Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Australian regulation

    APRA CPS 234

    CPS 234 is the APRA prudential standard on information security. It requires regulated entities — banks, insurers and superannuation trustees — to define information security roles, maintain capability proportionate to threats, test controls, manage third-party risk, and notify APRA of material incidents within 72 hours.

    What APRA CPS 234 means in practice

    CPS 234 applies to APRA-regulated entities, but its reach extends well beyond them, because the standard makes regulated entities responsible for information assets managed by third parties. Any technology provider serving a bank, insurer or superannuation fund will be asked to demonstrate controls that satisfy their client's CPS 234 obligations.

    The core requirements are clear enough to work against. Boards hold ultimate responsibility for information security, and roles and responsibilities must be clearly defined. Information security capability must be commensurate with the size and extent of threats, and with the criticality and sensitivity of the assets. Information assets must be classified by criticality and sensitivity, including those managed by related parties and third parties. Controls must be implemented, and — this is the part organisations underestimate — systematically tested, with results reviewed by people independent of those who designed or operate them.

    Notification obligations are strict. Material information security incidents must be notified to APRA within 72 hours, and material control weaknesses that cannot be remediated in a timely manner within 10 business days. That timeline requires an incident classification process defined in advance, because the clock is not a reasonable moment to be deciding what counts as material.

    In a Microsoft environment, the evidence CPS 234 assessors ask for maps onto identity and endpoint telemetry: who holds privileged access and how it is granted, whether multi-factor authentication covers all remote and privileged access, how device compliance is enforced, what logging exists and for how long, and how backups are tested for restoration rather than just monitored for completion.

    CPS 230, the operational risk management standard, sits alongside it and broadens the lens to critical operations, service provider management and business continuity. Entities working through one usually find the other draws on the same evidence base, and building the two programmes together avoids duplicating the work.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.