What needs to be improved?

Areas that need improvement include a lack of rigor in the nature and frequency of security control testing, insufficient board oversight on cyber, incident response plans not regularly reviewed or tested, insufficient safeguards to protect sensitive customer data, and inadequate service provider oversight arrangements. APRA has asked firms to review their response to the prudential standard, and continous improvement in cyber resilience remained one of APRA's top priorities, according to APRA Chair John Lonsdale.

Operational risk management

APRA is also in the process of finalizing the operational risk management prudential standard CPS 230 to replace five existing standards for business continuity and outsourcing. Mr. Lonsdale said that cyber security is just one of many risks and that entities should ensure they identify and manage all operational risks effectively, deliver critical operations during disruptions, and prudently manage the risks of service providers. He emphasized that APRA is prepared to take enforcement action if necessary to avoid a costly and damaging cyber incident or other operational risk event.

Increased financial volatility

The financial environment has become more volatile, with an increased frequency of events outside the scope of what financial institutions typically model for. These risks include fluctuations in commodity prices, interest rate movements, and extreme weather events. Mr. Lonsdale said that the causes and impact of this greater financial volatility is something regulators need to examine as well.