The urgency of this initiative stems from a spate of cyberattacks on superannuation funds earlier this year, notably affecting AustralianSuper, the largest fund in the country. Although the impact of these incidents on individual members was reportedly contained, they underscored the superannuation system's vulnerability to cyber threats, especially during periods of market volatility.
APRA's analysis highlights the varied effectiveness of funds' responses to the incidents. Successful entities displayed a deep understanding of their control environments, particularly around payment processes, enabling them to respond swiftly to interrupt transactions and recover funds. However, the overall industry needs to raise its awareness of how such incidents affect public perception and member trust.
Lieutenant General Michelle McGuinness, National Cyber Security Coordinator, emphasised the need for collaboration over competition among superannuation funds, a sentiment echoed in APRA's findings. A crucial issue discussed was the responsibility for coordinating responses to cyber incidents affecting multiple stakeholders, with a consensus that the industry's capability in this area requires development.
The APRA reiterated that while individual fund trustees and operators should address immediate threats during an incident, a broader, coordinated response is necessary to protect the integrity of the superannuation ecosystem. The roundtable has presented both a challenge and an opportunity for the sector to cultivate this capability.