Data breaches could damage executive pay packets: APRA

Share:

Risk regulator reiterates expectations around cyber security risk.

By David Braue on Nov 29 2022 12:54 PM

Share

Executives could have their compensation slashed after a data breach, Australia’s peak insurance industry regulator has warned in announcing “intensified” scrutiny of Medibank and a crackdown on regulatory compliance as cyber criminals continue to pillory their victims online.

The severity of the breach – which has sent authorities scrambling as Russian cyber criminals publish the personal healthcare data of thousands of Australians – had “raised concerns about the strength of [Medibank’s] operational risk controls,” the Australian Prudential Regulation Authority (APRA) said in announcing that it had rolled up its sleeves to engage directly with the private health insurer and cyber investigators.

Medibank has been “open and cooperative with APRA during this time,” the agency said in revealing that it had been involved in setting the scope of an external review of the company’s risk management – which was announced by Medibank on 16 November and will be completed by Deloitte.

“While APRA notes Medibank’s constructive response to date, APRA will consider whether further regulatory action is needed when findings of the report become clear,” APRA Member Suzanne Smith said, noting that the regulator “expects Medibank to undertake any recommended actions.”

This included “appropriate consequence management” – including the potential for “impacts to executive remuneration where appropriate” in the wake of major data breaches that are allowed to happen under their watch.”

Despite their risk management failures, it was recently revealed that Medibank executives were still set to receive around $7.3 million in bonuses – despite revelations that they had decided not to take out cyber insurance to protect the company and its customers’ data against the risk of a cyber security breach.

This failure had left the company fighting to develop and execute an ad hoc response, even as hackers curated the stolen data and published it in small releases sorted by medical condition.

Putting teeth into cyber risk regulations

APRA’s crackdown comes amidst reports that the online blog that the hackers were using had gone dark, having gone offline some time between 21 and 22 November.

Whether that change marks a reprieve for Medibank, or hackers are simply regrouping for a redoubled attack on their victims, remains to be seen.

In the interim, however, APRA’s pronouncement marks an escalation of its expectations that companies and their executives take all appropriate measures to protect their data from compromise.

Those expectations were established with the November 2018 introduction of APRA’s Prudential Standard CPS 234 Information Security, which laid down the regulator’s expectations of insurers, superannuation operators, and other companies in APRA-regulated industries.

The companion Prudential Practice Guide CPG 234, last updated in June 2019, includes guidance for regulated companies – of which Medibank is one – about how to comply with CPS 234 and, more broadly, how to ensure they have appropriate risk management controls in place.

Poor cyber risk controls have increasingly created financial headaches for companies found to be in breach of their prudential obligations, with financial services firm RI Advice fined $750,000 after the Federal Court found the company’s directors had failed to meet their obligations to uphold a “reasonable standard” of cyber security.

As APRA and other government agencies pick up the pieces in the wake of a season of major data breaches led by the Medibank and Optus compromises, executives of companies holding information assets can anticipate continued close scrutiny.

APRA will “intensify its supervision of all entities not meeting [CPS 234],” Smith said, calling the recent attacks “a stark reminder for boards to ensure they can answer fundamental questions” including what data they hold; where it is; how they know it is safe; and whether they need to retain it at all.

“Cyber security is a highly significant risk area for all regulated entities,” she continued, “and we remind banks, insurers and superannuation funds to remain vigilant to protect their beneficiaries and the Australian community.”

https://ia.acs.org.au/content/ia/article/2022/data-breaches-could-damage-executive-pay-packets–apra.html?ref=newsletter&deliveryName=DM16245

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:29 pm, May 18, 2025
weather icon 16°C
L: 15° | H: 18°
few clouds
Humidity: 60 %
Pressure: 1020 mb
Wind: 2 mph NE
Wind Gust: 8 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 17%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:04 am
Sunset: 8:49 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 18°°C 0 mm 0% 7 mph 66 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 18°°C 0 mm 0% 11 mph 82 % 1022 mb 0 mm/h
Tue May 20 10:00 pm
weather icon
9° | 20°°C 0 mm 0% 8 mph 79 % 1022 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
12° | 18°°C 1 mm 100% 9 mph 93 % 1019 mb 0 mm/h
Thu May 22 10:00 pm
weather icon
9° | 17°°C 0 mm 0% 10 mph 63 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
16° | 17°°C 0 mm 0% 7 mph 56 % 1020 mb 0 mm/h
Today 7:00 pm
weather icon
16° | 17°°C 0 mm 0% 6 mph 54 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 6 mph 66 % 1020 mb 0 mm/h
Tomorrow 1:00 am
weather icon
12° | 12°°C 0 mm 0% 7 mph 69 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
12° | 12°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 51 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
18° | 18°°C 0 mm 0% 10 mph 45 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,096.51
0.91%
Ethereum(ETH)
€2,246.38
1.43%
Tether(USDT)
€0.90
0.00%
XRP(XRP)
€2.14
2.06%
Solana(SOL)
€153.63
2.63%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.200699
4.26%
Shiba Inu(SHIB)
€0.000013
4.05%
Pepe(PEPE)
€0.000012
7.67%
Peanut the Squirrel(PNUT)
€0.306376
14.91%
Scroll to Top