Following a formal investigation for cyber breaches following a cyber security attack in 2023 APRA commenced civil penalty proceedings in the Federal Court against Bendigo Bank Limited and Adelaide Bank (Bendigo Bank).
APRA and Bendigo Bank have agreed to a $8 million civil penalty for admitted contraventions of the Banking Executive Accountability Regime (BEAR), in relation to a cyber-attack in 2023. If ordered by the Court this would be highest penalty for a cyber security failing to date.
The failings concern breaches of the then BEAR requirement which have (now the Financial Accountability Regime (FAR) act requirements).
What follows is an overview of the implications of breaching BEAR/FAR obligations in respect to Senior Managers and Directors requirements under BEAR/FAR obligations with a particular emphasis on the recent Bendigo Bank proceedings in relation to cyber security.
Crucial factual circumstances
The proceedings relate to historical conduct and control weaknesses by Bendigo Bank in respect to cyber-security.
During the relevant period, Bendigo Bank operated the Alliance Bank network under its authorised deposit-taking institution (ADI) licence. The network included five authorised representatives and used the Ultracs banking system to provide customers with digital access to their accounts.
Penetration testing conducted in June 2020 identified several weaknesses in the customer authentication controls used by Service One Alliance Bank, including:
- password settings that allowed easily guessed passwords;
- different login error messages that could help an attacker determine whether a customer number was valid;
- the absence of CAPTCHA protections; and
- one-time-password multi-factor authentication being optional rather than automatically applied.
- These vulnerabilities were not merely theoretical. According to the agreed facts:
- the identified weaknesses were not remediated until March 2023;
- they were not appropriately escalated to Alliance Bank or Bendigo Bank management; and
- similar testing was not conducted across several other Alliance Bank partners before the attack.
Between 3 and 7 March 2023, an unidentified attacker carried out a brute-force attack against Service One Alliance Bank. At the time, 1,598 customer accounts were protected by the password “123456”, with other accounts using similarly weak passwords.
The attacker:
- gained access to approximately 257 customer accounts;
- made 286 unauthorised transactions;
- affected 87 Alliance Bank customers; and
- transferred approximately $490,000.
Although some payments were stopped or recovered, approximately $140,000 could not be recovered. Bendigo Bank reimbursed all affected customers.
APRA identified significant weaknesses in customer authentication controls for online banking, including password settings that permitted very weak passwords, multiple customer accounts with identical passwords and system design features that enabled a threat actor to identify valid customer IDs.
Furthermore, a number of those weaknesses were identified by penetration testing conducted in 2020 but were not addressed by Bendigo Bank prior to the cyber attack.
Testing happened. Coverage was still incomplete.
There was no shortage of governance processes. Bendigo Bank had an information security policy, an operational risk framework with an escalation matrix, a password standard approved by a technology committee, a dedicated framework for testing controls under the prudential information security standard, a three lines of defence model, and a risk register with dashboards at business unit, divisional and group level.
There was also independent assurance. Bendigo Bank received annual independent reports over the hosting infrastructure, a separate report over the software provider, and in 2022 it commissioned a further control review of the banking platform itself.
APRA was satisfied that Bendigo Bank satisfactorily remediated significant weaknesses following the cyber attack.
Furthermore, it was noted APRA does not currently have concerns regarding the adequacy of Bendigo Bank’s information security controls.
Implications
While the financial impact of the cyber incidents was limited, court action sends a clear message that all APRA-regulated entities must have appropriate cyber protection systems and regularly test the adequacy of those controls.
Expect that penalties for the same conduct today would be higher (noting that this occurred in 2023), with growing regulatory expectations.
Furthermore, the Banking Executive Accountability Regime has since been replaced by the Financial Accountability Regime, which applies a strengthened accountability framework to APRA-regulated entities, their directors and senior executives.
This also confirms continued focus on executives for management of these risks under the then BEAR (now Financial Accountability Regime (FAR)).
Note that BEAR now FAR is an extension of the general duties of officers and directors under the Corporations Act 2001 (Cth).
Senior Managers and Directors Accountability Obligations
Senior Managers and Directors need to ensure that polices and procedures are in place and in particular for information security.
APRA regulated entities need to ensure they:
- Have adequate governance and risk management for the information security of the IT system that enable digital access for customers;
- Undertake a systematic testing program for the customer authentication controls of as required by Prudential Standard CPS 234 – Information Security [1]; and
- Maintain adequate customer authentication controls for the prevention and detection of unauthorised access to customer accounts.
Reasonable Steps Going Forward
Senior managers and directors should ensure their FAR duties to have in place appropriate reasonable steps in respect to:
- governance, control and risk management;
- safeguards against inappropriate delegations of responsibility;
- procedures for identifying and remediating problems that arise or may arise ; and
- action a response to non‑compliance, or suspected non‑compliance.
Pavuk Legal can assist you with a full range of legal services in respect to your Corporate Governance needs including preparation of your Board Charter and Board Skills Matrix as well as the review of APRA regulated industry sector documents.
—
[1] Australian Prudential Regulation Authority, CPS 234 Information Security (at 1 July 2019) r 234.