APRA CPS 234 is the information-security prudential standard for ADIs, insurers and superannuation trustees. Boards have read it. Vendors have productised it. A surprising number of 'CPS 234 pentests' we are asked to replace are vulnerability scans with the standard cited in the footer.
If you are the CISO or the operational-risk owner, you need a test that an APRA supervisor, an internal auditor or a Board Risk Committee can look at without wincing. That is a scoping and reporting problem as much as a technical one.
What the standard actually asks
CPS 234 requires entities to maintain an information-security capability commensurate with threats, to test the effectiveness of controls, and to notify APRA of material incidents. Independent testing is how you show the controls work against a human adversary, not only against a CVE feed.
Brief the threat, not the tool
Write down the attacker you actually worry about: a customer of internet banking, a staff member, a supplier with VPN, a ransomware crew on the LAN. Then buy the test that starts from that position. An external scan of the marketing site does not test the control you described in the last Board paper.
Map findings to controls
Ask the tester to tag findings against identity, access, logging, change and incident response, not only against OWASP. CVSS stays. Context is added. A medium that exposes member data is not presented as a medium in the executive summary.
Onshore is not optional flavour
Member data, incident evidence and screenshots of production systems are the sort of information entities already restrict. Sending them to an offshore scan factory because it was cheaper per day is a CPS 234 conversation waiting to happen. Our testers and evidence handling are onshore. That is the point of an Australian practice.
Related: financial services testing and request a CPS 234-mapped quote.