CPS 234 Explained: Why Cyber Security Is a Board Issue
Show Links
CPS 234 has quickly become one of the most important—and misunderstood—cyber security standards in Australia. In this episode of the Don’t Be A Sitting Duck Podcast, Leigh Kefford explains what CPS 234 actually requires, why boards are now accountable for cyber security, and how regulators expect organisations to manage cyber risk. Whether you’re directly regulated by APRA or not, CPS 234 is shaping the future of cyber governance across all industries.
What CPS 234 Is Really About – Why APRA introduced CPS 234 and how it reframes cyber security as a business risk, not just a technical issue.
Board Accountability for Cyber Security – How CPS 234 makes boards ultimately responsible for information security outcomes.
Testing, Third Parties, and Incident Response – Why documented controls aren’t enough, how third-party risk is treated, and what happens when an incident occurs.
Closing Reflection
CPS 234 sends a clear message: cyber security failures are governance failures. Organisations that don’t understand their risks, test their controls, and prepare for incidents will eventually be exposed—by regulators, insurers, or attackers.
Key Takeaways
Cyber security is now a board-level responsibility
Security controls must be tested, not assumed
Third-party providers do not remove accountability
Incident response speed and reporting matter
Episode Transcript
Cyber security regulation doesn’t usually make headlines—until something goes wrong. And right now, one of the most misunderstood and underestimated requirements in Australia is APRA’s CPS 234 Information Security standard. We’re seeing organisations scramble at the last minute, boards asking the wrong questions, and businesses assuming this only applies to banks—when the reality is far broader and far more serious. Today, we’re breaking down what CPS 234 actually requires, why regulators care so much about it, and what happens when security controls fail. This episode is about accountability, resilience, and why cyber security is now a board-level responsibility, not just an IT issue.
Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford—let’s dive in.
CPS 234 is APRA’s prudential standard designed to ensure organisations are resilient against information security incidents, including cyber attacks. It applies to APRA-regulated entities like banks, insurers, superannuation funds, and private health insurers—but its expectations are quickly becoming the benchmark for all Australian businesses that handle sensitive data.
At its core, CPS 234 makes one thing very clear: the board is ultimately responsible for information security. Not the IT manager. Not the outsourced provider. The board. The standard requires organisations to maintain security capabilities that match their level of risk, protect information assets based on how critical and sensitive they are, and be able to detect, respond to, and report incidents quickly and effectively.
So how does this actually play out in the real world?
First, CPS 234 requires organisations to clearly define who is responsible for information security at every level—from the board through to operational staff. Vague ownership is no longer acceptable. If no one owns security, everyone is exposed.
Second, organisations must identify and classify all information assets. That includes systems, data, software, hardware, and even information managed by third parties. Once classified, security controls must be applied based on how damaging a loss of confidentiality, integrity, or availability would be.
Third, controls must be tested. Not assumed. Not ticked off once a year. CPS 234 explicitly requires systematic testing of security controls by skilled and independent specialists. If you don’t know whether your controls work, APRA considers them not to exist.
Another critical area is third-party risk. If your data is managed by an external provider—cloud platforms, managed service providers, software vendors—you are still accountable. CPS 234 requires organisations to assess the security capability of those third parties and ensure their controls are adequate.
Then there’s incident response. Organisations must be able to detect and respond to security incidents quickly, have documented response plans, test those plans annually, and escalate incidents appropriately. If a material incident occurs, APRA must be notified within 72 hours. If there’s a control weakness that can’t be fixed quickly, APRA must be notified within 10 business days.
Why does all of this matter?
Because regulators have learned that cyber incidents don’t just cause IT outages—they threaten financial stability, customer trust, and business continuity. Ransomware, data breaches, and system outages now represent systemic risk. CPS 234 exists to force organisations to treat cyber security with the same seriousness as financial controls.
And here’s the real takeaway for business leaders listening today: even if CPS 234 doesn’t legally apply to your organisation yet, its expectations will. Insurers, auditors, supply-chain partners, and regulators are already using CPS 234 as a yardstick. If you can’t demonstrate governance, testing, and accountability, you will eventually be exposed.
So what should you do next?
Start at the top. Make sure your board understands its responsibility for cyber security. Identify and classify your information assets. Review whether your controls are actually tested—not just documented. Assess your third-party providers. And make sure you have a realistic, tested incident response plan.
Because in today’s environment, hoping nothing happens is not a strategy.
That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.
Until next time—stay safe, stay informed, and don’t be a sitting duck!
This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.



