ARC NEXUS
Independent Cyber Governance
Board Governance Insights

Assurance is not the same as coverage

What APRA v Bendigo and Adelaide Bank means for how Australian Boards test the assurance they rely on.

By Ashwin Ram, Founder and Managing Director, ARC Nexus
Published 11 August 2026 · Last reviewed 11 August 2026 · 5 min read

On 10 August 2026, APRA commenced civil penalty proceedings in the Federal Court against Bendigo and Adelaide Bank over a 2023 cyber attack on its Alliance Bank business.

The bank has admitted two contraventions of the Banking Act under the former Banking Executive Accountability Regime. The parties have proposed a penalty of $8 million. APRA is also seeking declarations of contravention. The Court has not yet determined the matter, and it is for the Court to decide whether the declarations and the penalty are appropriate.

The number will attract attention. The governance record deserves more.

In June 2020, a security test found weaknesses in how customers logged in to Alliance Bank. Passwords could be too simple. The login page also gave away, through the wording of its error messages, whether a customer number was real. Together those two things make it far easier for an attacker to guess their way in.

The findings were rated moderate and recorded in the bank's vulnerability tracking system. They were not assessed against the bank's own escalation process. They did not reach the executive who owned the risk. They did not reach senior management or the Board. And they were not fixed until March 2023.

A control was added, but not everywhere it was needed

In October 2022, attackers ran automated login attacks against two Alliance Bank platforms, trying to exploit the same weaknesses the 2020 test had already identified. No accounts were accessed. Thousands of customers were locked out. The attacks were detected after those customers reported that they could not get into their internet banking. The bank monitored accounts for suspicious transactions. It did not monitor for suspicious login activity.

The bank responded. It put a web application firewall and a CAPTCHA in place for Alliance Bank's online banking. The firewall is designed to filter potentially malicious web traffic before it reaches the application. The CAPTCHA is the familiar "prove you are human" test, designed to stop exactly the kind of automated login attempts the bank had just seen.

Both were implemented for online banking. The agreed facts record that the CAPTCHA was inadvertently not implemented for mobile banking, and that adequate anti-automation protection was still absent there when March 2023 arrived.

In March 2023, an attacker ran another automated attack. At that moment, 1,598 Service One customer accounts were protected by the password 123456, and many others by passwords almost as simple. The attacker reached about 257 accounts and made 286 transactions totalling about $490,000. The bank became aware roughly four days in, when a customer reported fraudulent transactions on their account.

The agreed facts do not say the missing CAPTCHA caused the attacker to use mobile banking. They do record that it had not been implemented there, and that automated traffic to mobile banking increased exponentially during the attack.

For a Board, the lesson is not to understand how a CAPTCHA works. It is to ask a much simpler question about any material control change: did it cover the whole risk?

The Board question
When the Board relies on cyber assurance, can it see what was tested, what was not, what was found, and whether the gaps were closed?

That is a different question from asking whether testing happened.

Testing happened. Coverage was still incomplete.

There was no shortage of governance machinery. The bank had an information security policy, an operational risk framework with an escalation matrix, a password standard approved by a technology committee, a dedicated framework for testing controls under the prudential information security standard, a three lines of defence model, and a risk register with dashboards at business unit, divisional and group level.

There was also independent assurance. The bank received annual independent reports over the hosting infrastructure, a separate report over the software provider, and in 2022 it commissioned a further control review of the banking platform itself.

None of those three assessed the customer login controls at issue in the March 2023 attack.

The bank had also, by December 2021, formally classified this platform as a critical and sensitive technology asset. It admits that between January 2021 and March 2023 it performed no testing of the login controls on it.

This is the distinction directors should take away. A Board can know that assurance was performed and still not know whether the risk that matters was actually inside its scope. A report can be valid for what it tested and tell the Board little about what it did not.

Findings have to go somewhere

After the March 2023 attack, the bank commissioned further testing of the same platform. It found the same vulnerabilities the 2020 test had found.

The bank's own internal review, conducted later that year, concluded that the 2020 findings should have been identified and reported as significant risks and escalated under its risk framework. It went further, and found it was possible the attack could have been avoided had those risks been properly assessed, escalated and managed, with critical thinking applied across all three lines of defence.

Finding a weakness is not the same as governing one. A finding needs an owner, a decision, escalation where the risk warrants it, and evidence that it was closed, retested or formally accepted by someone with the authority to accept it.

Accountability had a gap too

Running alongside the assurance failure was a second one.

In August 2022, responsibility for Alliance Bank IT operations was expressly excluded from the Chief Transformation Officer's accountability statement. An internal document identified a proposed recipient for the responsibility and recorded that roles had been confirmed.

The responsibility was never written into anyone else's accountability statement. From 29 August 2022 to 30 August 2023, no accountability statement of any of the bank's accountable persons covered IT operations for Alliance Bank. That is the second contravention the bank has admitted.

The Banking Executive Accountability Regime has since been replaced by the Financial Accountability Regime, which applies a strengthened accountability framework to APRA-regulated entities, their directors and senior executives.

The regime has changed. The question has not: when responsibility moves, what proves that it landed?

This is not a story of no Board attention

The record needs to be read carefully in both directions.

Concerns about the way some technology was managed outside the central technology team were raised at committee and Board level meetings between 2020 and 2022. Board cyber reporting in November 2022 identified recent automated login attacks affecting Alliance Bank, including the platform that would be successfully attacked four months later. A cyber security update to the Board on 29 November 2022 recorded that the bank was at a critical point of needing further investment in cyber resourcing and capability.

No substantive review of those October attacks, or of the login controls involved, followed.

After the March 2023 attack, the Board maintained close oversight of the response, with regular briefings to the Managing Director, the Board Chair and the Chair of the Board Risk Committee, and it reviewed the independent post-incident review. All 48 actions arising from that review were implemented by May 2024. APRA has said the conduct was historical, that it was satisfactorily remediated, and that it does not currently have concerns about the adequacy of the bank's information security controls.

That combination makes the case more instructive, not less. Board attention existed, and the bank has still admitted that its information security governance and risk management were inadequate.

The question is therefore not whether cyber appears on the agenda. It is whether what reaches the Board lets directors understand the limits of what they are being asked to rely on.

The questions worth asking at the next meeting

Not simply "have we tested this?" That can be answered with a schedule of activity.

Questions worth asking
  1. 1.Which of our most important systems and cyber risks have actually been tested, and which have not?
  2. 2.When we receive an assurance report, can we see what was outside its scope?
  3. 3.What happens when testing finds a significant weakness, and what evidence shows it was closed?
  4. 4.When we change a control, how do we know the change was applied everywhere it was needed?
  5. 5.If accountability for a material system moves from one executive to another, what confirms the transfer actually happened?

If those answers cannot be supported by evidence, the Board cannot know whether its assurance coverage is complete.

That is the gap to close before an incident, a regulator, or other external scrutiny tests it.

Assurance is not the same as coverage.

Not assumed. Evidenced.

The proceeding against Bendigo and Adelaide Bank has not been determined. The facts and admissions in the Statement of Agreed Facts and Admissions were agreed solely for the purposes of that proceeding and do not constitute admissions outside it. The proposed $8 million penalty and the declarations sought remain subject to determination by the Federal Court. APRA has stated that the conduct and control weaknesses were historical and satisfactorily remediated, and that it does not currently have concerns regarding the adequacy of the bank's information security controls. This is governance commentary, not legal advice.

Ashwin Ram, Founder and Managing Director of ARC Nexus

Ashwin Ram (GAICD, CISM) is the Founder and Managing Director of ARC Nexus, an independent cyber governance advisory practice for Australian Boards, Audit and Risk Committees and senior leaders. He combines formal governance training with more than fifteen years in cybersecurity.

Sources

Key regulatory and court-filed sources for this article are set out below.

From article to assessment

Testing this on your own Board

This article reflects one of the questions an ARC Nexus review is built to answer: whether the Board can see the scope, limits and outcomes of the cyber assurance it relies on. A confidential briefing determines whether a Board Cyber Governance Review is warranted, and how it would be scoped.

Request a confidential Board briefing