icon-piggy-bank Financial Services

When a breach hits a super fund or a bank, the damage isn't just financial — it's the end of trust

Australia’s financial services sector holds more personally sensitive data per institution than almost any other industry: retirement savings, credit records, insurance histories, tax file numbers. That makes it a persistent, high-value target for both organised cybercriminals and state-sponsored actors. In April 2025, coordinated credential stuffing attacks struck multiple major superannuation funds simultaneously — AustralianSuper, Rest, Insignia Financial and Australian Retirement Trust among them — compromising thousands of member accounts and triggering urgent regulatory contact from APRA and the ACSC. The attacks were neither novel nor unpredictable; they succeeded because known exposures had not been closed.

Orro works with Australian banks, insurers, superannuation trustees and fintechs to build the security posture, operational resilience and network infrastructure that APRA, ASIC and regulators increasingly expect — and that customers and members now demand.

1 July, 2025

Date APRA CPS 230 took effect — mandating critical operations identification, disruption tolerance thresholds, scenario testing and material service provider registers across all banks, insurers and superannuation trustees

1700 +

ASD cyber threat notifications to Australian entities in FY2024–25 — an 83% increase year-on-year, with critical infrastructure entities notified over 190 times (up 111%)

Sector Intelligence Brief

The financial services cyber threat landscape in Australia

Australia’s financial services sector sits at the intersection of high data value, critical operational dependency and an increasingly aggressive threat environment. The sector encompasses institutions that Australians trust with their most sensitive financial lives: retirement savings, credit records, mortgage details, insurance histories and tax file numbers. That concentration of value makes it a persistent, high-priority target for financially motivated cybercriminals, state-sponsored actors pursuing economic intelligence, and increasingly sophisticated organised criminal networks operating across borders.

Why the financial services sector is targeted:

Financial services organisations hold a uniquely attractive combination of assets. Customer financial data can be monetised directly through account takeover and fraud. Personally identifiable information — names, dates of birth, tax file numbers, bank account details — commands premium prices on criminal marketplaces and enables follow-on identity fraud at scale. Payment systems and settlement infrastructure offer direct access to funds. And for state-sponsored actors, intelligence on capital flows, investment positions and institutional financial health carries strategic value entirely separate from financial gain.

The sector’s complexity compounds these risks. A mid-tier bank or super fund may depend on dozens of third-party technology and service providers — core banking platforms, payment processors, identity verification services, cloud hosting providers, managed security vendors — each of which represents a potential entry point. APRA’s introduction of CPS 230 in 2025, with its explicit requirements around third-party and material service provider risk, reflects regulators’ growing recognition that the supply chain is now as important as the perimeter.

The April 2025 super fund attacks — and what they revealed:

In late March and early April 2025, a coordinated series of credential stuffing attacks struck multiple major Australian superannuation funds in rapid succession. AustralianSuper, Rest, Insignia Financial, Hostplus and Australian Retirement Trust all reported suspicious activity, with approximately 600 AustralianSuper member accounts compromised and AU$500,000 stolen from four accounts. Rest’s CEO shut down the member portal immediately and launched incident response protocols. APRA and ACSC intervened directly, contacting fund boards about authentication control expectations.

The attacks were notable not for their technical sophistication, but for their effectiveness against known, addressable weaknesses. Attackers used stolen credentials from unrelated prior breaches, purchased from criminal marketplaces, to test access against super fund portals using automated bots — a technique that would have been blocked by mandatory multi-factor authentication. The incidents reinforced a pattern visible across the OAIC’s breach data: the finance sector continues to report high volumes of breaches attributable to compromised credentials and phishing, not novel zero-day exploits. Most preventable breaches succeed because exposure has not been closed.

The structural technology challenge:

Financial services IT infrastructure is characterised by complexity, legacy burden and a continuous modernisation tension. Major banks and insurers maintain core systems built across decades, with integration layers, middleware and cloud migrations layered on top. Superannuation funds have undergone rapid digital uplift to meet member expectations for self-service account management — often outpacing the security architecture designed to protect those new digital channels. Regional banks, customer-owned banks and insurers frequently operate with lean technology teams responsible simultaneously for daily operations, compliance uplift, cloud migration and incident response.

Branch network infrastructure introduces additional exposure. Payment terminals, ATMs, access control systems and customer-facing digital kiosks are increasingly networked into corporate infrastructure — creating convergence points that blur traditional security perimeters. A compromise of branch network infrastructure is no longer just an operational disruption; it is a potential entry point into broader payment and data systems.

The pace of digital banking adoption has accelerated these pressures. Customers now expect real-time payments, 24/7 mobile banking and seamless omnichannel service. Outages are newsworthy. A payments failure or prolonged application downtime carries immediate reputational and regulatory consequences — which creates pressure on operations teams to prioritise availability, sometimes at the cost of the security architecture upgrades that would reduce exposure.

Third-party and supply-chain risk:

APRA’s CPS 230 framework reflects the reality that financial institutions’ operational resilience is only as strong as their material service providers’. Core banking platform vendors, cloud hyperscalers, managed security providers, payment processors and software-as-a-service platforms each represent a risk concentration point. An institution may have excellent internal controls and still suffer a significant incident via a compromised vendor. The requirement under CPS 230 to maintain and submit a material service provider register to APRA, assess downstream provider risks, and demonstrate that critical operations can continue through vendor disruption has elevated third-party risk from a compliance checkbox to a sustained operational discipline.

Regulatory and compliance obligations for Australian financial services

Governing body

Australian Prudential Regulation Authority — apra.gov.au/information-security

What it requires

Maintenance of an information security capability commensurate with the entity’s size, nature and risk profile; implementation of controls to protect information assets across the enterprise and third-party supply chain; regular testing of those controls; and notification to APRA of material information security incidents within 72 hours of becoming aware.

Applies to

All APRA-regulated entities — banks, insurers, superannuation trustees and other authorised deposit-taking institutions — regardless of size.

Consequence of non-compliance

Supervisory escalation, enforceable undertakings, formal directions and potential licence conditions. APRA has flagged it will increasingly test control effectiveness, not just documentation.

How Orro supports financial services organisations

Orro has designed, deployed and managed retail technology infrastructure across some of Australia’s most complex and demanding environments. Our capability spans network, security, cloud and managed services — and we deliver it at the scale that national retail requires.

Financial services network architecture is more complex than most industries acknowledge. A regional bank or customer-owned financial institution may operate dozens or hundreds of branch locations, each requiring reliable, segmented connectivity for payment terminals, staff workstations, ATMs, digital signage and customer Wi-Fi — all of which must be isolated from one another and from core infrastructure while still being centrally managed. A superannuation fund may rely on a smaller physical footprint but depends absolutely on application performance for member portals, adviser platforms and back-office processing that runs continuously.

Orro designs and manages SD-WAN and SASE architectures for financial services environments that deliver the segmentation, redundancy and visibility that payment systems and regulated data environments require. SASE frameworks allow security policy to follow the user and the transaction across branch, cloud and mobile contexts — removing the complexity of maintaining multiple perimeter controls across a distributed estate. For institutions operating across states, or managing significant workforce mobility, SASE provides a consistent security baseline regardless of where access originates.

Where private, carrier-independent connectivity is required — for backup links, out-of-band management, or remote site access — Orro holds private spectrum, one of only a handful of organisations in Australia to do so. Combined with Orro’s One Touch Control platform, which provides unified multi-vendor, multi-carrier network visibility and management, financial services technology teams gain the operational clarity needed to manage complex environments with lean resources.

Outcome: A resilient, segmented financial network that supports always-on payment operations, protects cardholder data environments, and provides the unified visibility that CPS 230 operational continuity requirements demand.

Proof of impact

24×7 security operations for Australia’s leading alternative lender

Australia’s number one alternative lender — a non-bank financial services organisation with offices across Australia, New Zealand, Asia and Europe — engaged Orro to establish a 24×7 Security Operations and Management capability to address growing cyber threats, complex compliance obligations and a shortage of specialist internal security resources. Orro delivered collaborative SOC-based security operations and incident response for the Australian operation; based on the outcomes achieved, the client’s global parent subsequently adopted a scaled version of the same service. Orro’s programme enabled faster and more consistent incident detection and response, demonstrated control effectiveness and risk management outcomes to regulators and the board, and supported proactive threat hunting capability that reduced reliance on internal cybersecurity headcount.

Securing a top general insurer across 27 countries

An Australian-headquartered general insurer ranked among the world’s top general insurers — with more than 11,000 staff and operations across 27 countries — engaged Orro to deliver security architecture and consultancy, 24×7 SOC-based security operations management for the Australian region, security assurance and governance services, and a Global Security Service Desk covering BAU security requests across all international regions. Orro’s embedded team documented standard operating procedures, supported APRA regulatory and risk management obligations, delivered visibility of security control state across the organisation’s application estate, and enabled the internal team to redirect focus toward higher-value security project work.

Delivering resilience at scale — Australia Post

Orro designed, deployed and manages Australia’s largest retail network: over 4,000 Australia Post locations. The outcome: a 70% reduction in network outages, 4x faster connections, 43% fewer critical incidents and 44,000 business impact hours avoided. The relevance to financial services extends beyond scale — Australia Post’s Licensed Post Office network provides everyday banking services to millions of Australians, including cash deposits, withdrawals and bill payments on behalf of major banks and financial institutions. The same Orro-managed network that keeps a parcel lodgement counter operational is simultaneously supporting financial transactions in communities across the country, many of them in areas where physical bank branches no longer exist. Managing that network at 4,000 sites, with the uptime and security discipline it demands, is exactly the operational model Orro brings to multi-branch financial services environments.

Frequently asked questions

CPS 230, which took effect on 1 July 2025, requires APRA-regulated entities to identify their critical operations — the functions whose disruption would materially harm customers or financial markets — and set tolerance thresholds for how long and to what degree those operations can be disrupted. Institutions must develop and regularly test business continuity arrangements against those thresholds, maintain and submit to APRA a register of material service providers and their associated risks, and demonstrate that critical operations can continue through a severe disruption to any of those providers. Directors and executives are explicitly responsible for ensuring operational resilience is embedded in governance and decision-making. Non-significant financial institutions have an additional 12 months to comply with certain business continuity and scenario analysis requirements; service provider contract uplift obligations apply from 1 July 2026 or earlier renewal.

Why financial services organisations choose Orro

Our difference

Why financial services organisations choose Orro

chevron-right-pink
Deep regulatory alignment

Orro’s financial services practice is built around APRA CPS 234 and CPS 230, ASIC cyber expectations and Essential Eight maturity — providing capability that maps directly to current regulatory obligations rather than generic security frameworks.

chevron-right-pink
CTEM for continuous assurance

Orro’s Continuous Threat Exposure Management service replaces point-in-time security assessments with an ongoing operational programme — providing the continuous control visibility that CPS 234 and board-level oversight require.

chevron-right-pink
National Cyber Defence Centre

24/7 security monitoring and incident response from Orro’s Australian-operated SOC, with Australian-based escalation aligned to the data sovereignty and regulatory expectations of APRA-regulated entities.

chevron-right-pink
CPS 230-ready managed services

As a potential material service provider under CPS 230, Orro provides the resilience architecture, continuity documentation and service level visibility that APRA-regulated entities need from their technology partners.

chevron-right-pink
ISO/IEC 27001 :2022 certified and IRAP assessed

Orro holds ISO/IEC 27001:2022 certification — with scope covering all processes and procedures — and has been successfully assessed under the IRAP (Infosec Registered Assessors Program) framework. For APRA-regulated entities conducting vendor due diligence, Orro’s independently verified security posture and SecurityScorecard A-rating provide auditable assurance. Full details at orro.group/about/trust-security/.

chevron-right-pink
Proven scale at network complexity

Orro designs and manages enterprise-scale distributed networks — including Australia Post’s 4,000+ site network — with the segmentation, redundancy and proactive management discipline that payment and regulated data environments require.

chevron-right-pink
SD-WAN, SASE and private spectrum

Orro delivers modern network architectures for multi-branch financial services environments, including private LTE capability for carrier-independent connectivity — one of only a handful of organisations in Australia to hold private spectrum.

chevron-right-pink
One Touch Control

Orro’s proprietary platform provides unified, multi-vendor, multi-carrier network visibility and management — supporting the operational transparency that CPS 230 critical operations oversight requires.

chevron-right-pink
Australian-owned with Australian-based support escalation

Orro is an Australian-owned partner with Australian-based account management and support escalation, and 24/7 global operations capability — directly supporting data sovereignty and regulatory expectations.

chevron-right-pink
Vendor-agnostic architecture

Orro designs solutions based on what best fits the institution’s environment and regulatory obligations, not vendor commercial relationships — providing independent advice across network, security and cloud domains.

Ready to talk?

Australia’s financial services regulators have set clear expectations for what cyber resilience, operational continuity and third-party risk management look like. We help you meet those expectations — not on paper, but in practice.

Our accreditations