In a renewed call to action, APRA's General Manager of Operational Resilience, Alison Bliss, conveyed through a letter that organizations need to assess their current control frameworks against identified weaknesses. Immediate rectification of these gaps is mandated to safeguard the entities' risk profiles and financial stability.

"APRA demands that regulated entities scrutinize their controls, addressing any deficiencies expediently," Alison Bliss emphasized. "Failures that significantly impact risk profiles or financial health are categorized as major security control weaknesses under the CPS 234 Information Security standards."

Insurers are urged to "stay alert and proactively employ strategies to mitigate risks from the dynamic and intensifying cyber threat landscape," added Bliss. She underscored the necessity for robust identification and authentication protocols to prevent identity falsification.

Frequent self-evaluation and the adoption of established cyber-safety strategies are crucial steps recommended by APRA. Practical tips include:

  • Timely remediation of vulnerabilities due to insecure configurations in information assets.
  • Maintaining comprehensive records of privileged accounts and ensuring data access is granted only for well-justified business needs and for a limited period.

Further, APRA advocates conducting a variety of modern security tests regularly. Insurers should report test outcomes to the appropriate authority or individual and monitor the implementation of corrective actions methodically.

The ongoing advisories from APRA follow a previous notification sent in June, underscoring the necessity to pivot swiftly towards stronger cyber defenses. As emerging cybersecurity threats loom, APRA’s persistent emphasis reflects a broader trend of regulatory bodies cracking down on cyber vulnerabilities to protect financial ecosystems.