APRA CPS 234 penetration testing is how APRA-regulated entities demonstrate that their information security controls actually work under pressure, rather than only on paper. The Prudential Standard CPS 234 Information Security requires banks, insurers and superannuation trustees to systematically test the effectiveness of their controls at a frequency that reflects how fast threats change and how critical each asset is.
This guide explains what CPS 234 requires, where board accountability sits, how the standard connects to broader operational resilience obligations under CPS 230, and what testing evidence APRA expects to see. It is written for Australian financial services teams who need to turn a compliance obligation into genuine, defensible assurance.
What CPS 234 Actually Requires
CPS 234 sets baseline expectations for information security across the entities APRA regulates. It is principles-based rather than prescriptive, which means it describes outcomes you must achieve rather than a checklist of tools to buy. The core obligations include:
- Clearly defining the information security roles and responsibilities of the board, senior management, governing bodies and individuals.
- Maintaining an information security capability commensurate with the size and extent of threats to your information assets.
- Implementing controls to protect information assets, and undertaking systematic testing of the effectiveness of those controls.
- Notifying APRA of material information security incidents, generally within 72 hours, and of material control weaknesses that cannot be remediated in a timely way.
The phrase that matters most for testing is control effectiveness. It is not enough to have a firewall, an identity platform or an endpoint tool. You must be able to show that these controls stop the kinds of attacks a capable adversary would actually attempt.
Who CPS 234 Applies To
The standard applies to APRA-regulated entities, and the categories are broad. If your organisation sits within the prudential framework, CPS 234 almost certainly applies to you. In scope are:
- Authorised deposit-taking institutions, including banks, building societies and credit unions.
- General insurers, life insurers and private health insurers.
- Registrable superannuation entity licensees and the funds they manage.
- Licensed non-operating holding companies within regulated groups.
Because these entities hold highly sensitive financial and personal data, and because a serious incident can undermine confidence in the wider financial system, APRA treats information security as a prudential matter, not merely an IT concern.
Testing the Effectiveness of Your Controls
This is where offensive security testing does its most valuable work. CPS 234 requires a systematic testing program, and the frequency of testing must be commensurate with three things: the rate at which vulnerabilities and threats change, the criticality and sensitivity of the asset, and the potential consequences of an incident.
In practice, that risk-based approach usually means:
- High-criticality, internet-facing and data-rich systems are tested more often and more deeply.
- Significant changes, such as major releases or new integrations, trigger fresh testing rather than waiting for a calendar date.
- Testing depth scales with risk, so crown-jewel assets warrant hands-on assessment by skilled testers, not only automated scanning.
A well-run penetration testing program gives you direct evidence of whether controls hold. For entities that want to test detection and response as well as prevention, a red team engagement simulates a realistic adversary across people, process and technology, which is exactly the kind of end-to-end assurance boards increasingly ask for.
Board Accountability and Governance
CPS 234 places ultimate responsibility for information security with the board of the regulated entity. This accountability is deliberate and cannot be outsourced. Even where technology or operations sit with a third party, the board remains answerable for the security of the entity's information assets.
For directors and executives, that means:
- Ensuring the entity maintains an information security capability that matches its threat profile.
- Commissioning independent testing and genuinely reviewing the results, including uncomfortable findings.
- Tracking remediation of significant weaknesses through to closure and validating that fixes worked.
- Receiving reporting that is clear enough to support informed oversight, not buried in technical detail.
Testing evidence is most powerful when it feeds this governance loop. A report that sits unread does little for compliance. A report whose findings are triaged, remediated and retested demonstrates the active oversight the standard expects.
The CPS 230 Operational Resilience Context
CPS 234 no longer stands alone. Prudential Standard CPS 230 Operational Risk Management, now in force, broadens the lens to operational resilience and the management of critical operations, including those delivered through material service providers. The two standards reinforce each other.
Key connections for your testing program:
- Third-party risk: CPS 234 already requires you to assess the information security capabilities of third parties handling your information assets. CPS 230 sharpens the focus on material service providers and critical operations.
- Critical operations: testing scope should consider the systems and connections that underpin the operations your organisation cannot afford to lose.
- End-to-end view: resilience is about withstanding and recovering from disruption, so testing that exercises detection and response, and validates recovery assumptions, is increasingly relevant.
Where a serious weakness is found, having a rehearsed response matters. Coordinating testing outcomes with your incident response planning helps ensure that if prevention fails, detection and recovery do not.
Building Evidence APRA Expects
APRA supervisors and independent reviewers look for a systematic, risk-based program, not a single tick-box report. To build defensible evidence:
- Document a clear testing methodology and tie scope to asset criticality and sensitivity.
- Test at a frequency justified by risk, and record the reasoning behind that cadence.
- Rate findings by severity, track remediation, and retest to confirm that fixes actually worked.
- Report results to the board or relevant committee, and record the decisions and actions taken.
- Review your program periodically, especially after material changes to your environment or threat landscape.
Understanding where your organisation sits today also helps. A security maturity assessment can benchmark your current controls and governance against the outcomes CPS 234 requires, so you can invest testing effort where it matters most rather than spreading it thinly.
Common Scoping Mistakes to Avoid
Even well-intentioned CPS 234 programs can fall short if the testing is scoped poorly. Because the standard is principles-based, there is real room to get the approach wrong while still producing plenty of reports. The most common pitfalls include:
- Treating testing as an annual formality rather than a risk-based, continuous activity that responds to change.
- Scoping to the systems that are easy to test rather than the assets that would hurt most if compromised.
- Relying on automated scanning alone and describing it as a control effectiveness test, when it cannot demonstrate whether a capable attacker is actually stopped.
- Focusing narrowly on the entity's own systems while ignoring the critical third-party connections that CPS 234 and CPS 230 clearly bring into scope.
- Producing findings but never validating that remediation worked, which leaves the loop open and the assurance incomplete.
Avoiding these mistakes is largely about intent. A program designed to genuinely reduce risk, rather than to generate paperwork, naturally scopes to criticality, blends manual depth with automation, and closes findings through retesting. That mindset is exactly what supervisors and boards are looking for when they ask whether the entity's controls are effective.
Turning Obligation Into Assurance
CPS 234 is best treated not as a compliance burden but as a framework for genuine assurance. The entities that handle it well use systematic testing to find weaknesses before an attacker does, to give their boards real visibility, and to demonstrate to APRA that their controls are effective in practice.
If you need CPS 234 testing scoped around your real risks and reported in a way your board and regulator can rely on, our team of expert operators can help. Explore our penetration testing services, review our red teaming capability, or get in touch for a scoping conversation. You can also call StrikeCyber on 1300 654 898.
Frequently asked questions
What is APRA CPS 234?
CPS 234 Information Security is a prudential standard from the Australian Prudential Regulation Authority that applies to APRA-regulated entities, including banks, insurers and superannuation trustees. It requires these organisations to maintain information security capabilities commensurate with the threats they face, clearly define roles and responsibilities, and systematically test the effectiveness of their security controls. The board holds ultimate accountability for information security under the standard.
Does CPS 234 require penetration testing?
CPS 234 does not name penetration testing explicitly, but it requires entities to test the effectiveness of their information security controls through a systematic testing program. Penetration testing is one of the most direct ways to demonstrate whether controls actually stop a capable attacker. Most APRA-regulated entities use penetration testing, and often red teaming, as core evidence that their controls work as intended rather than only on paper.
How often should CPS 234 testing happen?
The standard requires testing at a frequency commensurate with the rate at which vulnerabilities and threats change, the criticality and sensitivity of the asset, and the consequences of an incident. In practice this means high-criticality systems are tested more often than low-risk ones. Many entities combine annual or more frequent penetration testing with continuous assurance activities so that significant changes trigger fresh testing rather than waiting for a fixed calendar date.
Who is accountable for CPS 234 compliance?
The board of the APRA-regulated entity is ultimately responsible for the information security of the organisation. This accountability cannot be delegated away, even when technology or services are outsourced to third parties. Boards are expected to ensure the entity maintains adequate information security capability, and that includes commissioning independent testing and reviewing the results, not simply accepting management assurances at face value.
Does CPS 234 apply to third-party providers?
Yes. CPS 234 requires entities to assess the information security capabilities of third parties that manage their information assets, and to ensure those capabilities are commensurate with the sensitivity and criticality of the assets involved. This is reinforced by CPS 230 on operational risk management. Entities remain accountable for security even where a supplier does the work, so testing scope often needs to consider critical third-party connections and shared platforms.
What evidence does APRA expect from testing?
APRA looks for a systematic, risk-based testing program rather than a single report. Useful evidence includes a defined testing methodology, clear scope tied to asset criticality, findings with severity ratings, remediation tracking, and validation that fixes actually worked through retesting. Board and committee reporting that shows results were reviewed and acted upon is important, as it demonstrates the governance and accountability the standard requires.
