DrochaidHorizon3.ai
NodeZero/Industries/Insurance/Superannuation trustees
Insurance — Superannuation trustees

Member data and payment authorities in one place. APRA's watching.

As an RSE licensee, you hold concentrated member data, payment authorities, and beneficiary information — and you've been in APRA's focus since the 2025 credential-stuffing and account-takeover wave. CPS 234 applies equally to you as to the major banks. CPS 230 adds tested critical operations resilience. FAR extended to superannuation in March 2025, placing personal exposure on the accountable person for information security.

Your specific challenges

Credential stuffing is the proven vector

The 2025 wave of super fund attacks was credential-stuffing and account takeover. Members reuse passwords across services. The attack path is well understood and actively being used against the sector.

Same rules, smaller security teams

CPS 234 applies equally to a $300B fund and a $30B fund. But the security team, pentesting budget, and tripartite response resources are not proportional.

APRA's focus has sharpened

Following the 2025 credential-stuffing wave, APRA has sharpened focus on CPS 234 compliance demonstration rather than attestation. Tripartite assessors expect structured evidence that controls work against today's tradecraft.

How NodeZero helps

Built for your situation

01

Credential exposure testing

AD Password Audit identifies weak, breached, and reused credentials. Phishing Impact Testing validates MFA enforcement — the specific controls that would have blocked the 2025 super fund account-takeover wave.

02

Member portal and API validation

External pentesting and cloud pentesting of member-facing portals, advice engines, and integrations. Validates that the attack surface members use is not the attack surface attackers use.

03

FAR-defensible evidence

Continuous validation is the strongest available demonstration of reasonable steps for the accountable person under FAR. Evidence documented at a cadence that supports the regulator's trajectory.

7,013
organisations tested (Horizon3.ai)
310,332
pentests completed
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Test the credential path before the next stuffing attempt

Book a baseline against the CPS 234 obligation areas APRA is sharpening focus on