Scattered Spider made Insurance the next sector.
Four insurers compromised in weeks. An APRA capital charge for a cyber failure. CPS 230 in force. The regulatory environment and the threat environment moved in the same direction at the same time.
Why Insurance is in the crosshairs
Five shifts shaping the Insurance threat environment — from attacker tradecraft to the regulatory trajectory that is closing the gap between what controls look like on paper and whether they actually work.
Scattered Spider pivoted to insurance, and the tradecraft is help desk social engineering
Across June and July 2025, activity with the hallmarks of Scattered Spider hit Erie Insurance, Philadelphia Insurance, Aflac, and Allianz Life. The common entry pattern was not software exploitation — it was voice-based social engineering of IT help desks to reset MFA and credentials. Allianz Life was breached via a third-party CRM. Help desk process is rarely in the scope of a traditional pentest.
Insurers concentrate the data attackers want — and intelligence about everyone else's security
Life insurance holds detailed health records. General insurance holds property, asset, and location data. Cyber insurance holds the detailed cybersecurity architecture of the insured parties themselves. Kroll's framing captured the double exposure — concentrated PII plus concentrated intelligence about other targets. Aflac's final figure reached approximately 22.6 million individuals globally — about 13.9 million of them in the United States.
The Medibank capital charge reframed CPS 234 enforcement
APRA's $250 million increase to Medibank's capital adequacy requirement was the first time APRA imposed capital consequences specifically for a cyber attack. The tripartite assessment programme has since covered more than 300 banks, insurers, and superannuation trustees — and has revealed widespread, systemic gaps, particularly in third-party risk, control testing, and demonstrable evidence of effectiveness.
CPS 230 adds cyber-adjacent resilience requirements that CPS 234 did not
Since 1 July 2025, APRA-regulated entities must identify critical operations — for insurers, including claims processing and customer service — and demonstrate that those operations can withstand disruption. Material service provider resilience must be assessed and tested. A completed material service provider register was due to APRA from insurers by 1 October 2025.
FAR extended to insurance and superannuation — the personal exposure is now direct
Since March 2025, the Financial Accountability Regime has applied to insurers and superannuation trustees. Specific accountable persons now hold personal accountability for CPS 234 and CPS 230 obligations — with disqualification and deferred remuneration on the line. "We tested annually" is increasingly inadequate as a defensible posture for an accountable person.
What regulators and experts are saying
Google Threat Intelligence Group is now aware of multiple intrusions in the US which bear all the hallmarks of Scattered Spider activity. We are now seeing incidents in the insurance industry. Given this actor's history of focusing on a sector at a time, the insurance industry should be on high alert, especially for social engineering schemes which target their help desks and call centers.
The network security of each company — [insurers] are so detailed on the cybersecurity each company has. What a wealth of knowledge to have to know how to attack the next company or industry, or develop tools to go in and attack.
This attack, like many insurance companies are currently experiencing, was caused by a sophisticated cybercrime group… This was part of a cybercrime campaign against the insurance industry.
CPS 230 is in force and FAR now covers insurers
Since 1 July 2025, APRA CPS 230 requires tested operational resilience including critical operations. Since March 2025, the Financial Accountability Regime has extended to insurance and superannuation — accountable persons for information security carry personal accountability, with disqualification and deferred-remuneration consequences.
APRA CPS 234 (Information Security) applies to all APRA-regulated insurers — general, life, private health — and superannuation trustees, with group-wide extension and Australian branch coverage for foreign entities. Paragraph 27 requires systematic testing of control effectiveness commensurate with the rate of change of the environment, the criticality of assets, and the threat environment. CPS 230 (Operational Risk Management) came into force on 1 July 2025 and requires tested resilience of critical operations, including cyber disruption scenarios and material service provider security. The Financial Accountability Regime extended to insurance and superannuation in March 2025, placing CPS 234 and CPS 230 obligations on named accountable persons with personal accountability and deferred-remuneration consequences. The Cyber Security Act 2024 (mandatory ransomware reporting) and the Privacy Act / NDB scheme apply in parallel. Many insurers also adopt ISO 27001 and the Essential Eight voluntarily as CPS 234-supporting frameworks.
Source: APRA — CPS 230 Operational Risk ManagementPrinciples-based information security standard applying to all APRA-regulated insurers and superannuation trustees. Paragraph 27 (testing effectiveness of controls) is the direct hook for continuous validation.
Widely adopted by Australian insurers as a complementary structured framework for CPS 234 evidence. Often required of material service providers.
Where NodeZero appliesNot mandatory for insurers, but commonly adopted as an operational baseline and increasingly expected by enterprise customers and reinsurers.
Where NodeZero appliesStandard service organisation control report for insurtechs, TPAs, claims handlers, and cloud platforms providing services into APRA-regulated entities.
Where NodeZero appliesInsurers hold concentrated PII, payment data, and sensitive health and claims information subject to the Australian Privacy Principles and the NDB scheme.
Where NodeZero appliesMandatory ransomware payment reporting within 72 hours for insurers, brokers, MGAs, TPAs, and insurtechs over $3M turnover.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
APRA CPS 230 — Operational Risk Management
1 Jul 2025In force since 1 July 2025. Requires identification of critical operations (for insurers, including claims processing and customer service), tested business continuity, and material service provider resilience. A completed material service provider register was due to APRA by 1 October 2025. Pre-existing service provider contracts must comply by the earlier of next renewal or 1 July 2026.
Source: APRA — CPS 230Financial Accountability Regime (FAR) — insurance and superannuation
Mar 2025Extended to insurance and superannuation from March 2025. Specific accountable persons now hold personal accountability for CPS 234 information security and CPS 230 operational risk obligations. Disqualification and deferred remuneration are at risk for compliance failures.
Source: APRA — Financial Accountability RegimeCyber Security Act 2024
30 May 2025Mandatory ransomware payment reporting within 72 hours for entities over $3M turnover. Captures essentially all APRA-regulated entities, brokers, MGAs, TPAs, and insurtechs. A ransomware event at an APRA-regulated insurer now triggers both the CPS 234 72-hour notification to APRA and the Cyber Security Act 72-hour notification to ASD.
Source: Cyber Security Act 2024Privacy Act reform — statutory tort and expanded enforcement
2024–2026Introduction of a statutory tort for serious invasions of privacy, expanded OAIC enforcement powers, and tightened obligations around automated decision-making. Insurers — whose models increasingly incorporate algorithmic underwriting and claims decisioning — face a sharper regulatory environment. Both the OAIC and APRA took action following the Medibank incident.
Source: OAIC — Notifiable Data Breaches SchemeNodeZero produces the continuous evidence. Drochaid helps you bridge to the full CPS 234 and CPS 230 programme.
CPS 234 and CPS 230 obligations extend well beyond control testing — they cover policy, governance, operational risk, and tripartite reporting, and many insurers engage a Big 4 or specialist advisor across that breadth. NodeZero directly validates the control-testing obligation, producing the evidence paragraph 27 demands and the tripartite assessor asks for — continuously, not once a year. Drochaid helps you bridge from NodeZero's testing evidence to the full programme: board reporting, tripartite preparation, and the remediation record.
Find your organisation
See how the changes affect you specifically
General, life & health insurers
APRA-regulated insurers carrying full CPS 234, CPS 230, and FAR obligations — with concentrated PII, health, and claims data exposure.
View details →Superannuation trustees
RSE licensees managing concentrated member data and payment authorities. Targeted through the 2025 credential-stuffing wave, after which APRA directed all trustees to self-assess their controls under CPS 234.
View details →Brokers, MGAs & insurtech
Not APRA-regulated directly, but embedded in APRA-regulated supply chains under CPS 234 third-party obligations and CPS 230 material service provider requirements.
View details →The only autonomous pentesting platform that is:
References
Everything cited on this page — regulator reports, incident coverage, and official framework documentation.
See your CPS 234 and CPS 230 gaps before your tripartite assessor does
Book a baseline assessment mapped to paragraph 27 control effectiveness and CPS 230 critical operations


