Siege Cyber provides end-to-end APRA CPS 234 compliance consulting for APRA-regulated financial institutions and third-party service providers. We assess your current security posture against CPS 234 requirements, identify gaps, implement appropriate controls, prepare board reporting, and establish ongoing compliance processes. You get a clear path to compliance with the documented evidence APRA expects.
Here is what you get:

We have guided Australian financial institutions and service providers through CPS 234 compliance. Here is how it works.
We meet with your leadership team to understand your organisation, business activities and risk profile, information assets and systems, existing security controls, third-party dependencies, and APRA relationship (regulated entity or service provider). We conduct an initial assessment to determine the scope of CPS 234 requirements applicable to your organisation and identify obvious gaps requiring immediate attention.
We assess your information security capability against all CPS 234 requirements through document review (policies, procedures, asset registers), technical assessment (control testing), interviews with key personnel (board, executives, IT, risk), and third-party review (vendor management practices). You receive a detailed gap analysis report showing current compliance status, gaps requiring remediation, prioritised remediation roadmap, and estimated timelines and resources required.
We work with your team to identify all information assets, classify them based on criticality and sensitivity, assess risks to each asset classification, determine appropriate controls commensurate with risk, and document the information asset register. This establishes the foundation for demonstrating that controls are appropriate to your risk profile, as APRA requires.
We guide implementation of required controls to close identified gaps. This phase duration varies significantly based on your starting point and the extent of remediation required. We provide technical guidance for control implementation, policy and procedure development, board reporting templates, incident management procedures, third-party assessment frameworks, and project management to keep remediation on track. You maintain visibility into progress throughout.
CPS 234 requires systematic testing of information security controls. We conduct independent testing and validation including vulnerability assessments and penetration testing, configuration reviews and security audits, third-party security assessments, incident response testing (tabletop exercises), and validation that controls operate effectively. Testing provides the evidence APRA expects that your controls actually work, not just exist on paper.
We prepare comprehensive CPS 234 compliance documentation including board attestation of compliance, information asset register, control implementation evidence, third-party risk assessments, incident management procedures, testing results and remediation tracking, and annual compliance report. Your board has the documentation needed to attest compliance with confidence, and you have evidence ready if APRA conducts an assessment.
Most summaries of CPS 234 describe it in general terms. Your reviewer will not. The standard is specific, and the obligations that catch entities out are the ones nobody reads past the headline of. Here is what the load-bearing requirements say and what evidence satisfies them. You will see the standard written both CPS 234 and CPS234, and they are the same thing.
Not the CISO, not IT, and not the managed service provider. The Board is ultimately responsible for the information security of the entity, and must ensure the entity maintains information security commensurate with the size and extent of threats to its information assets. In practice, board papers have to show the Board was informed, asked questions and made decisions. An annual status slide does not demonstrate that.
You must clearly define the information security related roles and responsibilities of the board, senior management, governing bodies and individuals with responsibility for decision making, approval, oversight, operations and other information security functions. The word doing the work there is "individuals". A responsibility matrix that stops at team level does not satisfy this. Named people, named accountabilities, and a document that is current rather than one written at implementation and never touched again.
You must maintain an information security capability commensurate with the size and extent of threats to your information assets, and one that enables the continued sound operation of the entity. This is the requirement that makes "we bought a firewall" insufficient. Capability means people, processes and controls sized against a threat picture you can describe, and it extends to the capability of any related party or third party that manages your information assets. If your core banking platform is someone else's SaaS, their capability is in scope for your obligation.
You must classify your information assets, including those managed by related parties and third parties, by criticality and sensitivity. This classification is the spine of everything downstream. It decides which controls apply, how often testing happens, and what counts as material when an incident occurs. Entities that skip it end up applying uniform controls to everything, which is expensive where it does not matter and thin where it does.
Controls must protect information assets, including those managed by related parties and third parties, and must be commensurate with the vulnerabilities and threats, the criticality and sensitivity of the asset, the stage at which it sits in its life cycle, and the potential consequences of an information security incident. "Timely" is the word that turns a known gap into a finding. A control you have scheduled for next financial year is not a control.
Testing of control effectiveness has to be systematic, and the frequency is not a number the standard hands you. It is set by five things: the rate at which vulnerabilities and threats change, the criticality and sensitivity of the information asset, the consequences of an information security incident, the risks associated with exposure to environments where you cannot enforce your own information security policies, and the materiality and frequency of change to information assets.
This is where penetration testing belongs inside your compliance programme rather than beside it. A CREST accredited test across your internet facing systems, your critical internal networks and your cloud environments, repeated on a schedule you can justify against those five factors, is the cleanest evidence a CPS 234 reviewer will accept. A quarterly vulnerability scan is not the same thing, and the difference shows up in the report.
Internal audit activities must include a review of the design and operating effectiveness of information security controls, including those maintained by related parties and third parties. Two things trip entities here. Design and operating effectiveness are separate tests, and a control that is well designed but not actually running still fails. And internal audit has to be able to assess the third party's controls, which means audit rights need to be in the contract before the reviewer asks for them, not after.
You must notify APRA no later than 72 hours after becoming aware of a material information security incident, and no later than 10 business days after becoming aware of a material information security control weakness that you expect will not be remediated in a timely manner. The 72 hours runs from awareness, not from confirmation and not from containment. Entities that have not decided in advance what "material" means for them spend most of that window arguing about it internally.
CPS 234 is not a certification. There is no CPS 234 certificate to hand a customer, which is why APRA regulated entities and the companies that supply them so often end up running an ISO 27001 information security management system underneath it. The ISMS supplies the documented policy framework, the asset register, the risk treatment plan and the internal audit programme the standard asks for, and unlike CPS 234 it produces something certifiable you can show a third party.
If you are the service provider rather than the regulated entity, the pressure arrives from the other direction. Your APRA regulated customer has to assess your controls as part of their own obligation, and the fastest way to answer that is SOC 2 or ISO 27001 evidence they can accept without auditing you themselves. Our CERTIFY programmes are built for exactly that situation, on fixed pricing rather than open ended consulting.
This service is designed for two primary audiences:
APRA-Regulated Entities – Banks, credit unions, building societies, general insurers, life insurers, private health insurers, and superannuation funds that are directly regulated by APRA and must demonstrate CPS 234 compliance to satisfy prudential obligations.
Third-Party Service Providers – Technology companies, SaaS providers, managed service providers, payment processors, data centres, and other service providers that handle information assets for APRA-regulated entities and must demonstrate adequate information security to maintain customer relationships.
You are a good fit if:

20+ years of information security and compliance expertise. Our Technical Director, Peter Stewart, has spent over two decades in hands-on cybersecurity roles including security assessments, penetration testing, and compliance consulting. We understand information security from both technical and governance perspectives, allowing us to bridge the gap between APRA requirements and practical implementation.
Deep understanding of Australian financial services regulation. Beyond CPS 234, we understand the broader APRA prudential framework including CPS 230 (operational risk), CPS 231 (outsourcing), and how these standards interact. We also understand related obligations under the Privacy Act 1988 and Notifiable Data Breaches scheme. You get compliance advice grounded in the full Australian regulatory context, not just isolated CPS 234 requirements.
We speak both board language and technical language. CPS 234 compliance requires board-level oversight and technical implementation. We prepare board reports that communicate information security posture without technical jargon, while also providing detailed technical guidance to IT teams implementing controls. Both audiences get what they need in language they understand.
Practical, risk-based approach to compliance. APRA expects controls commensurate with your risk profile, not a checklist approach. We tailor recommendations to your organisation's size, business activities, and threat landscape. A community credit union with 50 employees does not need the same controls as a major bank. We help you demonstrate appropriate controls for your actual risk, which is what APRA expects.
Proven track record with Australian financial institutions. We have guided banks, insurers, and superannuation funds through CPS 234 compliance, as well as technology service providers seeking to meet customer security requirements. You benefit from our experience with APRA expectations, common pitfalls, and what documentation actually satisfies regulatory requirements versus what looks good on paper but fails scrutiny.
APRA CPS 234 directly applies to all APRA-regulated entities including banks, credit unions, building societies, general insurers, life insurers, private health insurers, and superannuation funds. The standard also has implications for third-party service providers that handle information assets for APRA-regulated entities, as those entities are required to manage third-party information security risks under CPS 234. If you provide technology services, data processing, or other services involving access to information assets for APRA-regulated customers, you will need to demonstrate adequate information security.
APRA expects information security controls that are appropriate to the size, business activities, and risk profile of your organisation. A large bank faces different threats than a small credit union, and controls should reflect that reality. The standard does not prescribe specific technical controls but rather requires you to conduct a risk assessment, identify threats to your information assets, and implement controls that address those threats proportionate to the risk. You must be able to justify why your chosen controls are appropriate for your environment.
CPS 234 does not define specific thresholds for materiality, as this depends on the nature and circumstances of each entity. Generally, an incident is material if it has resulted in or may result in material disruption to business operations, significant financial loss, regulatory breach, material reputational damage, or compromise of sensitive customer or business data. You are required to establish criteria for assessing materiality and notify APRA within 72 hours if an incident meets those criteria. When in doubt, contact APRA.
CPS 234 requires "systematic testing and assurance" of information security controls but does not prescribe specific frequencies. Industry practice for APRA-regulated entities typically includes annual penetration testing and vulnerability assessments, quarterly vulnerability scanning, continuous security monitoring, and ad hoc testing after significant changes to systems or threats. The appropriate frequency depends on your risk profile and the criticality of your information assets. You must be able to demonstrate that testing is systematic, not ad hoc.
CPS 234 requires that testing and assurance "includes control testing and assurance undertaken by an independent party." This means some level of independent verification is required, though it does not necessarily require external auditors for all activities. Many organisations conduct internal assessments and testing but engage independent third parties for annual penetration testing, security audits, and validation of key controls. The key is demonstrating independence and objectivity in assurance activities.
CPS 234 is principle-based and does not prescribe specific technical frameworks. Many APRA-regulated entities use ISO 27001, NIST Cybersecurity Framework, or similar standards as the foundation for their information security capability, then demonstrate how those frameworks address CPS 234 requirements. ISO 27001 certification can provide supporting evidence of sound information security practices but does not automatically satisfy CPS 234, as APRA has specific requirements around board accountability, incident reporting, and third-party management that extend beyond ISO 27001.
APRA typically expects to see: information asset register with classifications, board reporting and attestation of compliance, policies and procedures for information security, risk assessments and treatment plans, third-party security assessments and contracts, security testing results (penetration tests, vulnerability scans), incident management procedures and incident logs, evidence of control implementation and effectiveness, and documentation of board and executive oversight. Essentially, you need documented evidence that your information security capability exists, is appropriate to your risks, and is actively overseen by the board.
APRA's expectations for information security are clear: board accountability, controls commensurate with threats, systematic testing, incident reporting, and third-party risk management. The question is whether you can demonstrate compliance with documented evidence when APRA asks, or whether you are relying on good intentions without substantiation. Waiting until APRA raises concerns is too late.
Book a free 30-minute consultation with our team. We will assess your current information security posture against CPS 234 requirements, identify immediate gaps requiring attention, and explain exactly what compliance looks like for an organisation of your size and risk profile. You will leave the call knowing where you stand and what needs to happen next.