X
  • About
  • Advertise
  • Contact
  • Events
Subscribe to our Newsletter
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
No Results
View All Results
Home News Regulation

Operational risk landscape still a ‘moving target’

According to an APRA executive, businesses need to change the way they think about risk mitigation.

by Jessica Penny
August 23, 2023
in News, Regulation
Reading Time: 3 mins read
Share on FacebookShare on Twitter

The Australian Prudential Regulation Authority (APRA) has issued caution regarding the rapid evolution of the operational risk landscape, emphasising the need for businesses to adopt a more defensive approach.

APRA executive board member Therese McCarthy Hockey noted that while the concept of operational risk isn’t a new one, the nature of the risks themselves have evolved as the financial sector and customers become more reliant on digital technology.

X

“The most widespread threats to business continuity today are less to do with breaking into safes and more to do with breaking into servers; less about office fires than breached firewalls,” Ms McCarthy Hockey said.

“In an environment where one crashed server or ransomware attack can leave potentially millions of Australians without access to funds, the ability to mitigate operational risks is essential for financial stability and community well-being.”

Last month the regulator confirmed it had finalised Prudential Standard CPS 230 Operational Risk Management (CPS 230), which sets out new rules to ensure APRA-regulated entities are able to better manage operational risks and respond to business disruptions.

In response to consultation feedback last year, the final CPS 230 incorporates a number of changes, including deferring the commencement of the new standard from January 2024 to July 2025.

Ms McCarthy Hockey noted that while APRA only began consulting on CPS 230 in July 2022, the operational risk environment has already shifted substantially since then.

“These developments have a few things in common. The obvious one is the connection to technological innovation. The second is that these innovations rely on the successful integration of multiple technologies provided by a range of financial system players: the banks, insurers and super funds themselves, the cloud, payments providers, telcos, and big tech companies.

“A failure at any point in the chain has the potential to break down services to the entire system – with system latency and backups being ever more important.”

However, APRA pointed to many banks, insurers, and superannuation trustees still struggling to meet their minimum requirements as per CPS 234 introduced in 2019, which aims to ensure that an APRA-regulated entity takes measures to be resilient against information security incidents.

“Given that cyber risk is at or near the top of every corporate risk register today and has been for several years, the obvious question is, ‘Why?’”

Ms McCarthy Hockey partially attributed this to the evolving nature of cyber threats that are compelling businesses to be “constantly firing at moving targets” but asserted that the root cause is organisations historically treating information security as a technology risk rather than an overall business risk.

“Rather than leaving cyber resilience to the IT and cyber security departments, boards need to become much more tech savvy and alert to how the threats have changed, in particular for the data they collect and manage. Boards need to provide stronger oversight of these ‘crown jewels’ in order to address threats as they emerge with the expediency they deserve.

“Understanding these reasons is not the same as accepting them, and APRA is rapidly running out of patience with the slow pace of uplift.”

As such, the regulator has moved forward with CPS 230 alongside the expectation that boards focus on three key actions: putting the right governance arrangements in place, identifying critical operations and material service providers, and beginning to develop a new organisational mindset.

Related Posts

Nvidia surge stokes AI-bubble fears

by Adrian Suljanovic
November 21, 2025

A renewed surge in Nvidia’s earnings outlook has intensified debate over whether the artificial intelligence boom is veering into bubble...

APRA report highlights super’s outsized role in times of crisis

by Georgie Preston
November 21, 2025

In its newly released Systemic Risk Outlook report, the Australian Prudential Regulation Authority (APRA) has flagged rising financial system interconnectedness...

Tariff slowdowns clash with AI optimism heading into 2026

by Georgie Preston
November 21, 2025

Despite widespread scepticism over President Trump’s follow-through on tariffs - highlighted once again this week by his dramatic reversal on...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Global dividends hit a Q3 record, led by financials.

Global dividends surged to a record US$518.7 billion in Q3 2025, up 6.2% year-on-year, with financials leading the way. The...

by Capital Group
November 18, 2025
Promoted Content

Why smaller can be smarter in private credit

Over the past 15 years, middle market direct lending has grown into one of the most dynamic areas of alternative...

by Tim Warrick, Managing Director of Principal Alternative Credit, Principal Asset Management
November 14, 2025
Promoted Content

Members Want Super Funds to Step Up Security

For most Australians, superannuation is their largest financial asset outside the family home. So, when it comes to digital security,...

by MUFG Pension & Market Services
October 3, 2025
Promoted Content

Boring Can Be Brilliant: Why Steady Investing Builds Lasting Wealth

In financial markets, drama makes headlines. Share prices surge, tumble, and rebound — creating the stories that capture attention. But...

by Zagga
October 2, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Latest Podcast

Podcast

Relative Return Insider: Economic shifts, political crossroads, and the digital future

by InvestorDaily team
November 13, 2025
After more than two decades, InvestorDaily continues to be an institution that connects and influences Australia’s financial services sector. This influential and integrated media brand connects with leading financial services professionals within superannuation, funds management, financial planning and intermediary distribution through a range of channels, including digital, social, research, broadcast, webcast and events.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Markets
  • Appointments
  • Regulation
  • Super
  • Mergers & Acquisitions
  • Tech
  • Promoted Content
  • Analysis

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Markets
  • Regulation
  • Super
  • M&A
  • Tech
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited