DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/CPS 234
Australia & NZ compliance

APRA CPS 234 — Information Security

The mandatory information security standard for all APRA-regulated financial institutions -- banks, insurers, and superannuation funds. A principles-based standard requiring entities to maintain security capability commensurate with the threats they face.

See where NodeZero applies

What is CPS 234?

APRA Prudential Standard CPS 234 is the mandatory information security standard for all entities regulated by the Australian Prudential Regulation Authority -- banks, insurers, superannuation funds, and other financial institutions holding some $9.8 trillion in assets. Unlike prescriptive frameworks that list specific controls, CPS 234 is principles-based: it requires entities to maintain information security capability "commensurate with the size and extent of threats to its information assets" and to "test the effectiveness of its information security controls through a systematic testing program."

That principles-based approach gives regulated entities flexibility, but it also raises the bar for evidence. APRA expects boards to define clear roles and responsibilities, entities to classify and protect information assets, and -- critically -- to test controls with a rigour and frequency that matches the threat landscape. CPS 234 explicitly requires that testing be conducted by "appropriately skilled and functionally independent specialists," and that material incidents and control weaknesses be reported to APRA within prescribed timeframes (72 hours for incidents, 10 business days for control weaknesses).

APRA Prudential Standard CPS 234

Where NodeZero applies

NodeZero directly addresses the testing obligation at the heart of CPS 234 (paras 27-29). Autonomous pentesting provides evidence-based testing whose findings are not shaped by the team that owns the controls — with proof-of-exploit output that clearly distinguishes exploitable controls from merely configured ones, evidence you can put in front of an APRA supervisor. Strong coverage also extends into control implementation (network, credentials, cloud IAM, EDR), information-asset classification (discovery + data-impact analysis), and incident-management validation (active deception + SOC validation). Governance obligations (board accountability, APRA notification, internal audit) sit outside autonomous testing — we flag them explicitly.

APRA CPS 234 (Jul 2019)

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Please note the following require separate evidence: Roles and responsibilities, Internal audit and APRA notification.

Showing coverage grouped by compliance category.

Information security capability

Narrow coverage. NodeZero contributes the threat-commensurate testing capability the standard requires entities to maintain and actively update.

Internal pentestingCore

Provides on-demand attacker-perspective testing capability sized to whatever threats the entity faces — autonomous, scalable, and always available rather than dependent on scheduled engagements.

Rapid ResponsePro & Elite

Targeted tests for newly disclosed critical CVEs are released as the threat landscape changes — keeps the testing capability actively current with respect to changes in vulnerabilities and threats.

2 controls mapped

Information asset identification and classification

Partial coverage. NodeZero discovers assets and identifies what an attacker could actually exfiltrate.

Internal pentestingCore

Enumerates every reachable host and service from the attacker perspective — often surfacing assets missing from the information-asset register para 20 requires you to classify.

High-Value TargetingElite only

Identifies the small set of assets that carry most of the business risk and maps them to business-impact categories — concrete input to the material-affect judgement para 20 expects.

Advanced Data PilferingElite only

Auto-classifies the data an attacker could actually reach against 12 business-risk categories — concrete evidence of whether confidentiality could be lost. Processing happens locally on your Docker host; no data leaves your network.

3 controls mapped

Implementation of controls

Strong coverage. NodeZero tests whether implemented controls actually prevent exploitation.

Internal pentestingCore

Returns proof of which controls actually prevent exploitation under current vulnerabilities and threats — evidence you can put in front of an APRA supervisor beyond configuration screenshots.

Segmentation testingCore

Enumerates IPs, ports, services, and applications to validate network controls around critical information assets hold against current threats.

AD Password AuditCore

Credential audit is a prevention measure — finds weak, breached, or reused passwords that reduce the likelihood of a credential-driven information security incident.

Cloud pentestingCore

Where an entity runs its own cloud tenant, cloud pentesting gives direct evidence of whether the entity's cloud IAM and configuration controls resist exploitation. Evaluating a third party's control design under paragraph 22 remains organisational governance NodeZero does not perform.

Endpoint Security EffectivenessCore

EDR is the canonical detection-and-response measure under p.12(g). NodeZero reports per-host block/allow outcomes across 40+ EDR vendors mapped to MITRE ATT&CK — direct evidence the detection/response measure reduces likelihood and impact.

Identity Security ValidationCore

Runs credential harvest, replay, privilege escalation and lateral movement against your real IAM, PAM and identity threat detection and response tooling — direct evidence of whether those prevention and detection measures actually hold.

Insider Threat TestingCore

Starts from an authenticated user's position and proves the reach of over-provisioned or stale access, credential reuse, and weak user-to-server segmentation — direct evidence of whether controls are commensurate with the malicious-insider threat CPS 234 contemplates for a financial institution.

External pentestingCore

Tests whether your internet-facing interconnects with related and third parties can actually be exploited — direct evidence for the technical slice of paragraph 22. Evaluating a third party's own control design remains organisational governance NodeZero does not perform.

4 controls mapped

Incident management

Narrow coverage. NodeZero contributes active deception and detection validation.

NodeZero TripwiresPro & Elite

Tripwires drop decoys on high-risk assets during testing and fire a high-fidelity alert on any interaction — direct evidence of whether your detection and response can actually see an attacker, complementing rather than replacing your SIEM/EDR. Detection of real incidents and the paragraph 35 notification decision remain your operational responsibility.

Internal pentestingCore

Every NodeZero action is timestamped with proofs and commands, giving you a realistic attacker scenario to run the plausible-incident response plans paragraph 24 requires against real attacker behaviour.

Advanced Data PilferingElite only

Emulates stealthy exfiltration — slow exfil and impersonated-user access — to test whether your defences actually notice: direct evidence of whether your mechanisms to detect and respond to incidents catch data leaving the network, complementing the Tripwires deception layer above.

3 controls mapped

Testing of controls

Strongest alignment — autonomous pentesting is exactly what paragraphs 27-31 ask for.

Internal pentestingCore

NodeZero delivers the systematic testing programme paragraph 27 requires — on demand, at any cadence that matches your rate of threat change.

Web application pentestingPriced separately

Extends the systematic testing programme to the applications APRA-regulated entities put in front of customers and members — authenticated, role-based testing for access-control failures, injection and business-logic flaws, on the same on-demand cadence. Programme scope and sufficiency review remain paragraph 31 governance.

Rapid ResponsePro & Elite

Continuous testing between annual reviews with targeted tests for newly disclosed critical CVEs — matches the rate of threat change paragraph 27(a) refers to.

Quick VerifyCore

Re-test remediation with Quick Verify — produces audit-ready evidence of which control deficiencies were remediated in a timely manner versus which require Board escalation.

Vulnerability Risk IntelligenceElite only

Overlays attacker-first validation on your existing scanner outputs — concrete input to the annual sufficiency review of the testing programme.

5 controls mapped
CPS 234 kit

See every control mapped to NodeZero

The full control-by-control coverage map — every CPS 234requirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

CPS 234 is mandatory for every entity regulated by the Australian Prudential Regulation Authority. This includes authorised deposit-taking institutions (banks, credit unions, building societies), general insurers, life insurers, private health insurers, non-operating holding companies, and registrable superannuation entity (RSE) licensees. APRA currently supervises 1,147 entities holding some $9.8 trillion in assets for Australian depositors, policyholders, and superannuation members.

The standard also extends to related parties and third-party service providers. If your organisation provides material IT services to an APRA-regulated entity -- such as cloud hosting, managed security, or core banking platforms -- your client's CPS 234 obligations require them to assess and monitor your information security controls. This means CPS 234 requirements flow down through the supply chain, even to organisations that are not directly APRA-regulated.

APRA has demonstrated a willingness to enforce CPS 234 through formal supervisory actions. Entities must notify APRA of material information security incidents within 72 hours and material control weaknesses that cannot be remediated in a timely manner within 10 business days. If your organisation falls under APRA's supervision, or provides critical services to one that does, CPS 234 compliance is not optional.

FAQ

Common questions

What is CPS 234 and who does it apply to?

APRA Prudential Standard CPS 234 is the information security standard binding all APRA-regulated entities — authorised deposit-taking institutions (banks, credit unions and building societies), general, life and private health insurers, non-operating holding companies, and RSE licensees. It requires an information security capability "commensurate with the size and extent of threats to its information assets". As at its 2024-25 annual report, APRA supervised 1,147 entities holding some $9.8 trillion in assets.

APRA — CPS 234
What does CPS 234 require for control testing?

Paragraph 27 requires an entity to "test the effectiveness of its information security controls through a systematic testing program", with nature and frequency commensurate with "the rate at which the vulnerabilities and threats change". Paragraph 30 requires testing by "appropriately skilled and functionally independent specialists", and paragraph 29 requires escalating testing results that identify control deficiencies that cannot be remediated in a timely manner to the Board or senior management.

APRA — CPS 234 (PDF)
How does NodeZero help meet the systematic testing requirement?

NodeZero directly addresses the testing obligation in paragraphs 27–31 — its strongest alignment with CPS 234. It runs the systematic testing programme on demand, at any cadence matching your rate of threat change, with targeted tests for newly disclosed critical CVEs and proof-of-exploit evidence showing which controls actually prevent exploitation. Third-party testing assessment, annual sufficiency review governance, scope definition and internal audit integration remain your responsibility.

APRA — CPS 234 (PDF)
Is NodeZero functionally independent testing under CPS 234?

NodeZero testing is functionally independent of the teams that operate your controls — it is not run by your IT team, and it is backed by Horizon3's attack research team. Whether your overall testing program satisfies paragraph 30 is a judgement for your compliance function; NodeZero gives that judgement attack-based evidence to stand on, alongside the pentest, scanner and breach-and-attack-simulation work it replaces.

APRA — CPS 234 (PDF)
Does NodeZero help with the board's information security responsibility?

NodeZero supplies the evidence, not the governance. Board-level definition of information security roles and responsibilities is a governance obligation NodeZero does not cover — we flag that explicitly. What it provides is attack-based evidence for the reporting paragraph 29 requires: escalating control deficiencies that cannot be remediated in a timely manner, with Quick Verify re-tests producing audit-ready evidence of what was fixed and what needs Board escalation.

APRA — CPS 234
How does CPS 230 relate to CPS 234?

CPS 230, APRA's operational risk management standard, commenced on 1 July 2025, with an amended version in force from 1 July 2026. It requires tolerance levels for each critical operation — maximum outage time, maximum data loss, minimum service levels — and a systematic testing program for business continuity plans, including an annual exercise. CPS 234 control effectiveness feeds that operational resilience evidence, so the two standards compound.

APRA — CPS 230
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.