Identity-related security remains a core challenge for Australia’s finance sector

Identity-related security remains a core challenge for Australia’s finance sector

As APRA highlights recurring failures in identity and third-party security, the finance sector faces renewed urgency to modernise its controls, exceed CPS 234 requirements and adopt adaptive, intelligence-driven cyber-resilience strategies. Scott Hesford, Director of Solutions Engineering Asia Pacific and Japan, BeyondTrust, explores how identity-related security remains a core challenge for Australia’s finance sector.

Cyber-resilience remains a key concern for the finance sector heading into the new year. While entities have had to take measures to be resilient against information security incidents for six years now under the Australian Prudential Regulation Authority (APRA) Prudential Standard CPS 234, it is apparent from mandatory incident reports that resilience remains a work in progress.

“Six years after APRA’s first prudential standard on information security, CPS 234, took effect, all APRA-regulated entities take cybersecurity with the seriousness you’d expect,” APRA member Suzanne Smith said in a recent speech. “However, looking across the financial system, the level of cyber-resilience remains uneven and persistent gaps remain.”

The centrepiece of Smith’s comments on CPS 234 highlights four ‘repeatable patterns’ that regularly feature in the detailed reports it receives from institutions that experience security incidents.

Two of the four ‘repeatable patterns’ are identity-security related.
This is a clear indication of where Australia’s finance sector should be prioritising investment in security strategies, controls and solutions to support its efforts.

The first regularly observed pattern is ‘credential compromise and a lack of strong authentication’. This is perhaps unsurprising given the spate of credential-stuffing attacks against Australian superannuation funds earlier this year. But CPS 234 pre-dates that threat activity and for APRA to call it out, it is likely that the issue runs deeper than the superannuation sector alone.

In Smith’s words, credential-stuffing and spraying-type attacks are ‘more effective than they should be’ in this day and age. Password spraying targets multiple accounts within an organisation using a few common passwords. In contrast, credential stuffing involves using a large set of username–password pairs obtained from previous data breaches to gain unauthorised access to various online services.

Defending against these attacks requires a proactive, multi-layered cybersecurity approach and robust identity-based security, including the removal of admin privileges on workstations, password vaults, multi-factor authentication, monitoring and auditing of user activity and account lockout mechanisms, to name a few. Additionally, implementing controls that enforce the Principle of Least Privilege ensures that, should an account be hijacked by an attacker, the ability to inflict damage is limited. This also extends to the ability to report on the privileges associated with identities, whether human or machine — including AI agents.

The second identity-security related pattern regularly seen by APRA relates to ‘service provider incidents’. “These include exposures in service providers spilling into regulated entities, underscoring third-party assurance gaps as well as the effectiveness of techniques to limit contagion,” Smith said.

Third parties — including vendors, service providers, independent consultants, contractors and partners — often need access to an organisation’s network to conduct essential business and IT operations. Previous research has found that, on average, 182 users from various third parties, including vendors, log into the systems of the typical enterprise each week.

Best practice dictates that access shouldn’t be as simple as ‘on’ or ‘off’. Rather, to conduct business safely, IT organisations must be in control of centralised vendor access pathways that allow them to enforce access control policies and record and monitor all third-party activity. By using a just-in-time control mechanism, specific users are given precisely the right level of access to applications, sessions and protocols — and only for the duration that access is needed.

Privileged password management and multi-factor authentication provide additional layers of protection by managing vendor and remote employee passwords, injecting credentials directly into remote access sessions without ever revealing them to the user, and rotating them regularly. Such systems are also capable of recording all user activity, which can be played back on demand or provide an opportunity to terminate access when suspected malicious activity is detected.

The end goal is adaptive security

A key theme in these best-practice approaches to identity-related security is getting organisations to a point where their security and access controls become adaptive — dynamically adjusting based on the circumstances in which system access is being sought.

This is the pinnacle of cybersecurity maturity in the identity-related security space. While many organisations may never achieve this, it remains a desirable end goal.

In this state, information security capability is fully integrated, adaptive and self-improving. The organisation not only meets the requirements of CPS 234 but exceeds them, using pre-emptive technology and processes to continually enhance its security posture.

Reaching such a state is important given recent context. In a separate speech, APRA’s Executive Director Carmen Beverley-Smith was unambiguous that exceeding CPS 234 requirements should be the end goal.

While acknowledging the constantly changing nature of the threat environment, Beverley-Smith made it clear that organisations are expected not just to keep pace but to exceed expectations. “It is important to remember that CPS 234 articulates compliance obligations or minimum requirements. It by no means represents the level of information security governance that well-managed funds should aspire to,” she said.

Now, more than ever, Australia’s finance industry needs to update its information security approach and prioritise investments in identity-related security.

By implementing a holistic, multi-level approach to the way privileges are managed across their organisation – including all local users and third parties – cybersecurity leaders afford themselves the opportunity not only to get ahead of evolving CPS 234 baseline requirements but also to make their environments more adaptive to whatever the security landscape throws at them in the coming years.

Browse our latest issue

Intelligent Fin.tech

View Magazine Archive