DrochaidHorizon3.ai
NodeZero/Industries/Insurance/Brokers, MGAs & insurtech
Insurance — Brokers, MGAs & insurtech

You're not the APRA-regulated entity. You're the third party their CPS 234 assessor is asking about.

Brokers, MGAs, claims handlers, TPAs, and insurtech platforms are not APRA-regulated directly — but you sit inside APRA-regulated supply chains under CPS 234's third-party service-provider obligations and CPS 230 material service provider requirements. Your insurer customers are being asked to evidence the security of the information assets they manage through you. Allianz Life was breached in July 2025 via a third-party CRM. The Cyber Security Act still applies to you over $3M turnover.

Your specific challenges

Your customers now need third-party evidence

Under CPS 234, APRA-regulated entities must ensure the security of information assets managed by their service providers. CPS 230 extends this to material service providers more broadly. SOC 2 reports are often being treated as insufficient on their own.

Allianz Life changed the conversation

The Allianz Life breach via a third-party CRM made "our vendor was compromised" a CPS 234 topic directly, not just a commercial risk. Third-party privileged access paths are now explicitly in scope.

Mandatory ransomware reporting still applies

Cyber Security Act 2024 mandatory ransomware reporting covers you over $3M turnover — independent of whether your insurer customer also has to report.

How NodeZero helps

Built for your situation

01

Third-party attestation customers can use

NodeZero findings provide structured evidence your APRA-regulated customers can include in their CPS 234 third-party assurance — going beyond a SOC 2 point-in-time report.

02

Cloud CRM and platform testing

Cloud Pentesting validates the attack surface Allianz Life's attackers exploited — CRM platform compromise paths, cloud misconfiguration, and privileged vendor access.

03

Ransomware path reduction

Pre-incident AD Password Audit, Phishing Impact, and credential-reuse testing target the attack paths ransomware actors exploit — and produce the "vulnerabilities exploited" content for any Cyber Security Act 72-hour report.

50–70%
estimated savings vs consulting pentesting
Unlimited
re-testing via Quick Verify
7,013
organisations tested (Horizon3.ai)
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Give your insurer customers third-party evidence that holds up

See how NodeZero produces CPS 234 third-party and CPS 230 material service provider evidence