← SecureAZ Blog

Compliance · 6 min read · Published 24 April 2026 · Reviewed 17 August 2026

APRA CPS 234 Security Awareness Training: What AU Financial Services Must Do

APRA CPS 234 is mandatory for Australian banks, insurers, and super funds. Staff awareness training is a core people-control requirement. Here's what compliance looks like.

Australian Prudential Regulation Authority's CPS 234 — Information Security — is one of the most prescriptive cybersecurity frameworks in the Australian financial sector. It applies to every APRA-regulated entity: banks, credit unions, insurance companies, and superannuation funds. No exceptions.

While CPS 234 covers a broad range of technical and governance controls, staff awareness training is consistently cited by APRA as a core people-layer control — and one of the most common gaps found during regulatory reviews.

What CPS 234 Requires on People Controls

CPS 234 requires regulated entities to maintain information security capability commensurate with the size and extent of threats they face. Section 15 of the standard specifically requires that the board and senior management define information security roles and responsibilities clearly — and that all individuals with such responsibilities are adequately trained and capable.

In practice, this means:

  • All staff with access to regulated systems must receive security awareness training
  • Roles with elevated access (finance, executive, IT) require more targeted training
  • Awareness must be ongoing — not a single onboarding event
  • Capability must be documented — APRA reviewers will ask for evidence

The Australian Cyber Security Centre's Essential Eight framework, which overlaps significantly with CPS 234 requirements, similarly mandates awareness training as part of the maturity model.

Why Financial Services Staff Are a Primary Target

Banks, insurers, and super funds are the most targeted organisations in Australia for a simple reason: that's where the money is. The ACSC's Annual Cyber Threat Report consistently identifies financial services as the sector most targeted by business email compromise, credential phishing, and ransomware.

The attack vector is almost always the same: a convincing phishing email lands in a staff member's inbox. Without training, the click rate is typically 20–30%. With regular, well-designed training and simulations, it drops to under 5%.

CPS 234 doesn't mandate phishing simulations explicitly — but APRA reviewers view them as strong evidence of a functioning awareness programme.

The APRA Review Process

APRA conducts information security reviews of regulated entities, and finding gaps in people controls is one of the most common outcomes. Typical findings include:

  • Training completion rates below 90%
  • No evidence of role-specific training for privileged access holders
  • Training content not updated to reflect current threats (e.g., still using outdated phishing examples)
  • No testing mechanism to verify training effectiveness

Each finding requires a remediation plan and follow-up review. More seriously, material deficiencies in CPS 234 compliance can trigger formal supervisory action.

What a CPS 234-Ready Training Programme Looks Like

Coverage — all staff, contractors, and third parties with system access. CPS 234 explicitly extends obligations to service providers who might impact information security.

Content — phishing identification, business email compromise (a major AU financial sector threat), social engineering, data classification, incident reporting, and remote work security.

Frequency — at minimum annually, but quarterly for roles with elevated risk exposure.

Testing — phishing simulations with remedial training for staff who click.

Documentation — exportable completion records, assessment scores, and simulation results for regulatory evidence.

Connecting CPS 234 to Cyber Insurance

Australian financial services entities carry significant cyber insurance coverage. Insurers are increasingly aligning their underwriting questions directly with APRA's expectations — and training programme evidence is a standard component of policy renewal.

Cyber insurance approved training documentation produced by your training platform serves double duty: it satisfies your APRA obligations and your insurer's requirements simultaneously.

Getting Started

For APRA-regulated entities that don't yet have a formal awareness training programme, the gap is straightforward to close:

  1. Select a platform that covers AU-specific threats (ATO scams, myGov phishing, Aussie bank fraud)
  2. Enrol all staff — prioritise roles with payment or system access
  3. Set a completion deadline (30 days is standard for existing staff)
  4. Schedule quarterly refreshers and simulations
  5. Export your first compliance report

SecureAZ is built for exactly this use case — Australian-specific threat content, APRA CPS 234 aligned documentation, and phishing simulations using real AU lures. 45-day free trial.

External references: