Australia is unique in a lot of ways, including its approach to cyber resilience. In this episode, Robert Veres, CISO at Colonial First State and Co-Chair of the Australian Superannuation Cybersecurity Forum, outlines how one of the world's largest retirement savings systems is adapting to escalating cyber threats, highly prescriptive resilience regulations, and growing concentration risk across critical suppliers. From the limits of traditional vendor attestations to the challenge of managing third- and fourth-party dependencies, he shares practical lessons and a candid look at the impact of collaboration in the financial ecosystem.
Elizabeth Heathfield: Welcome to FS-ISAC’s podcast, FinCyber Today. I'm Elizabeth Heathfield. In a recent conversation with Robert Veres, CISO and Co-Chair of the Australian Superannuation Cybersecurity Forum, we discussed Australia's superannuation system and why resilience must be integrated into supplier ecosystems from the very start, blending human insight, regulatory innovation, and shared intelligence.
Heathfield: Thank you so much, Robert, for joining us all the way from Australia, and thank you for taking the time. I know the time difference is challenging for us to find time, so I'm glad we did. So, let's talk about Australia's cyber risk landscape, specifically with the superannuation industry. But first, can you just start off explaining what that is to those who are outside Australia and may not have heard that term before?
Robert Veres, Chief Information Security Officer at Colonial First State and Co-Chair of the Australian Superannuation Cybersecurity Forum: Yeah sure. I'll skip you through some of the uniquenesses. To me, it's also a bit unique too, having just returned to Australia after 20-odd years overseas. And the industry here is indeed quite unique. I would probably bring a little bit of comparison to the 401(k) savings approach that is in the US. In Australia, there's something called the superannuation guarantee, and that's 12% … salary that legally needs to be contributed to this retirement fund. There's a very high degree of savings, about three trillion US dollars. And that represents, if you compare that to the Australian Stock Exchange, about 1,570 companies, it's quite significant both locally and internationally.
And what that really gives Australia is a bit of a false sense of security coupled with the geographic aspect of Australia. We call ourselves, you know, living down under. I understand there's quite a few billionaires that have decided to set up underground bunkers in New Zealand just across the pond. So, it seemed a bit of a geographically remote environment. And that gives a false sense of security, given that the digital attacks we have know no borders. And we are in a pretty, I guess, contested area of the world – a lot of hostilities in this geography.
And I'll say that, in light of the regulatory landscape, it’s quite unique as well. Our financial regulator, APRA [Australian Prudential Regulation Authority], has put out two key regulatory frameworks. One called CPS 234, which is more cyber controls. And one that we'll probably discuss a little bit more, which is 230, which is more about risk management and resilience. That is very key to the industry. And the 230 is one of the ones that is more recently developed.
In terms of the actual cyber landscape, I'd say it's pretty consistent with the rest of the world. Australia has the Australian Signals Directorate, which I believe in function is similar to the NSA [US National Security Agency]. And within that, there's a department that is more focused on cybersecurity known as the ACSC [Australian Cyber Security Centre] and which again, is very similar to – in both name and function – to the UK’s NCSC. They put out an annual report which really expresses a lot of similarity to what's happening in the rest of the world … I think it's over 80,000 incidents called into the ACSC, which represents one event almost every six minutes. Average losses, I think, have gone up by over 50%, but particularly in the larger organizations, that's closer to 220%. So, there's some significant movements over the period of time. They did call out a lot of points regarding smaller companies, legacy technology, and obviously the threats from state-sponsored actors. And going to my previous point, that we are living in a geography that has quite a lot of activity with that regard.
Heathfield: OK, so there was a lot there to unpack. Let's start with, you mentioned the two pieces of regulation that are unique and different. And given that the regulatory landscape around the world is widely varying, I'd love to hear a little bit more about what does the regulatory landscape look like in Australia. And are there any principles that you think might be more widely applicable.
Veres: Yeah, CPS 230 with regards to resilience is one that is a bit more unique to Australia that is highly prescriptive. One piece of regulation that came, I believe slightly before CPS 230 was DORA in the EU. That had similar intentions as well. Although the Australian regulation, as I think a lot of Australian regulation, it's far more prescriptive and it's a bit broader than the control stipulated in DORA.
But I do believe that the main underpinning theme is that there is an acceptance that we've moved well beyond an era of prevention from the late 90s and early 2000s into an era of recognizing the breaches do happen. You know, it's not a matter of if, but when. And then to be prepared for that eventuality and to show resiliency through the course, the controls that you have, and your capacity to react and respond. And more importantly, and I believe it's in DORA as well, the expectation to report these events. Now ASD also has an expectation [of reporting cyber ransoms]. And hence the focus is shifting towards a transparency of activity that has occurred, as opposed to the expectation that you have all the controls in place such that nothing will ever go wrong.
Heathfield: What are the pros and cons of this level of prescriptive regulation for the industry and how are you seeing that play out in terms of priorities, risk management, all of the stuff that the actual teams have to deal with?
Veres: One of the interesting side effects of this is an expectation to have a better understanding of the control performance inside our third and fourth parties. And simply to understand our third and fourth parties.
Heathfield: Supply chain risk and supply chain risk management is definitely – across FS-ISAC’s community globally – probably the number one issue. Probably AI might be the next, but supply chain is massive. Unsurprising that it’s also an issue in Australia. I'd love to hear if you think if there's any interesting ways beyond, as you mentioned, concentration mapping to deal with it. How are you guys dealing with it? Because even though it's a large dollar volume, it's a pretty small community, right? I would imagine that everybody knows each other, you know who the suppliers are. So I would love to hear how, as a national ecosystem, you are trying to move forward to deal with this.
Veres: Well, it does take a village, right? I mean, I think it was Nassim Taleb that wrote The Black Swan that characterized the more complex the ecosystem is, the more fragile it is. And what we really need to understand is how to maintain resilience within this fragility. So, it really takes a village to work together. And I think the number one out of this is to really share. Share both in terms of best practice, but also intelligence. And we find that whether it's the events of major service outages that we experienced last year or even towards the tail end of last year and in fact the year before, I'm not going to call out the particular cases – it's not about naming and shaming, but it does happen. What we've found is when the community comes together to work together, it's just amazing how effective the outcomes actually are, to understand what's happening in real time, but also leading up to the event, and even post the event, to understand how to improve.
And, look we all benefit from this, whether we're large organizations and have the resources, but also the smaller organizations that are in these communities, as well, to better appreciate the best practices that we've come across. The work that we do with the regulators and the governing general, especially with the ASD, is also really crucial. There are limited use regulations that came out about a year ago in Australia that limit, for example, the ASDs from sharing information on to regulators, for example, such that if we share breach information, you must be compartmentalized within the ASD.
And this is trying to signal that it's safe to share – ‘It will be used for this reason, this reason only.’ And we're finding that partnership and collaboration with government as being highly effective as well and we really encourage that. And as I mentioned, the work that I do with … advisory boards of other industry groups, it's really to bring everyone together to recognize that in this part of the industry, even if we're competitors on the business side, everyone plays a team sport when it comes to cyber. And the real need to lean on everyone in times of crisis, especially.
Heathfield: And are you seeing that extend to the supplier ecosystem? Are you working as closely with, for example, your critical technology providers as you are across the financial sector? Or is that still an area that we as a global community need to make some more progress in?
Veres: Right, that's a good question. I think it'd be case-by-case. Some suppliers are quite open, and it really depends on the nature of the supplier as well. I mean, you get a large supplier that you'd have very small business with that you know will support you accordingly and rightly so, whereas you can get some small suppliers with disproportionate commercial engagement that you'd work quite closely with. We do find, however, across the board, there is general willingness. But at the same time, a recognition that if certain transparency, I wouldn't say transparency, if a certain type of engagement was extended across the board, they'd just be inundated with all sorts of questions. So that sort of standardized approach, which again goes back to the point I tried to make before in working with the Financial Services Council here, is to find some sort of standardized way that makes it easy for these suppliers and third parties to interact in a way that's expected while at the same time making it easy for us to extract the right information.
I also want to say that there's been a recognition in the industry by a lot of my peers of a sense of growing frustration. A lot of suppliers are making key security features, especially the software vendors, an optional paid-for add-on, [such as] MFA or monitoring or logging. These are almost essential to understanding the landscape of what's going on and are seen as, again, optional extras … MFA may have been optional 10 or 20 years ago, but now it's as essential as an airbag is in a car. So, we really need to shift the industry as well, how it supports the final customers, to understand that some cyber capabilities just need to be embedded in the fabric of the service as a mandatory item.
Heathfield: Some financial regulators are now going and doing direct regulation on critical third parties, like in the UK. But it's definitely a challenge, and I think you're right to raise it that way. I want to touch on this because you mentioned the geopolitical dimensions, because of where Australia is in the world. And I wanted to hear your thoughts on does – and if so how – your actual location impact this whole consideration of cyber resilience and third-party risk management?
Veres: Yeah, well, geographically, as we talked earlier, it's isolated, which gives that false sense and a very inappropriate narrative that we're safe because we're out on an island in the middle of nowhere down under. But because of our heavy reliance on our service industry and our financial sector – and that being very much exposed digitally to the rest of the world – and being a very strong target to various threat actors, it makes us a prime target.
We're digitally quite mature in terms of our consumption of digital services. Certainly not as mature as some parts of the world, like Estonia, etc., but certainly quite down the path there. And as a result, we need to be quite aware.
So the financial sector and certainly the banks have become very, very prominent in this, to doing public notifications, public engagement. The Australian Signals Directorate has done a lot of public work as well. They've got a program now called “Act Now. Stay Secure,” focusing on key topics like passwords, patching, and MFA. You know, simple things that, for the industry, are considered 101, but for the general population, it's something that is quite a pressing topic.
We're finding, again, if I go back to the super[annuation] industry, we need to support people from the time they enter the workforce to the time they retire and beyond, cradle to grave. This is a long period of time for which we need to support people. So, it gives us a very wide cross-section of society. And we do find that … some members in our community would be troubled to use a mobile phone, period. And therefore trying to work out how to support those elements of our community that struggle and how to make sure that we have a cyber environment that accommodates every type of individual is certainly a significant challenge, but one that we certainly have employed a lot of very unique technology and certainly I believe we've been quite effective in our fight to date. There's certainly a lot that needs to be done.
Heathfield: On the one hand, Australia is isolated down under, but on the other hand, in the larger region, there's a lot of geopolitical complexity. Does there need to be extra awareness and extra vigilance – especially around third parties – but just in general around managing resilience because the threat actors nearby are so sophisticated?
Veres: I'm not sure whether geographically there's going to be anything unique to Australia. Like I said … they're not going to respect geographies as such. It's more the services we consume and effectively will get involved in, and because Australia is very active in the intelligence sharing in terms of Five Eyes. We are part of a number of security pacts that obviously we get affected in, as a reaction to what we're getting involved in, that would put us in harm's way in many different scenarios in just the last many months alone. Australia's mineral sector is a key strategic interest to many countries around the world, as well. And hence, I think that question would be much more interestingly, probably, responded to by our energy and mining sector especially. But we certainly are aware. And we certainly do not kid ourselves at the formidable tasks that we have to protect our borders digitally.
Heathfield: Well, it's been a really interesting conversation. Is there anything else, any other points that you wanted to get across in terms of key takeaways?
Veres: I tried to ponder on this when we set up the original interview, how do you bring it all together? And I tried to write down a phrase that would bring it all together. And if you don't mind, I sort of landed on this: Resilience must be engineered into the supplier ecosystem from the start, governed by humans, augmented by technology, validated continuously, and reinforced through shared intelligence. I really reckon that for all the ideas that we shared today, that sums up in one sentence both the challenge that’s ahead of us and the expectations that are placed on us to make us effective.
And I'll underline the fact that Australia is unique in the sense that it does have a lot of wealth per capita. It is very digitally connected. It does have significant threats placed upon it, but at the same time, it does have a lot of self-awareness, a great community spirit. I think there's an incredible peer group in Australia that I've not experienced in many, if any, other parts of the world because it is such a small country at 27-odd million people. And yet we're battling some significant forces … with much deeper pockets than we have. So I think we're doing a great job, but it does rely on everyone stepping up and working together.
And for that, we're very grateful for the industry bodies that we work with, whether it's the Financial Services Council, or whether it's FS-ISAC. And we just really hope that we can continue working together and not only within these communities, but also having these communities work together as well for our common cause. And thank you very much for all the efforts that's gone into that work as well.
FinCyber Today is a podcast from FS-ISAC that covers the latest developments in cybersecurity, contemporary risks, financial sector resilience and threat intelligence.
Our host Elizabeth Heathfield leads wide-ranging discussions with cybersecurity leaders and experts around the world who bring practical ideas on how to confront cyber challenges in the financial sector, improve incident response protocols, and build operational resilience.
Amid the clutter and noise, FS-ISAC Insights is your go-to destination for clarity and perspectives on the future of finance, data, and cybersecurity from C-level executives worldwide.
© 2026 FS-ISAC, Inc. All rights reserved.
Listen on
Robert Veres is the Chief Information Security Officer at Colonial First State and one of Australia’s leading voices on cyber resilience, AI governance and emerging technology risk. Over a career spanning nearly three...
Read Moredecades, Robert has led cybersecurity transformations across Europe, Asia and the United States, working with some of the world’s largest financial services organisations. His experience stretches from security operations and incident response through to board advisory, executive leadership and large-scale organisational change. At Colonial First State, Robert is leading a significant cyber transformation, building capabilities that bring together cybersecurity, technology risk, data governance and AI governance to help the organisation innovate with confidence. Prior to CFS, he developed and executed a global cyber strategy for ORIX in Japan, creating a sustainable security framework across 140 businesses and 35,000 employees worldwide. Earlier, in Paris, he played a key role in shaping AXA’s global cyber transformation program. Beyond his executive role, Robert is an active contributor to the broader financial services industry. He serves as Co-Chair of the Financial Services Council’s Superannuation Cyber Committee and sits on the FS-ISAC APAC Strategy Committee, helping financial institutions navigate an increasingly complex threat landscape. Known for translating complex cyber and AI risks into practical business decisions, Robert is passionate about helping leaders understand how technology, resilience and trust can become competitive advantages in the digital age.
Elizabeth is a storyteller at the intersection of technology and money. Layer in geopolitics and the criminal underworld and you get today's issues in cybersecurity for the global financial system. Crypto. Web...
Read More3.0. Quantum. AI. Ransomware. Privacy. Regulation. Zero-days. Supply chain attacks. Developing new and diverse talent. How to protect the future of money. These are the topics Elizabeth asks top executives and experts in the field about on FinCyber Today.
© Copyright 1999 - 2026 FS-ISAC, Inc. All Rights Reserved.