// Financial services

Penetration testing for Australian financial services

APRA-regulated entities do not need another scan PDF. They need independent testing that maps to CPS 234, survives a risk-committee read, and does not leave customer data in a contractor's laptop overseas.

A completed security checklist with a verification seal

Australian ADIs, insurers and superannuation trustees sit under APRA CPS 234. Complementary standards (CPS 230 operational resilience, the SOCI Act for critical infrastructure) keep asking the same practical question: have you tested the controls you claim, independently, recently, against a threat that looks like the one you wrote down?

We run web, API, cloud and network tests for financial-services teams who need that answer in writing. Findings are rated with CVSS 3.1 and with business context a CISO can take upstairs. Evidence stays onshore. Retesting is included so the board pack can say "closed", not "open, vendor quote pending".

We will not pretend a three-day external scan is a CPS 234 information-security control test. If your last "pentest" was a Nessus export, we should talk before the next prudential review.

How we map to CPS 234

  • Information-security capability: the test itself is independent control testing, not self-assessment.
  • Testing of controls: we exercise identity, access, logging and incident paths, not just CVE lists.
  • Incident management: critical findings are phoned through the same day, with an agreed severity rubric.
  • Notification: we help you distinguish a reportable incident from a finding, we do not notify APRA for you.

Longer briefing: APRA CPS 234 and security testing.

Internet banking and portals

Authenticated testing of customer and adviser channels, including session and step-up.

Payments APIs

BOLA, idempotency, replay, and the partner callbacks nobody listed in the last scope.

Cloud tenancy

Identity paths and public storage in the AWS/Azure estates that now hold the core.

Internal AD

The assumed-breach path from a standard user to something a regulator would call material.

Talk to a tester, not a form-letter

Send the framework, the target and the date of the next audit. We will quote a test that produces evidence for that date.

Get a fixed quote