iTnews
  • Home
  • News
  • Business
  • Finance

APRA presses banks, funds to check backup storage and deletion controls

By Ry Crozier
Jun 3 2024 2:57PM

Weeks after cloud incident at UniSuper.

Australia’s financial safety regulator has warned banks and other regulated entities to check their IT backups and admin permissions, in what appears to be a cloaked response to the UniSuper incident last month.

APRA presses banks, funds to check backup storage and deletion controls

The Australian Prudential Regulation Authority wrote an open letter to all entities to “clarify expectations on cyber security and adequacy of backups".

The letter notably describes three “common issues” that APRA suggested it had observed with backup systems in the sector.

Two of the three concerns related to where the backups are housed and who - if anyone - can modify or delete them.

APRA wrote that “sufficient isolation of backups from the production environment” must exist “so that a compromise of the production environment does not compromise backups." 

“This should include access controls preventing any single account or person to have permission to modify or delete both production and backup,” it said.

That advice appears to reflect some of the characteristics of the UniSuper incident last month, where a Google private cloud environment powering online services was mistakenly deleted due to a provisioning error a year earlier.

The super fund had backups on both Google and non-Google cloud infrastructure; both are said to have aided the fund’s recovery, although online services were still heavily impacted for a week.

APRA had indicated during the UniSuper incident that it had been observing the occurrence and recovery, though it publicly stayed relatively quiet throughout that process.

APRA did not link the sending of the letter to the specific UniSuper incident.

In a brief statement, it said “the communication is part of APRA's ongoing commitment to supervising cyber resilience across industry, as outlined in its interim policy and supervision priorities update" from January. The update makes no mention of backups, however.

Update, 17/6: The article originally emphasized the role of third-party backups in the restoration, referencing published information that "UniSuper had backups in place with an additional service provider. These backups have minimised data loss, and significantly improved the ability of UniSuper and Google Cloud to complete the restoration." Both organisations have since sought to emphasize the role that backups within Google Cloud also played in recovery.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
aprabackupcloudfinancenpgstorageunisuper

Related Articles

  • Defence advances 'novel' analytics capability Defence advances 'novel' analytics capability
  • CSR uses analytics for transport, manufacturing visibility CSR uses analytics for transport, manufacturing visibility
  • BHP taps Azure to keep to its ERP transformation timeline BHP taps Azure to keep to its ERP transformation timeline
  • Bendigo and Adelaide Bank is under new technology leadership Bendigo and Adelaide Bank is under new technology leadership

Partner Content

SOCO Reveals Microsoft AI with Power Platform Use Cases at Upcoming Government Event
Partner Content SOCO Reveals Microsoft AI with Power Platform Use Cases at Upcoming Government Event
Unlocking Cloud Potential: The Fusion5 Approach to Seamless Migration
Partner Content Unlocking Cloud Potential: The Fusion5 Approach to Seamless Migration
Non-technical job seekers are missing out on this in-demand cybersecurity career
Partner Content Non-technical job seekers are missing out on this in-demand cybersecurity career
AI isn’t coming for your job, but it might be coming for your Intellectual Property
Promoted Content AI isn’t coming for your job, but it might be coming for your Intellectual Property

Sponsored Whitepapers

Nine Ways To Prepare Your Database for a High-Traffic Event
Nine Ways To Prepare Your Database for a High-Traffic Event
How to Put AI at the Heart of Business Growth
How to Put AI at the Heart of Business Growth
Streamline Your Processes and Reduce Managed File Transfer Expenses
Streamline Your Processes and Reduce Managed File Transfer Expenses
Maximise Your Azure Investment with Fusion5
Maximise Your Azure Investment with Fusion5
CyberArk's 2024 Playbook: Identity Security and Cloud Compliance
CyberArk's 2024 Playbook: Identity Security and Cloud Compliance

Events

  • Integrate Integrate
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Bendigo and Adelaide Bank is under new technology leadership

Bendigo and Adelaide Bank is under new technology leadership

NAB finds legal limits for GenAI in fight against financial crime

NAB finds legal limits for GenAI in fight against financial crime

ANZ joins NAB and CBA on ConnectID

ANZ joins NAB and CBA on ConnectID

Bendigo and Adelaide Bank uses GenAI, MongoDB to refactor application

Bendigo and Adelaide Bank uses GenAI, MongoDB to refactor application

Digital Nation

COVER STORY: What AI regulation might look like in Australia
COVER STORY: What AI regulation might look like in Australia
More than half of loyalty members concerned about their data
More than half of loyalty members concerned about their data
How eBay uses interaction analytics to improve CX
How eBay uses interaction analytics to improve CX
State of Security 2023
State of Security 2023
Health tech startup Kismet raises $4m in pre-seed funding
Health tech startup Kismet raises $4m in pre-seed funding
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.