Australia’s Superannuation Industry Faces Growing Cyber Threats
A Wake-Up Call from APRA
The Australian superannuation sector is on alert as the Australian Prudential Regulation Authority (APRA) issues a strong warning regarding the rising threat of cyber attacks. APRA has set a firm deadline of August 31 for superannuation funds to implement multifactor authentication and to report any significant weaknesses in their cyber security protocols. This move emphasizes the urgent need for enhanced cyber resilience within the industry.
In a recent letter dated July 10 to board chairs, APRA highlighted a concerning gap between existing cyber security measures and the evolving landscape of cyber threats. The authority stated, “Although APRA has consistently emphasised the importance of robust cyber security, it is clear that current controls are not always commensurate with the evolving vulnerabilities and threats, nor with the criticality and sensitivity of the member data and assets they protect."
Understanding the Scale of the Situation
With superannuation funds collectively managing over $4 trillion in member assets, the stakes are incredibly high. Brenton Steenkamp, head of the cyber practice at Clayton Utz, insists that boards must recognize that recent cyber incidents, such as credential stuffing attacks that led to significant financial losses for several members, should not be dismissed as isolated events.
“Cyber attacks can exploit industry-wide vulnerabilities, which often fall outside the remit of IT departments,” Steenkamp noted. He urged business leaders to elevate cyber risk from a technical viewpoint to a strategic one, emphasizing the importance of understanding what allowed such attacks to occur in the first place.
Protecting Trust and Customer Loyalty
The impact of cyber incidents extends beyond immediate financial losses. Doug Nixon, risk advisory partner at Clayton Utz, pointed out that superannuation funds hold not just member savings but also critical personal and identity data. If a member encounters poor communication or inadequate support following a cyber incident, it can severely damage long-term loyalty.
Nixon suggested that superannuation executives must invest in mapping out members’ experiences during a cyber incident, ensuring clear communication and robust support systems are in place. He acknowledged that, while many organizations have made considerable improvements in their cyber resilience, the rapidly changing landscape requires continuous adaptability.
Reevaluating Third-Party Relationships
One proactive step for super funds is a thorough reassessment of their third-party due diligence processes, particularly when sensitive data is involved. Contracts should clearly stipulate audit rights, notification of incidents, and provisions for cyber liability, Nixon advised.
Furthermore, boards must contemplate their preparedness to navigate the aftermath of a cyber crisis. While many receive regular updates on cyber risks, these often focus on past incidents and compliance rather than forward-looking strategies.
Simulating Crisis Scenarios
Nixon stressed the importance of conducting incident simulations tailored to the specific context of the superannuation industry. Such exercises can uncover gaps in decision-making, escalation paths, and board engagement. They serve not only to test a fund’s technical response but also to explore potential legal, reputational, and financial implications in the event of a cyber breach.
Conclusion
The rising threat of cyber attacks in the superannuation industry is a critical issue that demands immediate attention from boards and executives alike. With the financial well-being of millions of Australians at stake, enhancing cyber resilience is not just a technical necessity but a strategic imperative.


