☀ New York | Saturday October 3, 2026 | Sign In
⚡ TRENDING NOW

Bank fined $8m over cybersecurity lapses

Bank fined $8m over cybersecurity lapses - cybersecurity lapses
Bank fined $8m over cybersecurity lapses

APRA has taken significant accountability enforcement action against Bendigo and Adelaide Bank for failing to address known cyber weaknesses, seeking over $8 million in penalties.

Federal Court documents filed on 10 August 2026 detail how the bank neglected multiple security recommendations, which later enabled a March 2023 cyber-attack on its Alliance Bank business. The incident resulted in consumer losses of $140,110, a fraction of the proposed penalty.

Preventable breach traced to years of inaction

The Statement of Agreed Facts and Admissions (SAFA) outlines a series of unactioned cyber security recommendations over an extended period. Among the unresolved issues were weak password configurations, the absence of mandatory multi-factor authentication and CAPTCHA, and an observation of “immature” information security governance at Ultradata, the provider of core banking system software.

These risks were logged into a tracking tool but were never escalated to bank or Alliance Bank management. They were also not assessed against the bank’s Operational Risk Framework or provided to the third-party provider for remediation. The vulnerabilities remained unaddressed until the March 2023 brute force cyber-attack, which the bank’s internal post-incident review concluded could likely have been avoided had the identified risks been properly assessed, escalated, and managed.

APRA’s case focuses on alleged violations of CPS 234, the prudential standard for information security. The regulator claims Bendigo and Adelaide Bank failed to maintain adequate customer authentication controls, undertake a systematic testing program for those controls, or ensure appropriate information security governance and risk management for systems allowing digital access to customer accounts.

Gaps in executive responsibility left operations exposed

The enforcement action highlights a material gap in accountability under the Banking Executive Accountability Regime (BEAR), the framework preceding the current Financial Accountability Regime (FAR). On 29 August 2022, the bank updated its Chief Technology Officer’s accountability statement to exclude “IT Operations for Alliance Bank” and “Support and maintenance of Business Managed IT.” These responsibilities were not reallocated to any other accountable person, despite being flagged at a BEAR workshop for new ownership.

From 29 August 2022 until 30 August 2023, no accountable person’s statement covered Alliance Bank’s information technology operations. APRA has alleged that this oversight breached the bank’s obligation to conduct the business of Alliance Bank with due skill, care, and diligence.

For other regulated institutions, the case shows the importance of ensuring audit findings and recommendations are progressed according to their significance and potential to cause consumer harm. While BEAR has since been replaced by FAR, APRA has emphasized that accountability statements must cover all operations without gaps.

Legal proceedings and industry implications

APRA is pursuing Federal Court orders under the Banking Act 1959 for the alleged breaches, including pecuniary penalties and costs. The proposed over $8 million in penalties reflects the regulator’s focus on cyber governance failures.

The case also serves as a reminder for institutions preparing for FAR compliance. The exclusion in the CTO’s role left critical IT functions unassigned for a year, demonstrating how such oversights can occur even in organizations with established risk frameworks.

For now, the matter remains before the Federal Court. The broader message to the industry is clear: cyber resilience requires identified risks to have clear ownership and timely action. Accountability mapping plays a central role in ensuring these standards are met.

LinkSquares recently rebuilt its contract intelligence engine, demonstrating how technology providers are addressing similar governance challenges in other sectors.

Leave a Reply

Your email address will not be published. Required fields are marked *