X
  • About
  • Advertise
  • Contact
  • Events
Subscribe to our Newsletter
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
  • News
    • Markets
    • Regulation
    • Super
    • M&A
    • Tech
    • Appointments
  • Podcast
  • Webcasts
  • Video
  • Analysis
  • Promoted Content
No Results
View All Results
No Results
View All Results
Home News Markets

No ‘finish line’ for cyber risk management: APRA

With online hackers developing new methods of attack, “all institutions” should consider cyber attacks a significant threat, says APRA.

by Jessica Yun
December 28, 2017
in Markets, News
Reading Time: 2 mins read
Share on FacebookShare on Twitter

APRA has reiterated the need to implement appropriate cyber protection measures across all firms in its 2017 Cyber Security Survey, which surveyed 38 regulated institutions and four non-regulated financial services providers.

“While no APRA-regulated entity has, to date, suffered a material loss due to a cyber attack, the survey results, combined with intelligence from APRA’s supervisory activities, confirm that all institutions must operate on the basis that cyber attacks remain a significant threat,” read an APRA report on the survey findings.

X

The attacks were also likely to become more frequent and sophisticated in nature, the report said.

“Institutions must recognise there is no ‘finish line’ for cyber risk management, which requires ongoing vigilance, improvement, investment and oversight,” it said.

Findings from the 2017 survey revealed that the most common form of cyber attack was ‘ransomware and other malware’, which involves malicious software threatening to publish the victim’s data or block access to it unless a ransom is paid.

According to APRA, this “underscores the need for effective anti-malware solutions and rehearsed incident response plans, as well as the importance of back-ups which cannot be compromised by the same attack”.

The second most prevalent attack was ‘distributed denial of service’ (DDoS), whereby digital services are swamped by fake requests and locking out legitimate users, highlighting the need for “effective DDoS mitigation strategies”, APRA said.

Other types of attacks were hack of an internet-facing platform, leakage of sensitive data, phishing attacks and website defacement.

According to the report, organised crime represented the “industry’s greatest cyber concern”, with the corporate regulator urging institutions to remain vigilant.

“In APRA’s view, entities must consider both external and internal threats, with internal threats able to more easily bypass perimeter and other controls,” the report said.

“Vigilance over access management (particularly privileged access) and effective oversight of controls at trusted third parties and offshore locations is essential.”

The findings also revealed that while a majority (90 per cent) of respondents had “formalised response plans” in place, they often went untested and “lacked integration with business continuity and disaster recovery plans”.

“In APRA’s view, cyber incidents must be planned for, and response plans validated as part of an overall approach to preparing for business disruptions,” APRA said.

“Cyber risk management requires ongoing vigilance, improvement, investment and oversight.

“There is no ‘end-state’ for cyber security, requiring a continuous cycle of investment in sound practices.”

Related Posts

Australian economy on track for growth: Ausbil

by Georgie Preston
December 15, 2025

Driven by US policy tailwinds announced since April, the fund manager has argued both global and US economies are on...

The furious five: Where CMC Markets sees value in 2026

by Olivia Grace-Curran
December 15, 2025

AI, energy, robotics, defence and rising interest in store of value assets like gold and Bitcoin are five ‘furious forces’...

Big Four banks ‘well positioned’ for 2026: Morningstar

by Georgie Preston
December 15, 2025

Australia’s Big Four banks are “well positioned” to navigate a difficult operating environment in 2026 supported by their strong earnings...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

VIEW ALL
Promoted Content

Why U.S. middle market private credit is a powerful income solution for Australian institutional investors

In today’s investment landscape, middle market direct lending, a key segment of private credit, has emerged as an attractive option...

by Tim Warrick
December 2, 2025
Promoted Content

Is Your SMSF Missing Out on the Crypto Boom?

Digital assets are the fastest-growing investment in SMSFs. Swyftx's expert team helps you securely and compliantly add crypto to your...

by Swyftx
December 2, 2025
Promoted Content

Global dividends reach US$519 billion, what’s behind the rise?

Global dividends surged to a record US$518.7 billion in Q3 2025, up 6.2% year-on-year, with financials leading the way. The...

by Capital Group
November 18, 2025
Promoted Content

Why smaller can be smarter in private credit

Over the past 15 years, middle market direct lending has grown into one of the most dynamic areas of alternative...

by Tim Warrick, Managing Director of Principal Alternative Credit, Principal Asset Management
November 14, 2025

Join our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

Latest Podcast

Podcast

Relative Return Insider: RBA holds, Fed cuts and Santa’s set to rally

by Staff Writer
December 11, 2025
After more than two decades, InvestorDaily continues to be an institution that connects and influences Australia’s financial services sector. This influential and integrated media brand connects with leading financial services professionals within superannuation, funds management, financial planning and intermediary distribution through a range of channels, including digital, social, research, broadcast, webcast and events.

Subscribe to our newsletter

View our privacy policy, collection notice and terms and conditions to understand how we use your personal information.

About Us

  • About
  • Advertise
  • Contact
  • Terms & Conditions
  • Privacy Collection Notice
  • Privacy Policy

Popular Topics

  • Markets
  • Appointments
  • Regulation
  • Super
  • Mergers & Acquisitions
  • Tech
  • Promoted Content
  • Analysis

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited

No Results
View All Results
NEWSLETTER
  • News
  • Markets
  • Regulation
  • Super
  • M&A
  • Tech
  • Appointments
  • Podcast
  • Webcasts
  • Promoted Content
  • Events
  • About
  • Advertise
  • Contact Us

© 2025 All Rights Reserved. All content published on this site is the property of Prime Creative Media. Unauthorised reproduction is prohibited