On 18 June 2025, the Australian Prudential Regulation Authority (APRA) published a speech given at the AFIA Risk Summit by its Executive Director of Cross-industry risk, Chris Gower, who draws parallels between the Perfect Storm of 1991, and the operational resilience headwinds that are brewing on the horizon for Australian financial services entities. The speech is entitled Preparing for the long haul: operational resilience in a shifting geopolitical environment.
Headwinds
In his speech Mr Gower highlights three converging risks in the operating environment:
- Technology – continues to become deeply integrated into every aspect of the financial system and, with that, heightened vulnerability to cyber-attacks and other operational disruption.
- Reliance on third parties to provide critical operations and technology – continues to increase and, with this reliance, comes exposure to disruption from entities outside the financial system, including overseas-based service providers.
- Shifts in the geopolitical environment – are likely to amplify risks to the financial system, including risks posed by cyber-attacks and third-party service providers, as well as risks from other sources, such as personnel risks associated with bad actors.
Charting a course
Steering the ship
For those business leaders steering their ship through this very uncertain outlook Mr Gower makes the following points:
- Via the recent engagement on CPS 230, APRA has seen those entities that adopt a “resilience” rather than a “compliance” mindset rise to the challenge far more effectively.
- When making investment decisions on digital transformations there are a number of questions entities need to ask from a risk management perspective. These include – Are appropriate cyber security controls in place to deal with AI-enabled threats? Has the entity considered AI risks introduced by third parties? Is data protected from misuse or theft, and do the right people have access to critical information and systems?
- APRA routinely undertakes “pulse checks” of the risk culture of entities, and its insights consistently reinforce the importance of training and awareness programs, creating a “speak-up” culture, and breaking down silos between teams to build end-to-end resilience.
- Entities should take steps to understand how shifts in the geopolitical environment may impact their risk profile. Under CPS 230, entities are expected to conduct scenario planning for a range of events, including geopolitical shocks, cyber incidents, and natural disasters.
- Operational disruptions will happen, so having effective and tested incident response plans is important.