“There’s a cyber attack in Australia every six minutes.”
That’s not a throwaway line – it’s a wake-up call from the Prime Minister. And the recent coordinated attacks on Australia’s largest superannuation funds show exactly why we should be paying attention.
AustralianSuper, REST, Hostplus, ART and Insignia all confirmed breaches in late March. The tactic was simple: stolen credentials used to access member accounts. The outcome? Four victims had $500,000 withdrawn. REST had to shut down its online portal. Member confidence was shaken overnight.
While the funds acted swiftly – and in most cases, successfully – to contain the damage, this event wasn’t a one-off. It’s the latest in a string of cyber incidents affecting critical sectors in Australia. And if you’re in finance, you should assume your organisation is already a target.
This isn’t a scare campaign. It’s reality.
Let’s be clear: the fact that the breaches didn’t cause more damage is not proof that these funds were invincible. It’s proof that well-executed incident response protocols can limit the fallout.
REST’s chief executive said it best – their immediate execution of response procedures meant fewer than 1% of members were affected. That’s not luck. That’s governance. That’s planning. That’s the kind of capability every financial organisation should expect from their managed service provider.
Because here’s the truth: in this threat landscape, your MSP isn’t just a support vendor. They are part of your front line. And if they’re not evolving their approach to match the risk – then you’ve already fallen behind.
Finance isn’t like other industries
The expectations for security in finance are higher – and rightly so. Institutions are expected to manage not just data, but trust. That means aligning with standards like CPS 234 and the incoming CPS 230. It means demonstrating governance, incident response maturity, and business continuity planning that’s boardroom-ready.
So ask yourself: does your MSP understand APRA regulations? Do they speak the language of risk assessments, security frameworks, and board-level accountability? Can they support breach notifications to APRA or ASIC within the mandated 72-hour window?
If they’re still catching up on this, it’s time to reconsider who you’re relying on.
What a finance-ready MSP should deliver
Not all MSPs are created equal. In today’s climate, your partner should be doing more than managing patching cycles or resetting passwords. You need a partner who is actively reducing your risk exposure and preparing your business for a cyber event.
At minimum, your MSP should be offering:
- Advanced cybersecurity policies and architecture tailored to financial compliance standards
- Expert governance knowledge and a tested, rapid incident response framework
- Disaster recovery planning and execution, ensuring business continuity in the event of a breach
These are not “add-ons.” They’re core requirements.
Disaster recovery is not a fallback – it’s a foundation
When systems go down, whether from ransomware, internal error, or infrastructure failure, what matters most is how fast you can bounce back.
That’s why VITG is soon launching a dedicated Disaster Recovery service for finance – a solution that provides real-time data backup, secure failover environments, and seamless service restoration. It’s designed with CPS 230 in mind, to help clients not only recover from incidents but demonstrate resilience to regulators and boards alike.
We don’t believe in theoretical preparedness. We believe in showing clients what recovery looks like, testing it regularly, and standing up systems when it counts.
The question we always ask
Christian Pacheco, VITG’s Founder & CEO, puts it simply:
“We’ve seen this in Europe and the US, and now global cyber criminals are targeting your pension in Australia. It won’t be just the big names either. For Australian financial funds of all sizes, it’s a matter of if, not when they will be targeted. My advice is simple – check if your MSP has the appropriate finance-specific security governance expertise and capability to implement a proactive security posture. If they don’t, or they’re playing catch-up, find an MSP that does – before it’s too late.”
This is the moment for leadership teams to ask hard questions. Because the threat has evolved. The regulations have evolved. Has your MSP?
Book a readiness check with VITG’s cyber governance team and find out if you’re truly prepared.



