Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Missing Mandate In Australia’s Efforts To Protect The Finance Sector From Cyber Threats
Articles

The Missing Mandate In Australia’s Efforts To Protect The Finance Sector From Cyber Threats

ISBuzz TeamBy ISBuzz TeamJune 6, 20194 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Australia’s financial services industry regulator has a new information security standard that is set to kick in from July, opening up a potential pathway to a much-needed national intelligence-led attack simulation scheme for the industry.

The Australian Prudential Regulation Authority’s (APRA) incoming CPS 234 standard on information security, which late last year was fast-tracked “due to the urgency of the threat”, essentially compels relevant providers to have adequate measures in place to protect customer information and be resilient against potential cyber-attacks.

Combined with APRA’s recently announced new Enforcement Approach, which will see the regulator take a stronger role in enforcing regulatory compliance, the scene is nearly set for the shaping of a financial services industry with a progressively robust and world-leading security posture.

This is a good start. The new standard calls for APRA-regulated financial services providers to maintain an information security capability commensurate with the size and extent of the threats to their information assets. It also mandates that relevant entities also need to test the effectiveness of information security controls through a systematic testing program.

Thanks to the nature of this systematic testing directive, the incoming standard effectively opens up scope for a scheme that flexes one of the most important security tools in any enterprise’s toolkit: threat intelligence-led attack simulation.

However, while the CPS 234 standard creates an opportunity for such a scheme, there is yet to be any clear indication from APRA that it actually plans to introduce an all-important initiative to support the incoming standard in terms of real-world threat prevention regimes.

And the value of an intelligence-led attack simulation regime cannot be overstated. Unlike traditional penetration testing, intelligence-led attack simulation exercises involve gathering threat intelligence to identify the real-world adversaries and the critical economic functions they are targeting within actual financial institutions.

Using this regime, further intelligence is able to identify the tactics, techniques and procedures (TTPs) commonly employed by specific adversaries. This allows a penetration testing team to simulate those specific adversaries using the same TTPs through a number of attack scenarios.

Such exercises commonly find weaknesses in the people, processes and technology within an organisation, along with the organisation’s ability to detect, respond to, and recover from the simulated attack. As a result, simulation exercises almost always provide a better understanding of an organisation’s overall resilience to attack than other methodologies.

This is perhaps why the Bank of England in the United Kingdom established an intelligence-led assurance framework in 2015, with the European Central Bank since launching a region-wide initiative supporting intelligence-led attack simulation.

The Hong Kong Monetary Authority, meanwhile, requires financial institutions to engage in intelligence-led cyber attack simulation testing and the Association of Banks in Singapore’s financial industry best practices guidelines rely heavily on similar attack simulation practices.

Given that some of the world’s leading financial services industry markets appear to not only be in favour of, but actively mandating, intelligence-led attack simulation, it’s clearly a major regulatory initiative that needs to be implemented in one of Australia’s biggest and most important industry sectors.

Let’s not forget that APRA-regulated entities hold somewhere in the vicinity of A$6.5 trillion in assets. It is one of the most important industries to the Australian economy, and also one of the most highly targeted by cyber criminals.

With this in mind, APRA clearly needs to go one step beyond the CPS 234 standard itself and roll out a supporting scheme aimed at mandating an intelligence-led attack simulation regime among all APRA-regulated entities of a certain size.

But what would such a regime look like in practice? APRA could begin by looking to those markets around the world that already have relatively well-established schemes making effective use of threat intelligence-led attack simulation practices, such as those already mentioned: Singapore, Hong Kong, Europe and the United Kingdom.

Indeed, the United Kingdom’s central bank was the first financial regulator to implement a threat-intelligence led attack simulation regime. In 2015 the Bank of England created CBEST, an intelligence-led assurance framework.

The CBEST framework, which was designed specifically for financial institutions, requires a CREST-certified threat intelligence provider to identify a financial institution’s potential cyber adversaries and a similarly accredited penetration testing provider – or red team – to simulate attacks by such adversaries.

If we take the Bank of England’s example as just one template from which APRA can draw upon to create an intelligence-led attack simulation scheme, Australian financial services providers could very well end up going toe-to-toe with the global financial industry leaders in terms of security posture.

But it will take commitment and foresight by APRA to get Australia to that point. With the CPS 234 standard set to take effect, the opportunity for APRA to step up to the plate is now here.  

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}