Strengthening Cyber and Operational Resilience in Financial Services
Financial services businesses depend on trust, continuity and the protection of sensitive information. LOOKUP helps firms strengthen identity, Microsoft 365, backup, recovery and incident readiness — building resilience that goes beyond prevention to detection, response and recovery.
The short answer
How should a financial services business strengthen cyber and operational resilience? By building coordinated controls across identity, MFA, privileged access, devices, patching, email, Microsoft 365, specialist platforms, information, third parties, backup, recovery testing, incident response and business continuity — and by understanding which regulatory frameworks apply to the specific entity.
Cyber resilience is broader than prevention. It encompasses the ability to detect, respond to and recover from disruption. Operational resilience extends further — covering critical business processes, technology dependencies, people, third parties and the ability to continue delivering services during and after incidents.
Importantly, not every financial services business is APRA-regulated. Requirements such as CPS 234 and CPS 230 apply to specific entity types. Businesses should confirm which regulatory frameworks apply to their circumstances rather than assuming universal obligations.
Cyber resilience is broader than prevention
No set of controls can eliminate all cyber risk. Financial services businesses need the ability to detect threats, respond effectively, recover operations and improve over time. This is the resilience model:
Identify
Understand assets, risks and dependencies.
Protect
Implement controls to reduce likelihood and impact.
Detect
Monitor for threats and anomalies.
Respond
Escalate, contain and manage incidents.
Recover
Restore operations and improve.
Prevention alone is insufficient. A business that can prevent common attacks but cannot recover from a successful incident is not resilient.
Identity and MFA
Identity is the modern security perimeter. Multi-factor authentication is one of the most effective controls for reducing unauthorised access. LOOKUP recommends enforcing MFA across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled.
Identity controls should cover user lifecycle — joiners, movers and leavers — as well as dormant accounts, privileged identities, shared accounts and external identities. Conditional access policies, where available, can add context-aware controls based on location, device and risk.
For deeper guidance on identity and access controls, see our guide to protecting client information in a financial services business.
Privileged access
Administrative accounts hold elevated privileges that can cause significant harm if compromised. Financial services businesses should identify privileged accounts, restrict their use, apply MFA, and review them regularly. Privileged access should follow least-privilege principles — administrators should have the minimum access necessary, not unlimited tenant-wide control by default.
Shared administrative accounts create accountability gaps. Wherever practical, individual accounts should be used so that actions are attributable to a specific person.
Endpoint and mobile security
Devices — laptops, desktops, tablets and phones — are where staff access sensitive information. Endpoints should be supported, patched, protected with endpoint security, and managed through device management where practical. Encryption should be enabled on devices holding sensitive information.
Lost or stolen devices should be remotely wiped. Businesses should understand which devices access business information and ensure those devices meet minimum security standards.
Email and business email compromise
Email remains a primary attack vector. Business email compromise — where attackers impersonate trusted parties to manipulate payments, redirect funds or extract sensitive information — is a significant risk for financial services businesses.
Important controls include MFA on email accounts, staff awareness of phishing and impersonation, verification processes for changes to payment details or client instructions, and email security configuration that reduces spoofing and malicious content reaching users.
Sensitive information should not be sent as unsecured email attachments. Controlled sharing through governed systems is safer than ad-hoc email distribution.
Microsoft 365 security
According to official Microsoft documentation, Microsoft 365 provides extensive security capabilities — including conditional access, multi-factor authentication, information protection, threat protection, audit logging and external sharing controls. However, security is not automatic. It requires deliberate configuration and ongoing governance.
Key areas to review include identity configuration, administrative roles, external sharing defaults, SharePoint and Teams permissions, email protection, device access policies and information protection settings. Not all capabilities exist in every licence — firms should understand what their subscription includes.
Learn how LOOKUP helps financial services businesses optimise Microsoft 365 security →
Specialist financial-services platforms
Financial services businesses use specialist platforms — CRM, advice platforms, practice management, loan systems and client portals — that hold sensitive information. Security must extend beyond Microsoft 365 to cover these systems.
Key considerations include user lifecycle management, administrative roles, MFA where supported, review of integrations and API credentials, and assessment of vendor security and data handling. Each platform may have its own security configuration that needs review.
LOOKUP does not assume Microsoft 365 is the only information environment. Security and governance should span the entire ecosystem of systems holding sensitive information.
Backup and verified recovery
A backup strategy is incomplete until recovery has been tested. Backup exists does not mean recovery is verified. Financial services businesses should assess backup and recovery requirements for business-critical information, including appropriate separation from the production environment and regular restore testing based on the firm's recovery objectives.
Cloud platforms provide infrastructure resilience, but organisations remain responsible for their information. Firms should understand what their cloud platforms provide and what they remain responsible for — and test recovery accordingly.
LOOKUP Perspective: For organisations where Microsoft 365 information is business-critical, LOOKUP generally recommends evaluating independent backup and recovery capabilities as part of the firm's broader business continuity strategy.
Incident response
Financial services businesses should have documented incident response plans that clarify who makes decisions, who contacts technical responders, who manages communications, where the plan is stored and how incidents are escalated. Plans should be tested or exercised periodically.
Incident response should cover detection, escalation, containment, technical response, communication, recovery and lessons learned. Where regulatory notification obligations may apply, firms should understand their responsibilities and seek appropriate professional advice.
Operational resilience
Operational resilience is the ability to continue delivering critical services during and after disruption. It encompasses technology, people, processes, third parties and recovery. For financial services businesses, operational resilience means understanding which processes are critical, what technology they depend on, what could disrupt them, and how the business would continue operating.
There is no single universal regulatory definition of operational resilience that applies to all financial services businesses. APRA-regulated entities have specific obligations; other businesses should adopt resilience practices proportionate to their risk profile and professional responsibilities.
APRA CPS 234
According to APRA, CPS 234 is a prudential standard on information security that applies to APRA-regulated entities. It requires those entities to maintain information security capabilities proportionate to the size and complexity of their operations, and to notify APRA of material information security incidents.
CPS 234 does not apply to every financial adviser or financial-services business. Regulatory obligations depend on entity type, licence and activities. Businesses should confirm their specific obligations with appropriate professional advisers.
APRA CPS 230
According to APRA, CPS 230 is a prudential standard addressing operational risk management, business continuity and the management of third-party service providers. It applies to APRA-regulated entities.
CPS 230 does not apply universally to all financial services businesses. Its requirements concerning operational risk, critical operations, business continuity and third-party management are specific to APRA-regulated entities. Confirm applicability and current implementation requirements with appropriate professional advisers.
ASIC and cyber resilience
According to ASIC, Australian financial services licensees have obligations relating to cyber resilience and the protection of client information. ASIC has published guidance on cyber resilience expectations and has taken regulatory action in cases involving inadequate cyber security controls.
ASIC's guidance should not be interpreted as a universal control checklist applicable identically to every business. Firms should understand their specific obligations and implement controls proportionate to their risk profile, activities and regulatory context.
The Essential Eight
According to the Australian Cyber Security Centre, the Essential Eight is a set of baseline mitigation strategies designed to reduce cyber risk. It covers application control, patching, Microsoft Office macro controls, user application hardening, restricting administrative privileges, operating system patching, multi-factor authentication and regular backups.
The Essential Eight is not a universal legal requirement for all financial services businesses. However, LOOKUP recommends it as a practical baseline for strengthening cyber resilience. Some regulated entities may be expected to implement equivalent or more comprehensive controls.
Third-party technology risk
Financial services businesses depend on cloud services, managed providers, specialist platforms, integrations and critical suppliers. Each third-party relationship introduces access, dependency and recovery considerations.
Businesses should identify critical suppliers, understand their access to systems and information, review integration and API credentials, assess vendor security and data handling, and consider what happens if a critical supplier is disrupted. Recovery dependencies on third parties should be understood and tested where practical.
How this maps to the LOOKUP Business Modernisation Framework™
Strengthening cyber and operational resilience follows a structured progression — from understanding the current environment through to continuous improvement.
Map critical business processes, technology dependencies and information flows.
Strengthen identity, access, devices, email and Microsoft 365 security.
Address unsupported systems and improve security foundations.
Create consistent security policies, device standards and access reviews.
Improve monitoring, logging and security visibility across systems.
Document incident response, business continuity and recovery plans.
Deploy security controls, backup improvements and resilience measures.
Test recovery, review incidents and continuously strengthen resilience.
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
Understand the current environment
Protect identities, devices and information
Remove legacy technology constraints
Create consistent systems and processes
Improve workflows and productivity
Establish governance and AI readiness
Introduce technology deliberately
Measure, review and continuously improve
What success looks like
Strengthening cyber and operational resilience is measured by the business's ability to prevent, detect, respond and recover — not by the number of security products deployed.
Stronger Identity
MFA, least privilege and managed access across systems.
Better Security Visibility
Clearer understanding of who has access and where risks exist.
Clearer Responsibilities
Defined ownership for security, recovery and incident response.
Verified Recovery
Backup and recovery tested against business objectives.
Better Incident Readiness
Documented plans for detection, escalation and response.
Stronger Third-Party Oversight
Vendor access, integrations and dependencies understood.
Improved Operational Resilience
Critical processes and dependencies mapped and protected.
Research and regulatory context
Australian financial services businesses operate within a regulatory ecosystem that includes APRA, ASIC, the OAIC and the ACSC. The specific obligations that apply depend on entity type, licence, activities and the information handled.
APRA-regulated entities are subject to prudential standards including CPS 234 (information security) and CPS 230 (operational risk management). These standards do not apply universally to all financial services businesses.
ASIC has published guidance on cyber resilience for financial services licensees and has taken enforcement action in cases involving inadequate cyber controls. The Australian Cyber Security Centre provides the Essential Eight as a practical baseline for reducing cyber risk.
These organisations do not prescribe a single approach applicable to every business. Regulatory obligations vary, and businesses should confirm their specific requirements with appropriate professional advisers.
What this could look like in practice
This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges financial services businesses may encounter and demonstrates how a structured technology approach could be applied.
A growing financial services firm uses Microsoft 365 alongside specialist cloud platforms for CRM, advice and practice management. Over time, privileged access has accumulated across several administrator accounts. MFA is enforced on some systems but not all. Backup exists for some platforms but recovery has not been recently tested. Third-party integrations have been added without recent review. No documented incident response plan exists.
Potential Business Outcomes
Frequently asked questions
Why do financial services businesses need cyber security?
Financial services businesses hold sensitive client, financial and identity information that is attractive to cyber criminals. Strong cyber security protects client trust, supports business continuity, reduces operational risk and helps meet regulatory and professional obligations where applicable.
What cyber controls should financial advisers use?
Key controls include multi-factor authentication, least-privilege access, patched and supported devices, email security, Microsoft 365 configuration, backup and verified recovery, incident response planning and staff awareness. Controls should be proportionate to the business's risk profile and obligations.
Do financial services businesses need MFA?
LOOKUP recommends enforcing multi-factor authentication across user accounts, with any necessary technical exceptions formally assessed and appropriately controlled. MFA is one of the most effective controls for reducing unauthorised access.
What is operational resilience?
Operational resilience is the ability of a business to continue delivering critical services during and after disruption. It encompasses technology, people, processes, third parties and recovery. It is broader than cyber prevention — it includes detection, response, recovery and adaptation.
What is CPS 234?
CPS 234 is an APRA prudential standard on information security. It requires APRA-regulated entities to maintain information security capabilities proportionate to the size and complexity of their operations, and to notify APRA of material information security incidents.
Who must comply with CPS 234?
CPS 234 applies to APRA-regulated entities such as banks, insurers and superannuation trustees. It does not apply to every financial adviser or financial-services business. Regulatory obligations depend on entity type, licence and activities.
Does CPS 234 apply to every financial adviser?
No. CPS 234 applies to APRA-regulated entities. Many financial advice practices, credit businesses and other professional financial-services firms are not APRA-regulated. Businesses should confirm their specific obligations with appropriate professional advisers.
What is CPS 230?
CPS 230 is an APRA prudential standard on operational risk management. It addresses operational risk, business continuity and the management of third-party service providers. It applies to APRA-regulated entities — not universally to all financial services businesses.
Who does CPS 230 apply to?
CPS 230 applies to APRA-regulated entities. Its requirements concerning operational risk, business continuity and third-party management do not apply universally to every financial adviser or financial-services business. Confirm applicability with appropriate professional advisers.
What is the Essential Eight?
The Essential Eight is a set of baseline mitigation strategies published by the Australian Cyber Security Centre to help organisations reduce cyber risk. It covers application control, patching, MFA, least privilege, backups and other controls. LOOKUP recommends it as a practical baseline for financial services businesses.
Do financial services businesses have to use the Essential Eight?
The Essential Eight is not a universal legal requirement for all financial services businesses. However, it is widely recognised Australian Government guidance and provides a practical baseline for strengthening cyber resilience. Some regulated entities may be expected to implement equivalent controls.
Do cloud applications need backup?
Cloud platforms provide infrastructure resilience, but organisations remain responsible for their information. Firms should assess whether their recovery objectives require additional backup capabilities beyond what the cloud platform provides. Recovery should be tested — backup exists does not mean recovery is verified.
What is recovery testing?
Recovery testing is the process of verifying that information can be restored from backup within the business's required timeframes. A backup that has never been tested cannot be relied upon. Testing confirms that recovery works, that information is intact and that the business can resume operations.
How should third-party technology risk be managed?
Third-party technology risk should be managed through vendor assessment, review of access and integrations, understanding of data handling, evaluation of business continuity dependencies, and clear contractual terms. Critical suppliers should be identified and their failure scenarios considered.
Where should a financial services business start?
Start by mapping critical business processes and technology dependencies. Review identity, MFA and privileged access. Assess backup and recovery. Document incident response responsibilities. Review third-party access. Then build a practical plan to strengthen the weakest areas first.
What business leaders should do next
To bring cyber and operational resilience into a coordinated technology strategy, see our guide to building a technology roadmap for a financial services business.
Executive guides
Business Modernisation Framework™
The eight-stage methodology guiding every LOOKUP engagement.
Business Technology Roadmap
Build a practical technology roadmap aligned with long-term business goals.
Cyber Insurance Readiness
Strengthen cyber maturity before insurance renewal discussions.
ISO 27001 Advisory
Understand ISO 27001 and strengthen information security governance.
Preparing for AI
Governance, information and security foundations for AI adoption.
Financial Services Industry Page
Technology services designed for financial services businesses.
How LOOKUP can help
LOOKUP helps financial services businesses strengthen cyber security, improve Microsoft 365 governance, verify recovery and build operational resilience — through practical, business-first technology leadership.
Sources & Further Reading
Australian Prudential Regulation Authority
Information Security — CPS 234 (2023)
APRA prudential standard on information security applicable to APRA-regulated entities — not universal for all financial services businesses.
View SourceAustralian Prudential Regulation Authority
Operational Risk Management — CPS 230 (2024)
APRA prudential standard on operational risk management, business continuity and third-party management for APRA-regulated entities.
View SourceAustralian Securities and Investments Commission
Cyber Security Guidance (2023)
ASIC guidance on cyber resilience and information security for financial services licensees.
View SourceAustralian Cyber Security Centre
Essential Eight Explained (2023)
Recommended baseline of mitigation strategies for reducing cyber risk across Australian organisations.
View SourceMicrosoft
Microsoft 365 Security Documentation (2024)
Official documentation on identity, conditional access, information protection and security configuration within Microsoft 365.
View SourceOffice of the Australian Information Commissioner
Australian Privacy Principles Guidelines (2024)
Guidance on privacy obligations relevant to collecting, storing and handling personal information.
View SourceEvidence Standard: LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.
This page provides general business technology and governance information and is not financial, legal, regulatory, privacy or compliance advice. Cyber insurance requirements, coverage and underwriting decisions vary by insurer, policy and organisation. Confirm requirements with your insurer, broker and appropriate professional advisers.
Strengthen Resilience Before You Need It
LOOKUP helps financial services businesses strengthen cyber security, verify recovery, improve operational resilience and build practical incident readiness through business-first technology leadership.