When you are a financial services firm, IT support becomes part of what you have to be able to prove. Three Australian obligations decide what your provider has to evidence: APRA's prudential standards if you are an APRA-regulated entity, section 912A of the Corporations Act if you hold an Australian financial services licence, and Australian Privacy Principle 11 if the Privacy Act covers you. Read the three together and they ask for the same thing in different words: not better technology, but documentation that already exists when a regulator, a client or an insurer asks for it. inSUPPORT has run 1,500 or more cyber audits across Australian businesses, not only in this vertical.
If a framework has landed on your desk with a board or a client behind it, you are not behind for asking what it actually means. The guidance is written for the regulated entity, not for the person who has to turn it into a scope of work. Adequate, reasonable and commensurate is what the standards say, and none of it tells you what to switch on by Friday.
The three bind different firms in different ways, and the differences matter more than the overlap. APRA's standards do not apply to every business with finance in its name, section 912A applies to every AFS licensee, and the Privacy Act follows the personal information. Which of them you are under is the first question, and it is not a technical one.
So this piece takes them in turn: who each one binds, what the Federal Court has said adequate cyber risk management means, and what IT support for financial services firms looks like in practice. It is information about obligations rather than advice on yours, and it should leave you with a shorter list of questions.
TL;DR: What changes, and what does not
- ✅ Two APRA standards, one population: deposit-taking institutions, general insurers, life companies, private health insurers, superannuation trustees and the holding companies above them. CPS 234 Information Security commenced 1 July 2019; CPS 230 Operational Risk Management commenced 1 July 2025, with an updated standard and guide from 1 July 2026.
- ✅ CPS 230 is the newer of the two, and it is the one that reaches your provider: critical operations and tolerance levels, a register of material service providers submitted to APRA annually, and contract terms the arrangement has to carry.
- ✅ Every AFS licensee has to manage cyber risk under section 912A. The Federal Court confirmed it in RI Advice in 2022 and imposed the first penalty, $2.5 million, on FIIG Securities in February 2026.
- ✅ APP 11 asks for reasonable steps, and APP 11.3 says those steps include technical and organisational measures. Outsourcing changes what reasonable looks like rather than moving the obligation off your desk.
- ✅ The practical change is evidence on demand: your provider should be able to produce your control evidence without preparing it first, and aligned only counts when it names the framework, the scope, the level, the assessor and the date. Anything shorter is an adjective.
Contents
- Who Each Obligation Binds, and Who It Does Not
- What the Federal Court Said Adequate Looks Like
- What Lands on Your Provider's Desk, and What Aligned Has to Mean
- Financial services IT support, answered plainly
Who Each Obligation Binds, and Who It Does Not
Start with APRA, because its standards get quoted at businesses they do not cover. Two of them matter here, and both name the same population: authorised deposit-taking institutions including foreign ADIs, general insurers including Category C insurers, life companies, private health insurers, RSE licensees (the trustees of superannuation funds) and the authorised holding companies above them, applied on a group basis where an entity heads a group. A planning practice, a broker or a fund manager that is not itself APRA-regulated is bound by neither directly, whatever a vendor slide may suggest.
CPS 234 Information Security commenced on 1 July 2019. CPS 230 Operational Risk Management is the newer one, and the one to check your own briefing for. It commenced on 1 July 2025, picking up pre-existing service provider contracts from the earlier of their next renewal or 1 July 2026, and an updated standard and guide commenced on 1 July 2026. It covers operational risk, holding critical operations inside stated tolerance levels through severe disruptions, and managing service providers. APRA's current standards list no longer carries CPS 231 Outsourcing or CPS 232 Business Continuity Management, whose ground CPS 230 now holds.
The licence obligation is separate and broader. Section 912A of the Corporations Act requires an AFS licensee to do all things necessary to ensure the services covered by its licence are provided efficiently, honestly and fairly, and to have adequate resources and adequate risk management systems. ASIC's published position is that cyber risk sits inside those obligations for every licensee.
The Privacy Act follows the information rather than the licence. APP 11 requires an entity it covers to take reasonable steps to protect the personal information it holds, and APP 11.3 states that those steps include technical and organisational measures, which is to say the controls and the paperwork both count. Coverage generally starts above $3 million in annual turnover. Financial services lodged 157 OAIC breach notifications across 2025, second only to health.
- Write down which of the three you are actually under, and which client or regulator is doing the asking. That answer sets the scope of the work before anyone quotes on it.
- If an APRA questionnaire arrived from a client, treat it as their obligation flowing to you, and answer it with artefacts rather than assurances.
- Know the clocks, because a provider's runbook has to meet them. Under CPS 234 an entity notifies APRA no later than 72 hours after becoming aware of a material information security incident. Under CPS 230 it is 72 hours for an operational risk incident it judges likely to have a material financial impact or a material impact on maintaining critical operations, and no later than 24 hours after a disruption to a critical operation outside tolerance.
What the Federal Court Said Adequate Looks Like
Two decisions now describe the standard. In ASIC v RI Advice Group, decided on 5 May 2022, the licensee admitted contravening sections 912A(1)(a) and (h) from 15 May 2018 to 5 August 2021, because its documentation and controls were not adequate to manage cyber risk across its authorised representative network. Nine incidents had occurred there between June 2014 and May 2020.
The detail is what makes the judgment useful, because none of it is exotic. Before one practice's file server was taken by brute force and held for several months, there had been 27,814 unsuccessful login attempts over ten days, from 2,178 usernames in ten countries. Afterwards, 90 per cent of its desktops had no up-to-date antivirus software, no offsite backups had run, and passwords sat in text files on the server desktop.
Justice Rofe set the standard in a line worth keeping: it is not possible to reduce cybersecurity risk to zero, but it is possible to materially reduce it through adequate documentation and controls. In a technical area, she held, the standard is judged by reference to a reasonable person qualified in that area, not by public expectation. RI Advice was ordered to engage a cybersecurity expert and to pay $750,000 towards ASIC's costs.
The second decision added a penalty. On 9 February 2026 the Federal Court ordered FIIG Securities to pay $2.5 million, and $500,000 towards costs, for failures between 13 March 2019 and 8 June 2023. ASIC called it the first time the Court has imposed civil penalties for cyber security failures under the general AFS licence obligations.
- Put the FIIG findings beside your own environment and mark each item done, partly done or not done: multi-factor authentication for remote access, access controls on privileged accounts, firewall and security software configuration, regular penetration testing and vulnerability scanning, a structured plan for patching key systems, qualified people watching the threat alerts, mandatory awareness training, and an incident response plan tested at least annually.
- Ask who in your arrangement is the relevantly qualified person, and whether they would put in writing that your controls suit a firm of your size holding your kind of client data.
- Note that both decisions turned on documentation as much as on controls. A control nobody can evidence is a hard one to defend.
What Lands on Your Provider's Desk, and What Aligned Has to Mean
All of it reaches the IT provider in the same shape: a request for evidence about controls the provider operates. Under CPS 234 the entity must assess a third party's security capability, evaluate the design of its controls and assess whether their testing is adequate. CPS 230 goes further into the commercial relationship: the entity keeps a register of its material service providers and submits it to APRA every year, and core technology services is one of the categories every APRA-regulated entity must classify as material unless it can justify otherwise.
For a material arrangement CPS 230 requires a formal, legally binding agreement covering the services and service levels, ownership and control of data, audit access, liability and indemnity, and notification when the provider relies on its own material subcontractors. The entity also notifies APRA within 20 business days of entering or materially changing an agreement it relies on for a critical operation. The OAIC is separately explicit that information whose storage you outsource is still information you hold. A provider who cannot answer those questions has not failed at IT. They have failed at the part of IT a financial services firm is buying.
Alignment is the other word that needs discipline here. A useful answer names the framework, the scope, the assessment or maturity level, the assessor, the date, and what that does and does not mean. The Essential Eight is the usual baseline here, and ASIC points licensees to those eight mitigation strategies as a minimum. It is a baseline with three maturity levels rather than a certificate, and this description is current as at September 2026, so read any alignment claim against ASD's guidance on the day.
In practice, IT support for financial services firms means the evidence stays current, not only the systems. inSUPPORT assesses against the compliance frameworks that apply to a client's industry and includes the remediation an audit finds in the support fee, which changes who is motivated to find a gap early. The method behind that is The 6 Step Cyber Strength System.
The cyber insurance questionnaire arrives in the same envelope, and the same evidence answers it. Cover is arranged through licensed insurance partners and underwritten by the insurers themselves, subject to the insurer's assessment, so the evidence does not decide the outcome. The provider is not the licensee there and holds no Australian Financial Services Licence, worth saying plainly to an audience that holds one.
- Ask your provider for your current control evidence today, without letting them prepare it first: the administrative access list, the patch report, the last restore test, the enforced multi-factor exceptions, and the date the incident response plan was last tested. What comes back, and how long it takes, is the first finding.
- Read your own service agreement against what a material arrangement has to contain. Data ownership, audit access, liability and subcontractor notification are contract terms rather than technical settings, so check what yours actually says instead of assuming.
- Require every alignment statement to carry a framework, a scope, a level, an assessor and a date, and strike any that cannot. What an Essential 8 assessment actually involves is the longer version of that sentence.
- If the answers are thin, get an independent read of the environment. A gap analysis turns a suspicion into a costed list a board can act on, and what underwriters check before they cover an Australian business covers the insurance side of the same desk.
Financial services IT support, answered plainly
Do CPS 234 and CPS 230 apply to a financial planning practice or a brokerage?
Not directly, unless the firm is itself an APRA-regulated entity: a deposit-taking institution, a general or life insurer, a private health insurer or an RSE licensee. Both standards share the same application paragraph, so the answer is the same for each. Where a planning practice or a broker feels them is through a client, because a regulated entity has to assess any third party managing its information assets and has to register and contract for its material service providers, so its suppliers get the questions. What does bind a non-APRA firm holding an AFS licence is section 912A, and the Privacy Act if the Act covers it. IT support for financial services firms starts by naming which of the three is doing the asking.
Do we need a specialist provider, or can our current IT company do this?
The test is capability and evidence, not the label on the door. The Federal Court judged adequacy by reference to a reasonable person qualified in the area, so the question for any provider is whether they can name the frameworks they align you to, say what scope and level that covers, and produce your control evidence on request without preparing it first. A generalist who can do that is fine. A specialist who hands you assurances instead of artefacts is not. If your current provider cannot show you your own administrative access list, your patch report and your last restore test this week, you have your answer already.
How long does it take to get to a defensible position?
It depends entirely on where the environment starts, which is why the honest first step is an assessment rather than a quote. Anyone who gives you a timeframe before they have looked is selling you one. What the assessment produces is the useful thing: a control-by-control position with the gaps priced, which a board can approve and a programme can work through. And a timeframe for the work is never a statement about how a regulator, a client or an insurer will view the result. What keeps a position defensible afterwards is that the evidence stays current, because a control documented once and drifted since is the pattern both Federal Court decisions describe.
Where should a financial services firm start?
Write down which of the three obligations you are under and who is asking, because that decides the scope. Then ask your provider for your current control evidence and note what comes back and how long it takes. Then put the FIIG findings list beside your environment and mark each item honestly. Those three steps cost you a week and no money, and they turn a vague worry into a list. If the list is longer than you expected, book an independent look at the environment itself, because IT support for financial services firms is judged on what can be shown.
If a regulator, a client or an insurer asked for your control evidence tomorrow, the useful question is what would come back and how long it would take. A Cyber Strength Audit examines what is actually configured across identity and access, patching, backup and recovery, email and endpoint security, assesses it against the compliance frameworks that apply to your industry, and hands you a plain-English read on where you stand, ranked by business impact, with a costed path to closing the gaps. Kane Nawrocki has spent more than 25 years in IT, and inSUPPORT has run more than 1,500 of these audits for Australian businesses of roughly 30 to 300 users. Evidence you have to go and build on the day somebody asks for it is not evidence you have. Better to know what is there while nobody is asking.
Book a Cyber Strength Audit →Citations
- "Prudential Standard CPS 230 Operational Risk Management, APRA, updated 30 April 2026", Paragraph 2's application to APRA-regulated entities, paragraph 6's commencement of the updated standard on 1 July 2026, the requirement to maintain a register of material service providers and submit it to APRA annually, core technology services as a category classified material for all APRA-regulated entities unless justified otherwise, the minimum contents of a formal agreement for a material arrangement, the 20 business day and offshoring notifications, and the 72-hour operational risk incident and 24-hour critical-operation disruption notifications (paragraphs 2, 6, 32, 41, 48 to 50, 53 and 60). apra.gov.au
- "Operational risk management, APRA, last updated 30 April 2026", APRA's own page for CPS 230, carrying the final targeted amendments released on 30 April 2026 and the statement that the updated CPS 230 and CPG 230 commence on 1 July 2026, plus the Material Service Provider Register template. The July 2023 version of the standard on the same page commences on 1 July 2025 and picks up pre-existing service provider contracts from the earlier of their next renewal or 1 July 2026. apra.gov.au
- "Prudential Standard CPS 234 Information Security, APRA, July 2019", The application paragraph naming which APRA-regulated entities it binds, the 1 July 2019 commencement, the Board's ultimate responsibility, the duties to assess a third party's capability, evaluate its control design and assess its testing, and the 72-hour notification requirement (paragraphs 2 to 5, 13, 16, 22, 28 and 35). Paragraphs 2 to 4 also carry the foreign-branch, holding-company and group-basis application this article states. apra.gov.au
- "Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496, Federal Court of Australia, 5 May 2022", The declarations under sections 912A(1)(a) and (h) for 15 May 2018 to 5 August 2021, the nine incidents between June 2014 and May 2020, the 27,814 login attempts from 2,178 usernames, the antivirus, backup and password findings, the order to engage a cybersecurity expert, the $750,000 costs order, and Justice Rofe's statements on reducing risk and on expert-judged adequacy. download.asic.gov.au
- "What a Federal Court ruling on cybersecurity means for AFS licensees, ASIC, 12 May 2022", ASIC's stated expectations of AFS licensees after the RI Advice decision, its statement that it does not prescribe technical standards, the pointer to the eight essential mitigation strategies as a minimum, and the note that dual-regulated licensees also answer to APRA. asic.gov.au
- "26-021MR ASIC action sees FIIG Securities ordered to pay $2.5 million over cyber security failures, ASIC, 9 February 2026", The $2.5 million penalty and $500,000 costs, the failure period of 13 March 2019 to 8 June 2023, the list of measures the firm did not have in place, and the statement that this is the first time the Court has imposed civil penalties for cyber security failures under the general AFS licence obligations. asic.gov.au
- "Chapter 11: APP 11 Security of personal information, Office of the Australian Information Commissioner, updated 3 October 2025", APP 11.1's reasonable steps duty; paragraphs 11.4 and 11.10, that those steps include technical and organisational measures under APP 11.3; the factors that decide what reasonable means, including outsourcing and the amount and sensitivity of the information; the list of areas reasonable steps should cover, including third-party providers; and paragraph 11.6, that outsourced storage is still information the entity holds. oaic.gov.au
- "The Privacy Act, Office of the Australian Information Commissioner", Which organisations the Privacy Act regulates, including the threshold of more than $3 million in annual turnover and the some other organisations covered regardless of size. oaic.gov.au
- "Data breach notifications increase to all-time high in 2025, new NDB stats show, Office of the Australian Information Commissioner, 6 July 2026", The 1,205 notifications recorded for the 2025 calendar year, an 8 per cent rise on 2024, with health service providers first on 225 and financial services second on 157. oaic.gov.au
Related Reading
- Cyber Strength Audit
- The 6 Step Cyber Strength System
- What Underwriters Check Before They Cover an Australian Business
- AI Governance and the Essential 8: What the Framework Misses
- What Does an Essential 8 Assessment Actually Involve?
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


