. APRA then published the gaps these tripartite assessments found most often.

We look closely at each of these areas in every assessment.

  • Information assets

    Critical and sensitive assets not fully identified or classified.

  • Third parties

    Little assessment of the security of third parties.

  • Control testing

    Testing programs that are poorly defined or not carried out.

  • Response plans

    Incident response plans that are not reviewed or tested often enough.

  • Internal audit

    Little internal audit review of security controls.

  • APRA notification

    Material incidents and control weaknesses not reported to APRA on time.

Testing must be independent.

CPS 234 says your controls must be tested by skilled specialists who are functionally independent. Vectra can run that testing for you, or check the testing program you already have.

From scope to board report.

Each step rests on evidence of what is in place today.

  1. Step 1: Scope

    Agree the entities, information assets, third parties and time period in scope, and who will receive the report.

  2. Step 2: Review

    Read your policy framework, roles, asset register, response plans, testing program and internal audit work.

  3. Step 3: Test

    Interview control owners, sample the evidence and test whether key controls are well designed and work as intended.

  4. Step 4: Third parties

    Check how you assess the security of related parties and third parties that manage your information assets.

  5. Step 5: Report

    Rate each requirement, rank the gaps by risk and write a summary the board can act on.

  6. Step 6: Remediate

    Help you plan and close the gaps, then check the fixes in a follow-up review.

CPS 234 work we run.

CPS 234 assessment

A review of your entity against each requirement of the standard, with a rating and the gaps we find.

CPS 234 audit

An audit of your controls and the evidence behind them, as APRA would expect to see it.

Control testing

Testing by skilled specialists who are independent of the teams that run the controls, as the standard requires.

Third-party review

A check of how your service providers protect your information assets, sized to the harm an incident could cause.

Risk management plan

The risks we found, the order in which to fix them and help to remediate each gap.

Ongoing assurance

Periodic reviews so your controls keep pace as your business and the threat environment change.

What you have at the end.

  • A rating against each CPS 234 requirement, backed by evidence.

  • A ranked list of gaps, with owners and fixes.

  • A plain summary for the board and senior management.

  • A clear view of the security risk held by your third parties.

  • A remediation plan you can track and test again.

CPS 234 questions, answered.

Who does CPS 234 apply to?

It applies to all APRA-regulated entities. That includes banks and other deposit-taking institutions, general insurers, life insurers, private health insurers, super fund trustees (RSE licensees) and authorised or registered non-operating holding companies. It has been in force since 1 July 2019.

Do we need an independent assessment?

The standard says control testing must be done by specialists who are skilled and functionally independent. Internal audit must also review how well your controls are designed and how well they work. An independent assessment meets these needs and gives the board evidence it can question.

What must we tell APRA, and when?

You must tell APRA within 72 hours of becoming aware of a material security incident. You must also tell APRA within 10 business days of finding a material control weakness that you do not expect to fix in a timely way.

Does CPS 234 cover our service providers?

Yes. Where a related party or third party manages your information assets, you must assess its security capability. Your internal audit must also review controls kept by those parties. We can assess your key providers as part of the work.

Can the evidence be used for other standards?

Yes. We map controls across CPS 234, ISO 27001, PCI DSS and the Essential Eight, so one set of evidence can support several reviews.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.