APRA Prudential Standard CPS 234

Your CPS 234 Asset Registersays one thing. The internet says another.

CPS 234 assumes you know what you expose. We answer that question from outside — independently, passively, and in a form APRA and internal audit will accept.

$250MCapital APRA added for information security weakness
#1 gapAPRA’s top finding: incomplete asset identification
10 daysTo self-report a weakness you cannot fix quickly
RemunerationAPRA required executive pay consequences

Passive only — no systems, networks or accounts are accessed at any point.

What CPS 234 Actually Requires — and Where It Fails in Practice

CPS 234 is short. That is what makes it demanding. It does not prescribe technologies; it prescribes outcomes, and outcomes are harder to evidence than controls.

Four obligations do most of the work:

Information asset identification and classification

You must maintain an information asset register, classified by criticality and sensitivity. This is the clause that most commonly fails in practice — not because the register does not exist, but because it was assembled from CMDB exports, procurement records and system owner interviews. Every one of those sources records what was intended. None records what actually answers on the public internet.

Security capability commensurate with the threat

Capability must be proportionate to the size and extent of threats to your information assets. That is a moving target. Demonstrating it requires evidence of what the current threat environment looks like against your specific exposure — not a control catalogue completed eighteen months ago.

Third-party and related-party information assets

The standard explicitly extends to information assets managed by third parties. Where a supplier holds your data, their exposure is your regulatory problem. The contract is not the control.

Testing by independent specialists

Controls must be tested by appropriately skilled and independent specialists, and internal audit must review design and operating effectiveness. Self-assessed maturity and independently validated maturity are two different artefacts, and only one of them survives scrutiny.

Why the Register Is Usually Wrong

In June 2026, attackers took data from more than a hundred organisations by reaching an administrative component of a widely deployed enterprise application. It was reachable from the public internet in roughly three hundred deployments. In most cases the organisations concerned did not know.

Not through negligence — through entropy. A subdomain created for a migration and never retired. A vendor standing up a staging environment on a certificate carrying your name. An integration endpoint opened for a project that finished two years ago. Individually, footnotes. Collectively, the map an attacker works from, and a set of information assets that appear on no register.

The distinction that mattersAn internal asset inventory records what you built. An external assessment records what answers. Those are different documents, and only one of them is the one an attacker consults — or a regulator asks about after an incident.

What a BlackFlag Advisory CPS 234 Assessment Covers

  • Information asset discovery from outside — hostnames, subdomains and services attributable to your organisation, drawn from certificate transparency logs, passive DNS and public source aggregation, including assets that appear on no internal register
  • Internet-facing administrative and management interfaces — the specific asset class that produced the 2026 enterprise breaches
  • Technology and version fingerprinting, mapped against published vulnerability data with CISA KEV, EPSS and SSVC decision triage so findings arrive as decisions rather than severity counts
  • Credential exposure where corporate identities appear in published breach and infostealer corpora
  • Email authentication posture — SPF, DKIM and DMARC enforcement, and whether your domain can be spoofed today
  • Third-party and related-party surface carrying your organisation’s name — the assets CPS 234 captures and no internal inventory ever will
  • Clause-level mapping of every finding to the relevant CPS 234 paragraph, with the evidence attached

What Your Board and Internal Audit Receive

A dual-audience report. The Board section states the position in plain terms with a risk matrix and an obligation-by-obligation view. The technical section carries the underlying evidence, methodology and reproducible findings so your security function and internal auditors can verify every claim independently.

Findings are prioritised by confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. For every finding not remediated immediately, you receive a documented rationale and a date. That artefact is the difference between a security report and an assurance record, and it is what matters if the question is asked after an incident rather than before one.

Passive Only — No Systems AccessedEvery BlackFlag Advisory assessment uses exclusively passive OSINT techniques against publicly available sources. No systems, networks or accounts are accessed, probed or tested at any point. No authorisation to test is required, and nothing we do can disrupt your operations.

Who This Is For

APRA-regulated entities

Banks, insurers, superannuation funds and their subsidiaries carrying CPS 234 obligations directly.

Internal audit functions

Where CPS 234 requires review of the design and operating effectiveness of information security controls, and you need evidence produced by someone other than the team being reviewed.

Boards and risk committees

Where the question is not “are we compliant” but “can we evidence it, and who owns each gap”.

Service providers to APRA-regulated entities

CPS 234 extends to third parties. If your client is regulated, their obligations reach you — and increasingly arrive as a contractual requirement.

How the Engagement Runs

Five steps. The only one that requires your time is the first and the last.

1. Scope

We agree the domains, entities or suppliers in scope and the frameworks the findings should be mapped to. Nothing else is required from you — no access, no credentials, no questionnaire to complete.

2. Passive collection

We observe what your organisation exposes using publicly available sources: certificate transparency logs, passive DNS, published vulnerability data, and public breach and infostealer corpora. No systems, networks or accounts are accessed, probed or tested at any point.

3. Analysis and triage

Findings are validated, deduplicated and prioritised against confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. Every finding carries the evidence that produced it.

4. Regulatory mapping

Each finding is mapped to the obligation it engages, so the report speaks in the language your Board, auditor, insurer or regulator already uses.

5. Delivery and walkthrough

A dual-audience report: a Board section stating the position in plain terms, and a technical section carrying reproducible evidence. We walk you through it, and we are available for the remediation questions that follow.

Frequently Asked Questions

The questions we are asked most often by risk, audit and technology leaders in APRA-regulated entities.

What is APRA CPS 234?

CPS 234 is the APRA prudential standard on information security. It requires an APRA-regulated entity to clearly define information security roles and responsibilities, maintain an information security capability commensurate with the size and extent of threats, implement controls to protect information assets, and notify APRA of material information security incidents within 72 hours.

Does CPS 234 require an independent assessment?

CPS 234 requires an entity to have its information security controls tested by appropriately skilled and independent specialists, and requires internal audit to review the design and operating effectiveness of information security controls. An independent external exposure assessment supports both requirements without replacing either.

Does CPS 234 apply to my third parties?

Yes. CPS 234 extends to information assets managed by related parties and third parties. Where a supplier holds or processes your information assets, their exposure is your regulatory problem. Third-party surface is included in a BlackFlag Advisory assessment.

Do you need access to our systems?

No. BlackFlag Advisory assessments are passive only. We observe what your organisation exposes to the public internet using publicly available data. No systems, networks or accounts are accessed, probed or tested, so no authorisation to test is required and no operational risk is introduced.

Engagement scopes and packages are set out on the assessment packages page, or you can book a short call to discuss scope against your specific obligations.

CPS 234 Asks What You Expose.
We Answer It, Independently.

A BlackFlag Advisory assessment gives your Board and internal audit function an independent, evidenced view of your external exposure, mapped clause by clause to CPS 234 — without a single system being accessed.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber Which one do I need? →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report