"We need MDR, and we need it before the audit."
The deadline is doing the scoping
Log source coverage, response authority and after-hours escalation all get settled by whoever replies fastest. Fix the outcome, then set the date.
Market view from CYBORIUM
Four parties now ask the same organisation to prove the same controls, and none of them accept the same evidence. This page sets out what we keep hearing on the evaluation side of the table, the rules we apply when we run one, and the categories where testing the market changes the answer.
The pattern repeats
None of these are wrong. Each one hides a decision that gets made by whoever answers first, unless the organisation makes it deliberately.
"We need MDR, and we need it before the audit."
Log source coverage, response authority and after-hours escalation all get settled by whoever replies fastest. Fix the outcome, then set the date.
"Our provider already does security."
Ask which controls the provider owns, which ones your team owns, and which ones nobody has written down. The exposure sits in the third group.
"The board wants a number."
Ask what evidence produced the number, who can reproduce it without the provider present, and how long it stays true.
"It came in cheaper than the others."
Ingest limits, retention, response scope and exit costs move total cost far more than the licence line does.
"We just need someone to run the tool."
Name the person who acts on a detection at 2am, and the authority they hold to isolate a host without waiting for you.
"Legal will handle the contract."
CPS 234 and CPS 230 duties stay with your organisation. The contract has to carry what the standard already places on you.
How CYBORIUM runs one
They are not clever. They are the ones that hold when the timeline compresses and the field starts answering back.
A tier name is not an outcome. Write what has to be true when the service is working, then ask the market to prove it.
Decide which artefact settles each requirement, a log sample, a runbook, a report, a named responder, while the field is still open.
Shared responsibility with no name against it is unowned responsibility. Split the model line by line and put initials on each line.
Data portability, log retention, tool ownership and transition support all cost more to negotiate after signature than before it.
Notification windows, access to evidence and audit rights belong in the schedule. A sales deck is not an obligation.
Ten categories, no vendor names
These are the categories organisations bring to us most often. In every one, what gets asked for at the start is rarely what settles it at the end.
Around the clock monitoring across the environment.
Which log sources are genuinely ingested, what the provider may do without ringing you, and how long you keep the data after you leave.
Multi-factor everywhere and a password vault.
Joiner, mover and leaver timing, how much standing admin access survives, and who approves break-glass at 3am.
Find our sensitive data.
Whether a finding gets a remediation owner, and whether the scan reaches the platforms your business actually stores data in.
Stop the phishing.
Time to act on a reported message, and whether quarantine release sits with the provider or with your service desk.
Scan the estate every month.
Who fixes what by when, and how an exception gets approved, recorded and reviewed rather than forgotten.
Check our cloud configuration.
Coverage across every subscription and account, including the ones a project spun up two years ago and never told anyone about.
A questionnaire we can send out.
What you do with an answer you do not accept, and whether the register lines up with CPS 230 material service providers.
Someone to call.
Contracted response time, whether prepaid hours expire unused, and who holds the forensic evidence when it is over.
Annual training for staff.
Whether reporting rates move, and whether a reported message reaches anyone with the authority to act on it.
A few days a month of a CISO.
Which decisions the role can make without you in the room, and what knowledge leaves the building at the end of the term.
No provider is named on this page. Names belong in an evaluation, next to the evidence that earned them a place.
Where the obligation sits
Two APRA standards shape most of the security procurement we see. They pull in different directions, and organisations often answer the wrong one.
CPS 234, information security
An APRA regulated entity stays responsible for the information security capability of any party that holds or processes its information, including a related party. The standard also sets reporting duties the entity carries itself: notify APRA no later than 72 hours after becoming aware of a material information security incident, and no later than 10 business days after becoming aware of a material control weakness it expects it cannot remediate in a timely manner.
That is why evidence access belongs in the contract. A provider cannot file those notifications for you, and you cannot file them from a status page.
Read CPS 234 at APRA ↗CPS 230, operational risk
CPS 230 has applied since 1 July 2025. It brought a register of material service providers, due back to APRA by 1 October 2025, and contract requirements that reach pre-existing agreements from the earlier of the next renewal or 1 July 2026. APRA made targeted amendments on 30 April 2026 that added limited exemptions from specific contractual requirements for certain categories of provider.
Security services often sit in both places at once: a CPS 234 control and a CPS 230 material arrangement. Sort out which one you are answering before you write the requirement.
CPS 230 due diligence guidance →If APRA does not regulate your organisation, the security schedule in your largest customer's contract usually does the same work with less notice.
The engagement boundary
This page helps you recognise the questions worth asking. A CYBORIUM evaluation maps them to your systems, obligations, provider evidence and commercial position, then produces something a board can challenge.
Managed detection and response, identity and privileged access, third party risk and incident response retainers come up most frequently. The category matters less than whether the requirement was written before the market saw it.
To you. CPS 234 holds the regulated entity responsible for the information security capability of parties that hold or process its information. The notification duties, 72 hours for a material incident and 10 business days for a material control weakness it cannot remediate in a timely manner, stay with the entity and cannot be delegated to a provider.
CPS 230 covers operational risk, material service providers, the register and the contract terms. Our CPS 230 guidance covers that path. This page covers what to test inside the security service itself, whichever standard brought you to market.
Not on a public page. Inside an engagement we test suitable providers against the same criteria and hand over a decision record showing why one was recommended and what the others offered.
No fee is paid to CYBORIUM by the client. The selected provider pays a capped fee and your organisation contracts directly with that provider.
Most of the cost we find in security procurement was decided in the first fortnight, by an organisation answering a question it had not written down yet. That part is fixable.