Skip to content

Financial services

Infrastructure evidence for APRA, built into how the environment runs.

CPS 234 and CPS 230 put infrastructure teams at the centre of compliance: controls that must be tested, recovery that must meet tolerance levels, providers that must be managed. We engineer the controls and recovery, and produce the evidence as part of operating the environment.

Start with a cyber risk assessment
Looking up the glass facade of an office tower at blue hour.

CPS 234 Information Security

  • Information asset inventories, classified by criticality and sensitivity
  • Controls engineered across identity, endpoints, network, cloud and data, with evidence that they work
  • Systematic control testing, scheduled and recorded
  • Incident detection and escalation fast enough to support notification to APRA within 72 hours
  • Third-party security: evidence packs for your providers, including us
A checklist of six security findings, four ticked as closed and two still open, connected to three areas of work: identity, endpoint and detection.

CPS 230 Operational Risk Management

  • Critical operations mapped to the systems and infrastructure that support them
  • Recovery designed and tested against your tolerance levels
  • Business continuity and IT disaster recovery plans tested against severe but plausible scenarios
  • Support for material service provider management: contracts, monitoring and exit plans

Evidence as a by-product

When configuration is kept as code, changes are reviewed, restores are tested on a schedule and the monthly engineering report records it all, the evidence your risk team and auditors need already exists. Nobody has to assemble it the week before an audit.

Where to start

  1. A cyber risk assessment mapped to CPS 234, or an Infrastructure Review with an APRA lens.
  2. Critical operations mapped to systems, with recovery tested against tolerance levels.
  3. Gaps closed as projects, then kept closed under Managed Engineering.

Questions buyers ask

Will you be a material service provider under CPS 230?

Possibly, depending on the services we provide and whether they support critical operations. We provide what you need to manage that: contract terms, reporting and exit planning.

Can you give us evidence for our auditors?

Yes. Control tests, restore and failover results, change records and posture reports are produced as part of the work and kept in your repository.

Do you provide the CISO function APRA expects?

Our fractional CISO can provide security leadership, board reporting and ownership of the security risk register alongside your risk team.

Does this cover superannuation and insurance?

Yes. CPS 234 and CPS 230 apply across APRA-regulated entities, including banks, insurers and superannuation trustees.

Do you help with incident notification?

We gather the evidence and assessment you need to decide on notification, and support your team through it.

Start a conversation

Make APRA evidence part of running the environment.

Tell us what your risk team is asking IT for.

Talk to an Engineer