NGS Super rapped by APRA over cyber deficiencies

ngs super cybersecurity APRA cyber threats

11 December 2023
| By Laura Dew |
image
image
expand image

APRA has imposed additional licence restrictions on NGS Super, which suffered a cyber attack earlier this year.

Significant deficiencies have been identified in the fund’s cyber controls, APRA said, which has 114,000 members and $14 billion in assets under management.

The fund suffered a cyber attack in March wherein a cyber attacker gained access to some of its systems for a short period of time. The super fund assured members the incident had not impacted their super savings or the funds’ assets, which remained secure on a separate platform. 

The restrictions, which will apply from 11 December, follow an internal report by NGS and an independent tripartite review undertaken at APRA’s request.

The reviews identified deficiencies in NGS’ compliance with Prudential Standard CPS 234 – Information Security, while the cyber incident involved a significant amount of data being lost and NGS’ systems being compromised for a period. 

APRA acknowledged that NGS has taken steps since the attack to address the review’s recommendations – the additional licence conditions will require NGS to engage with an independent third party to provide assurance regarding NGS’ remediation activities and to address the recommendations contained in the internal audit and tripartite review reports and conduct an operational effectiveness review of the CPS 234 controls and frameworks in place for NGS.  

NGS is required to provide APRA with an attestation from its chair that the actions are complete and effective and are compliant with CPS 234.

A statement from NGS Super said: "NGS Super is working with APRA to meet the additional requirements they have requested of the fund, primarily in relation to compliance with CPS 234. We’ve reviewed our processes and acted to further strengthen the protection of our members’ data and retirement savings. We’ve had multifactor authentication for a very long time and have now implemented enhanced cyber controls across the fund and we’ll continue to do so to minimize risk and maximize protection of our information security. 

"We remain confident of the actions we’ve taken and continue to do following a thorough review of our cyber security. We’re also committed to working with APRA and an independent party to identify and implement additional actions. Ultimately, this will lead to further assurance and protection for our members.

"We use administrative, physical, and technical safeguards to protect the confidentiality and integrity of personal information and data and are committed to protecting our members' personal information."

In May, APRA wrote to its regulated entities to reinforce the importance of multifactor authentication to protect sensitive data from cyber attacks.

In an open letter, Alison Bliss, general manager for operational resilience, cross-industry division, told APRA-regulated entities that it was a “material security control weakness” if firms failed to comply.

“Multifactor authentication (MFA) is one of the most effective controls an organisation can implement to prevent an adversary from gaining access to a device or network and accessing sensitive information.”

 

Read more about:

AUTHOR

Add new comment

The content of this field is kept private and will not be shown publicly.

Recommended for you

sub-bgsidebar subscription

Never miss the latest news and developments in wealth management industry

MARKET INSIGHTS

James Patterson

How much did IRESS pay Deloitte for this analysis? Not sure they are the arbiter of intelligent forecasting in this spac...

13 hours ago
Howard Elton

Article makes no comment that the advisers leaving industry are older and have many years of work an life experience w...

1 day 20 hours ago
Peter Robinson

This article appears to overlook the fact that there must be a fairly large group of advisers who missed out on the expe...

1 day 20 hours ago

ASIC has secured travel restraint orders against a financial adviser while he is the subject of an investigation into alleged financial misconduct....

4 days 14 hours ago

Insignia Financial has unveiled a new operating model and executive team, including a new head of advice, while three senior executives are set to depart the licensee....

2 weeks 1 day ago

Analysis by Chant West of the annual performance of growth superannuation funds has uncovered which ones see the best performance....

1 week 1 day ago

TOP PERFORMING FUNDS

ACS FIXED INT - AUSTRALIA/GLOBAL BOND
Fund name
3y(%)pa
1
Ardea Diversified Bond F
144.00 3 y p.a(%)
3
Hills International
63.39 3 y p.a(%)