Managed Detection and Response
MDR for APRA-Regulated Financial Institutions
24/7 Australian-based managed detection and response for mid-market banks, insurers and superannuation trustees who need faster threat detection, guided response, and security operations that hold up under APRA scrutiny.
| Talk to Insicon Cyber | Visit insiconcyber.com |
The threat landscape mid-market financial services can't outrun
Financial services sits inside the group of Australian critical infrastructure sectors attackers hit hardest, and the cost of getting caught out is rising faster for mid-market organisations than for anyone else.
| 55% rise in the average self-reported cost of a cyber incident for medium-sized Australian businesses, to $97,200 ASD, Annual Cyber Threat Report 2024–25 (cyber.gov.au) |
13% of all cyber incidents ASD responded to involved critical infrastructure, with financial services among the sectors most affected ASD, Annual Cyber Threat Report 2024–25, via CyberPulse (cyberpulse.com.au) |
$80,850 average self-reported cost per cybercrime report across Australian businesses, up 50% year on year ASD, Annual Cyber Threat Report 2024–25 (cyber.gov.au) |
Australia and New Zealand's financial regulators are responding with sharper expectations, not softer ones. Detection speed is no longer just a security metric. It's a regulatory clock.
What APRA (and the RBNZ) actually expect
Prudential Standard CPS 234 does not tell entities which tools to buy. It tells the board what it is accountable for, and it starts a clock the moment an incident is discovered.
CPS 234 — Information Security
An APRA-regulated entity must notify APRA as soon as possible, and no later than 72 hours, after becoming aware of an information security incident that materially affected, or had the potential to materially affect, the entity or its customers. A separate 10-business-day clock applies to a material control weakness the entity cannot remediate in a timely manner. Paragraph 13 places ultimate responsibility for information security with the Board itself, not a delegate.
Source: APRA Prudential Standard CPS 234, via Cybereen (cybereen.com) and the APRA Prudential Handbook (handbook.apra.gov.au)
CPS 230 — Operational Risk Management
CPS 230 layers on a critical operations framework and a 24-hour notification requirement for disruptions to critical operations that fall outside tolerance, separate from CPS 234's 72-hour information security clock. It also requires an annual register of material service providers, first due 1 October 2025.
Source: APRA CPS 230 summary, via Cliffside (cliffside.com.au)
New Zealand: the Reserve Bank's parallel expectation
Registered banks, non-bank deposit takers and insurers regulated by the Reserve Bank of New Zealand face an equivalent obligation under its Guidance on Cyber Resilience: material cyber incidents must be reported as soon as practicable, and in any case within 72 hours. New Zealand-regulated financial institutions carry the same detection-speed pressure as their APRA-regulated counterparts across the Tasman.
Source: Reserve Bank of New Zealand, Cyber resilience for regulated entities (rbnz.govt.nz)
APRA currently supervises institutions holding around $9.8 trillion in assets for Australian depositors, policyholders and superannuation fund members. That scale is exactly why APRA has said it will take stronger supervisory action, and pursue enforcement where appropriate, where entities fail to manage risk proportionate to their size and complexity.
Source: APRA, Who we are (apra.gov.au)
Why detection speed is the real gap
FIIG Securities: six days between the warning and the investigation
In 2023, the ALPHV ransomware group breached FIIG Securities' network between 19 May and 8 June and stole approximately 385 gigabytes of client data, including driver's licences, passport scans, bank account details and tax file numbers. FIIG did not know its network had been compromised until the Australian Signals Directorate's Cyber Security Centre warned the firm on 2 June. FIIG's own investigation did not begin until 8 June, six days later. Around 18,000 clients were notified that their personal information may have been exposed.
In February 2026, the Federal Court ordered FIIG to pay $2.5 million in penalties plus $500,000 towards ASIC's legal costs, and mandated an independent expert review of the firm's cyber security arrangements. ASIC found FIIG's failures included not allocating the financial resources, staff or expertise a firm managing more than $2.88 billion in funds needed to detect and respond to a breach in time.
A regulator had to tell FIIG it had a problem. That's the gap between owning security tools and having someone watching them around the clock.
Sources: ASIC, media release 26-021MR (asic.gov.au); Cyber Daily (cyberdaily.au); BankInfoSecurity (bankinfosecurity.com)
|
Managed Detection and Response Get an MDR posture check against CPS 234 and CPS 230 A short conversation with Insicon Cyber on where your current detection and response coverage sits against APRA's notification clocks.
|
What Insicon Cyber's MDR delivers
Our Adaptive SOC (aSOC) is a 24/7, Australian-based managed service. Insicon Cyber analysts run detection and response across the platforms best suited to your environment and complexity, backed by service levels that map directly onto APRA's expectations for board accountability and third-party assurance.
| Severity (from alert raised) | Response target |
|---|---|
| Critical — compromise of key business services | Within 1 hour |
| High — compromise of business services | Within 2 hours |
| Medium — loss of business service | Within 4 hours |
| Low — suspicious behaviour | Within 8 hours |
Service availability is targeted at a minimum of 99.9% uptime across all managed security services, with 24/7 support and proactive maintenance.
A RASCI matrix before day oneEvery engagement starts with a RASCI matrix defining exactly which containment actions the aSOC can take unilaterally and which need your sign-off — the contractual clarity APRA's supplier risk expectations under CPS 234 and CPS 230 are looking for. |
Escalation to the founders, not a queueMissed response targets escalate directly to Matt Miller and Greg Bunt, with service credits available. There's no tier-two ticket queue between your incident and the people accountable for it. |
Australian data sovereigntyInsicon Cyber is headquartered in North Sydney and ISO 27001 certified at the organisational level, with data handled onshore for entities that need to demonstrate exactly that to their board and their regulator. |
Platforms matched to your environmentThe aSOC draws on multiple detection platforms, selected to suit your environment and complexity, all backed by Insicon Cyber analysts. You're buying a managed outcome, not a licence to a single vendor's console. |
Backed by fractional CISOs who've sat in your seat
Insicon Cyber is an award-winning Australia and New Zealand cybersecurity partner, co-founded in 2013 and headquartered in North Sydney. The people who built the firm are still in the room.
Matt Miller, Co-Founder, CEO and Fractional CISO, has 25+ years across NASDAQ and ASX listed organisations, is an ISO 27001 Senior Lead Auditor, and was Head of Technology for the asset finance division of a leading Australian regional bank — financial services governance from the inside, not just the outside.
Greg Bunt, Co-Founder, Director and Fractional CISO, has 25+ years in security, risk and enterprise architecture across Australia and Asia-Pacific, holds an Australian Government Baseline Security Clearance, and has delivered large-scale programmes in banking, finance and telecommunications.
Ready to close the detection gap?Talk to Insicon Cyber about MDR built around the compliance obligations your board actually carries, across Australia and New Zealand. Contact Insicon Cyber |
Sources
- APRA Prudential Standard CPS 234, APRA Prudential Handbook — handbook.apra.gov.au/standard/cps-234
- APRA CPS 234: The 36 Obligations and the 72-Hour Rule, Cliffside — cliffside.com.au/insights/apra-cps-234-compliance-guide
- APRA CPS 234: 2026 compliance guide, Cybereen — cybereen.com/standards/apra-cps-234
- Reserve Bank of New Zealand, Cyber resilience for regulated entities — rbnz.govt.nz/regulation-and-supervision/cross-sector-oversight/improving-cyber-resilience-for-regular-entities
- APRA, Who we are — apra.gov.au/who-we-are
- ASD, Annual Cyber Threat Report 2024–25 — cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
- ASD Cyber Threat Report 2025 Insights, CyberPulse — cyberpulse.com.au/2025/10/21/asd-cyber-threat-report-2025-australia
- ASIC, media release 26-021MR: FIIG Securities ordered to pay $2.5 million — asic.gov.au/.../26-021mr-asic-action-sees-fiig-securities-ordered-to-pay-25-million-over-cyber-security-failures
- FIIG Securities faces $2.5m fine following 2023 cyber attack, Cyber Daily — cyberdaily.au/security/13197-fiig-securities-faces-2-5m-fine-following-2023-cyber-attack
- Australia Sues FIIG Investment Firm in Cyber 'Wake-Up Call', BankInfoSecurity — bankinfosecurity.com/australia-sues-fiig-investment-firm-in-cyber-wake-up-call-a-27749