This is not just another cyber incident headline. APRA’s release points to a clear message for boards and executives: when a cyber event lands, accountability frameworks are tested as much as technical controls.
If the organisation cannot show who owned what, when decisions were made, and how the issue was escalated, the problem can quickly move from operational incident to prudential breach.
On 11 August 2026, APRA published Bendigo and Adelaide Bank admits to breaching its BEAR obligations in relation to cyber incident. Although the incident was a number of years ago and APRA outlines there are no concerns today. The release outlines this is about a breach of BEAR obligations in the context of a cyber incident.
The practical audience is broader than one bank: boards, accountable persons, risk leaders, cyber teams and governance teams across APRA-regulated entities should treat this as a signal on evidence, oversight and accountability.
The Board-Level Take
The immediate lesson is that cyber readiness is no longer judged only by prevention and response capability.
Regulators also care about whether the accountability model works under pressure. That means clear ownership, defensible escalation, and documentary evidence that the board and senior management were not just informed, but actively governing the response.
For many organisations, the risk is not a lack of policy. It is the gap between policy and proof. When APRA reviews a material incident, it will expect a coherent story across incident management, accountability mapping, board reporting and post-incident remediation.
What APRA Is Really Signalling
Cyber incidents are accountability events, not just operational disruptions
The significance of this release is that a cyber incident can expose weaknesses in the way accountability obligations are assigned and discharged. That matters because boards often assume the cyber team owns the incident, when in practice accountability usually spans technology, operations, risk, legal, communications and senior executives.
Boards and executives should ask whether their incident frameworks make those accountabilities explicit enough to stand up in a prudential review. If the answer is “mostly”, that is not enough.
Evidence matters as much as intent
APRA scrutiny typically turns on what can be demonstrated. It is one thing to say a committee was briefed or a senior executive was involved; it is another to show the contemporaneous papers, decision logs, escalation records and remediation tracking that support that claim.
Risk teams should check whether incident records are board-ready by design, not reconstructed after the event.
BEAR compliance needs to survive real-world stress
This release suggests a practical test of whether accountability arrangements hold up during a fast-moving cyber event. If responsibilities blur when an incident unfolds, the organisation may have a control design problem, not just a response problem.
That points to a need for stress-testing accountability mappings, incident playbooks and governance handoffs against realistic cyber scenarios.
Questions Risk and Governance Teams Should Ask Now
- Can we show, in one place, how a material cyber incident maps to accountability obligations and senior owner responsibilities?
- Would our incident logs, board papers and escalation records clearly demonstrate who made key decisions and when?
- Do we have a clean handoff between cyber response, risk oversight, legal review and board reporting?
- Have we tested whether our accountability framework still works when a cyber event unfolds quickly and under pressure?
- Are lessons learned from previous incidents being converted into control improvements and accountability updates, or just noted and closed?
- If APRA asked for evidence tomorrow, could we produce a coherent chronology of the incident, governance response and remediation?
Keeping the Board Ahead of the Curve
The Innovation of Risk focuses on empowering business leaders to deliver for the people the serve through risk maturity existing across the whole organisation, not just in senior leaders or the risk team.
If your board or risk team wants a structured way to assess maturity, identify evidence gaps and stress-test governance arrangements before they are tested by an incident, this is the place to start.

