What APRA's $8 Million Bendigo Bank Case Tells Boards in Australia and New Zealand
On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the...
5 min read
Insicon Cyber
:
Updated on September 1, 2026
Now more than ever, cybersecurity governance is crucial for protecting sensitive data and mitigating cyber threats. This blog from Insicon Cyber explores the best practices that organisations can implement to enhance their cybersecurity governance.
Updated 2026: Since first publishing this as a five-item guide, we have added a sixth best practice to reflect the governance discipline required in 2026's increasingly complex and fast-moving information security landscape.
Cybersecurity governance refers to the set of processes, policies, and structures that an organisation puts in place to manage and mitigate cyber risks. In broad terms it involves:
One of the key aspects of understanding cybersecurity governance is recognising the importance of aligning cybersecurity goals with overall business objectives. This requires collaboration between IT and business leaders to ensure that cybersecurity measures are integrated into the organisation's overall risk management framework.
Australian organisations now face evolving compliance requirements including the March 2025 ISM updates, Privacy Act reforms, SOCI Act obligations, and emerging AI governance mandates. Governance frameworks must be both strategically sound and operationally sustainable to meet these complex demands.
To establish a robust governance framework, organisations should start by defining clear roles and responsibilities for cybersecurity. This includes designating a cybersecurity leader or team who will be responsible for overseeing the organisation's cybersecurity programme.
The governance framework should also include:
Effective governance frameworks in Australian organisations increasingly connect strategic oversight to operational reality. While boards set policy and risk appetite, the framework must enable practical implementation through clear operational mandates, resource allocation, and accountability mechanisms that translate from the boardroom to day-to-day security operations.
Organisations should also establish clear policies and procedures for incident response and recovery. This includes defining roles and responsibilities for responding to cyber incidents, establishing communication channels for reporting incidents, and developing a plan for recovering from cyber attacks.
Implementing strong access controls is essential for protecting sensitive data and preventing unauthorised access to systems and networks. This includes:
Organisations should also implement network segmentation to isolate sensitive data and systems from the rest of the network. This helps to limit the potential impact of a cyber attack by containing the breach to a specific segment of the network.
Regular monitoring and auditing of access controls is also critical. This includes reviewing access logs, monitoring for unusual activity, and conducting periodic access reviews to ensure that access privileges are still appropriate.
Keeping systems and software up to date with the latest security patches is one of the most effective ways to protect against cyber threats. Vulnerabilities in outdated software are a common entry point for cyber attackers.
Organisations should establish a formal patch management process that includes:
In addition to patching known vulnerabilities, organisations should implement a proactive approach to security updates. This includes subscribing to security advisories from software vendors, monitoring threat intelligence feeds, and staying informed about emerging threats relevant to your technology stack.
Where do you actually stand?
APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.
Human error remains one of the leading causes of cybersecurity incidents. Regular security awareness training helps employees recognise and respond appropriately to cyber threats such as phishing attacks, social engineering attempts, and malware.
Effective security awareness programmes should include:
Training should be engaging and relevant to employees' daily activities. Rather than generic security lectures, effective programmes use real-world scenarios, interactive modules, and practical examples that demonstrate how security decisions impact the organisation.
Organisations should also establish clear reporting channels for security incidents and create a culture where employees feel comfortable reporting potential threats without fear of reprisal. The most effective security programmes recognise that employees are a critical line of defence when properly educated and empowered.
Compliance with relevant cybersecurity regulations and standards is not just a legal requirement but also a best practice for protecting sensitive data and maintaining stakeholder trust.
New Zealand organisations face complementary regulatory considerations including the Privacy Act 2020, Critical Infrastructure requirements, and alignment with the NZISM (New Zealand Information Security Manual) framework. Trans-Tasman organisations benefit from integrated governance approaches that address both Australian and New Zealand regulatory obligations while leveraging shared security operations and threat intelligence.
Organisations should conduct regular compliance assessments to identify gaps and ensure that their cybersecurity practices meet all applicable requirements. This includes reviewing policies and procedures, conducting internal audits, and engaging external auditors where required.
Effective compliance management in today's regulatory environment requires more than annual audits. Organisations across Australia and New Zealand are discovering that governance frameworks deliver maximum value when connected to operational capabilities that enable continuous compliance monitoring, automated evidence collection, and proactive gap remediation.
Continuous monitoring and improvement are critical for maintaining an effective cybersecurity governance programme. This involves regularly monitoring the organisation's cyber risk landscape, assessing the effectiveness of existing controls, and making necessary improvements to enhance the organisation's cyber resilience.
Organisations should establish a robust monitoring system that enables them to detect and respond to cyber threats in real-time. This includes:
Effective continuous monitoring requires more than technology and policy. Organisations across Australia and New Zealand are increasingly recognising that governance frameworks deliver maximum value when connected to operational capabilities like adaptive Security Operations Centres (aSOC) that provide real-time threat detection and response.
Key performance indicators (KPIs) and metrics should be established to measure the effectiveness of the cybersecurity programme. These metrics should be regularly reported to board and executive leadership, enabling informed decision-making and demonstrating the value of cybersecurity investments.
Understanding best practices for cybersecurity governance is essential. Implementing them effectively requires knowing where you currently stand against the obligation that actually binds you.
Insicon Cyber helps organisations across Australia and New Zealand establish robust governance frameworks and deliver them through integrated operational capabilities. From board education and policy development to continuous monitoring and compliance management, we provide comprehensive cybersecurity partnership that works across every level of your organisation.
The most practical starting point is an independent readiness assessment, measured against the Essential Eight, ISO 27001, ISO 42001, APRA CPS 234, NZISM, or whichever standard your customers, regulators, or insurers are asking you to meet. You receive a documented position, a prioritised roadmap, and a board ready briefing in two to four weeks.
Not ready to request an assessment yet? Download our Complete Guide to Cybersecurity Governance in 2026 and work through the frameworks at your own pace.
Related Resources:
On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the...
Black Hat always has a session everyone talks about, and this year it was OpenAI telling the room we're all gonna need a bigger boat. Their own...
The Australian Signals Directorate has moved the frontier AI conversation into the boardroom, and it has brought the Australian Institute of Company...
5 min read
AI SECURITY AND GOVERNANCE You don't need to be an AI engineer to run a good vendor review. But when a vendor pitch is built entirely on numbers...
1 min read
On 26 September 2022, a bank executive signed a document that removed a system from their individual list of responsibilities. The system was the...
1 min read
The Australian Prudential Regulation Authority (APRA) has introduced a new prudential standard, CPS 230, focusing on operational risk management....