A comprehensive cybersecurity assessment conducted by APRA (Australian Prudential Regulation Authority) continues to unveil vulnerabilities in how third parties handle data and meet security standards within Australia’s finance sector.
This ongoing assessment, expected to cover over 300 banks, insurers, and superannuation trustees by the end of 2023, marks the largest study of its kind conducted by APRA.
To date, APRA has assessed a quarter of the entities, and the results closely resemble those of a smaller sample assessed in 2021.
Supply chain security remains a concern within the finance sector, along with the need for incident response plans that test plausible disruption scenarios. The majority of the findings revolve around supply chain risk. APRA noted that third-party-managed information assets were inadequately identified and classified, with some cases lacking identification altogether.
Insufficient identification and classification make it challenging for entities to determine appropriate information security controls to safeguard critical and sensitive data from unauthorized access or disclosure, according to APRA.
Given the growing reliance on service providers for managing critical systems, APRA emphasized the necessity for stronger assurance of providers’ information security controls.
APRA expressed dissatisfaction with the depth of assessments conducted on providers’ controls, noting instances where no independent assessments were performed at all.
Even in cases where controls were independently assessed, APRA found that internal auditors lacked the necessary information security skills in some instances.
Furthermore, APRA discovered that contracts with critical third parties did not include requirements to report material incidents and control weaknesses to APRA, as mandated.
In addition to supply chain risks, APRA raised concerns regarding incident response plans, noting that they often focused on implausible scenarios or lacked sufficient testing.
Following a pilot assessment in 2021, APRA expressed concerns about the finance sector’s lack of preparedness in ransomware incident response. Consequently, APRA now urges a broader range of scenarios to be tested, encompassing data breaches, credential compromises, denial-of-service attacks, hacks of internet-facing platforms, and compromises by advanced persistent threats.
APRA stated that it intensifies supervisory oversight in areas where compliance gaps are identified.


