APRA Exposes Key Cybersecurity Flaws in Financial Industry
The Australian Prudential Regulation Authority (APRA) has issued new directives aimed at tackling prevalent cybersecurity vulnerabilities within the financial sector.
This update is a crucial element of APRA’s larger effort to enhance cyber resilience amid ongoing cybersecurity challenges in Australia.
Revealed Cybersecurity Shortcomings in the Financial Sector
The updated guidance draws attention to recurring weaknesses in three primary areas:
- Configuration management
- Privileged access management
- Security testing
APRA urges financial entities to re-evaluate their cybersecurity frameworks in light of these weaknesses and rectify any deficiencies that could compromise their risk management or security stance.
Addressing Cybersecurity Shortcomings in the Financial Sector
APRA stresses the importance of maintaining secure and up-to-date configurations for IT assets, particularly as new vulnerabilities arise.
Entities should adopt robust change management practices to ensure that security configurations remain consistent with the standards outlined in Prudential Practice Guide CPG 234 Information Security (CPG 234).
Regarding privileged access management, APRA highlights the need for precise records of privileged accounts and stringent control over access to critical systems based on legitimate business requirements. Secure storage and protection of access credentials are also emphasized.
The guidance also critiques the limited scope of security testing, advising entities to broaden their testing approaches to cover a wider range of IT assets and employ diverse methodologies, aligning with industry best practices.
APRA reminds entities to report any significant cybersecurity gaps that could impact their risk profile under paragraph 36 of CPS 234.
Continuing its commitment to strengthening financial sector cyber resilience, APRA encourages regular self-assessments, adherence to CPG 234 best practices, and the implementation of mitigation strategies from frameworks like the Essential Eight.
This latest directive underscores APRA’s dedication to enhancing cybersecurity measures and follows previous advisories on data backup security.
Entities with questions are encouraged to contact their assigned supervisor for further guidance and support.



