iTnews
  • Home
  • News
  • Business
  • Finance

APRA presses banks, funds to check backup storage and deletion controls

By Ry Crozier
Jun 3 2024 2:57PM

Weeks after cloud incident at UniSuper.

Australia’s financial safety regulator has warned banks and other regulated entities to check their IT backups and admin permissions, in what appears to be a cloaked response to the UniSuper incident last month.

APRA presses banks, funds to check backup storage and deletion controls

The Australian Prudential Regulation Authority wrote an open letter to all entities to “clarify expectations on cyber security and adequacy of backups".

The letter notably describes three “common issues” that APRA suggested it had observed with backup systems in the sector.

Two of the three concerns related to where the backups are housed and who - if anyone - can modify or delete them.

APRA wrote that “sufficient isolation of backups from the production environment” must exist “so that a compromise of the production environment does not compromise backups." 

“This should include access controls preventing any single account or person to have permission to modify or delete both production and backup,” it said.

That advice appears to reflect some of the characteristics of the UniSuper incident last month, where a Google private cloud environment powering online services was mistakenly deleted due to a provisioning error a year earlier.

The super fund had backups on both Google and non-Google cloud infrastructure; both are said to have aided the fund’s recovery, although online services were still heavily impacted for a week.

APRA had indicated during the UniSuper incident that it had been observing the occurrence and recovery, though it publicly stayed relatively quiet throughout that process.

APRA did not link the sending of the letter to the specific UniSuper incident.

In a brief statement, it said “the communication is part of APRA's ongoing commitment to supervising cyber resilience across industry, as outlined in its interim policy and supervision priorities update" from January. The update makes no mention of backups, however.

Update, 17/6: The article originally emphasized the role of third-party backups in the restoration, referencing published information that "UniSuper had backups in place with an additional service provider. These backups have minimised data loss, and significantly improved the ability of UniSuper and Google Cloud to complete the restoration." Both organisations have since sought to emphasize the role that backups within Google Cloud also played in recovery.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
aprabackupcloudfinancenpgstorageunisuper

Related Articles

  • NAB retires its Tableau environment NAB retires its Tableau environment
  • Oracle shares jump as AI push perks up cloud demand Oracle shares jump as AI push perks up cloud demand
  • Coles Group calculates a TCO for its enterprise applications Coles Group calculates a TCO for its enterprise applications
  • US proposes requiring reporting for advanced AI, cloud providers US proposes requiring reporting for advanced AI, cloud providers

Partner Content

Securing Modern Enterprise: IT Leaders Address Third-Party Risk Management
Partner Content Securing Modern Enterprise: IT Leaders Address Third-Party Risk Management
Why maintaining your hardware can improve your cloud journey
Partner Content Why maintaining your hardware can improve your cloud journey
Avoid a risky ‘big bang’ ServiceNow deployment with Accelerate IT Solutions’ staged approach
Partner Content Avoid a risky ‘big bang’ ServiceNow deployment with Accelerate IT Solutions’ staged approach
‘Work Anywhere, Thrive Everywhere’: Embracing Boundless Workplaces in a Changing World
Partner Content ‘Work Anywhere, Thrive Everywhere’: Embracing Boundless Workplaces in a Changing World

Sponsored Whitepapers

Redefining Vulnerability Management
Redefining Vulnerability Management
How JLL gained visibility into nearly 100K endpoints with Tanium
How JLL gained visibility into nearly 100K endpoints with Tanium
Why a holistic approach to managing risk is key to solving complex IT problems
Why a holistic approach to managing risk is key to solving complex IT problems
High Availability: The Foundation of Digital Transformation
High Availability: The Foundation of Digital Transformation
Nine Ways To Prepare Your Database for a High-Traffic Event
Nine Ways To Prepare Your Database for a High-Traffic Event
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Suncorp builds generative AI engine 'SunGPT'

Suncorp builds generative AI engine 'SunGPT'

NAB drives automation deeper into its IT operations

NAB drives automation deeper into its IT operations

Coles Group calculates a TCO for its enterprise applications

Coles Group calculates a TCO for its enterprise applications

ANZ joins NAB and CBA on ConnectID

ANZ joins NAB and CBA on ConnectID

Digital Nation

How eBay uses interaction analytics to improve CX
How eBay uses interaction analytics to improve CX
State of Security 2023
State of Security 2023
Health tech startup Kismet raises $4m in pre-seed funding
Health tech startup Kismet raises $4m in pre-seed funding
More than half of loyalty members concerned about their data
More than half of loyalty members concerned about their data
COVER STORY: What AI regulation might look like in Australia
COVER STORY: What AI regulation might look like in Australia
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.