DrochaidHorizon3.ai
NodeZero/Industries/Insurance/General, life & health insurers
Insurance — General, life & health insurers

CPS 234 requires paragraph 27 control testing. Tripartite assessors want demonstration, not documentation.

As an APRA-regulated general, life, or private health insurer, you hold concentrated PII, payment data, and in many cases sensitive health and claims data. CPS 234 paragraph 27 requires testing commensurate with the rate of change of your environment. CPS 230 adds tested critical operations resilience. FAR puts personal exposure on the accountable person. The tripartite programme has already revealed systemic gaps in third-party risk, control testing, and evidence of effectiveness.

Your specific challenges

Paragraph 27 wants demonstration

APRA's tripartite programme is moving from attestation to evidence of effectiveness. Self-assessments are no longer sufficient — the assessor wants to see what actually happens when someone tries to exploit the environment.

Scattered Spider tradecraft targets help desk process

The 2025 wave was not software exploitation. It was voice-based social engineering of IT help desks. Traditional pentest scopes rarely cover help desk reset procedures — and that is where the sector was compromised.

Capital consequences are now live

APRA's $250M capital charge on Medibank demonstrated CPS 234 non-compliance can directly drive prudential capital outcomes. The enforcement posture is "constructively tough."

How NodeZero helps

Built for your situation

01

Continuous paragraph 27 evidence

NodeZero produces testing evidence at a cadence CPS 234 paragraph 27 increasingly expects — baseline assessment, ongoing testing against the rate of change of the environment, Quick Verify post-remediation.

02

Help desk and MFA reset validation

Phishing Impact Testing validates the human-factor chain Scattered Spider used — not just whether staff click, but whether help desk reset procedures can be manipulated and what MFA coverage actually holds.

03

Evidence mapped for tripartite

Findings map to CPS 234 obligation areas and feed the 10-business-day material control weakness notification clock. Structured for the assessment taxonomy the tripartite programme uses.

310,332
pentests completed (Horizon3.ai)
Unlimited
re-testing via Quick Verify
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

See your CPS 234 gaps before your tripartite assessor does

Book a baseline assessment mapped to paragraph 27 and CPS 230 critical operations