top of page

How Managed File Transfer Helps You Meet Australian Compliance Regimes

26 Aug 2026

If you work in risk, security, or IT in an Australian regulated industry, the last three years have rewritten your job description. Four regulatory regimes - two from APRA, one covering critical infrastructure, and a substantially toughened Privacy Act - now converge on the same uncomfortable question:


Can you prove you control your data every time it moves?

Not where it sits. Where it moves - between systems, between business units, and especially to and from third parties. File #000000transfer is where sensitive data leaves your perimeter, and it's exactly where regulators, boards, and attackers are now focusing their attention.


Here's a plain language look at what each regime asks of you, and how a managed file transfer (MFT) platform like Fortra's GoAnywhere MFT helps you meet those obligations in practice.


CPS 234: Information security with board accountability

What it is: APRA's Prudential Standard CPS 234 applies to banks, insurers, and superannuation trustees. It requires regulated entities to maintain information security capability commensurate with their threats, implement controls to protect information assets (including those managed by third parties), systematically test those controls, and notify APRA of material information security incidents within 72 hours. Critically, accountability sits with the board - "we outsourced it" is not a defense.


How GoAnywhere MFT helps: CPS 234 is fundamentally about demonstrable controls over information assets. GoAnywhere centralises what is often the least-controlled activity in an enterprise - ad hoc file movement - into a single governed platform with AES-256 encryption at rest, secure protocols (SFTP, FTPS, HTTPS, AS2) in transit, and a FIPS 140-2 validated cryptographic module. Role-based administration, granular folder-level permissions, and integration with Active Directory, SAML SSO, and multi-factor authentication mean access to sensitive data maps to defined roles rather than shared credentials. And when APRA or your auditors ask for evidence, complete audit trails of every user event and file movement - exportable to your SIEM via syslog - turn "we believe our controls work" into "here is the record."


CPS 230: Operational resilience and third-party risk

What it is: CPS 230, in force since 1 July 2025, is APRA's operational risk management standard. It requires regulated entities to identify their critical operations, set tolerance levels for disruption, and - significantly - manage risks arising from service providers with the same rigour as internal operations. If a material service provider fails, APRA expects you to have seen it coming and planned for it.


How GoAnywhere MFT helps: Data exchange with counterparties, bureaus, administrators, and processors is one of the most common dependencies underpinning critical operations - and one of the least visible. GoAnywhere gives you a single point of visibility and control over every third-party data flow: automated workflows replace fragile scripts and manual FTP, transfer monitoring and alerting surface failures before they become disruptions, and detailed reporting shows exactly which counterparties exchange what data, when, and how. That inventory of data flows is precisely what CPS 230's service-provider management and business-continuity requirements assume you have.


The SOCI Act and CIRMP: Critical infrastructure obligations

What it is: The Security of Critical Infrastructure Act (SOCI Act) applies to owners and operators of critical infrastructure assets across eleven sectors - energy, water, healthcare, transport, communications, financial services, data storage, and more. Its Critical Infrastructure Risk Management Program (CIRMP) rules require responsible entities to establish and maintain a documented program addressing cyber and information security hazards (benchmarked against a recognised framework such as the Essential Eight, ISO 27001, or NIST CSF), report cyber incidents to the Australian Cyber Security Centre within tight timeframes, and have the board attest annually to the program.


Where GoAnywhere helps: A CIRMP has to show how you mitigate cyber hazards to systems that matter - and file transfer infrastructure is squarely in scope, as the industry's recent history of attacks on transfer systems has demonstrated. GoAnywhere supports the control frameworks CIRMPs are benchmarked against: network segmentation via its DMZ gateway (no inbound ports or credentials stored in the DMZ), IP allow-listing and automated brute-force blocking, restriction of administrative privileges through role-based access, and multi-factor authentication. Its centralised logging and reporting also give you the forensic record you need to meet mandatory incident-reporting timeframes with facts rather than guesses.


The reformed Privacy Act: Higher stakes for personal information

What it is: Australia's Privacy Act has been substantially strengthened. Maximum penalties for serious interferences with privacy now reach $50 million or more for companies. The Privacy and Other Legislation Amendment Act 2024 introduced a statutory tort for serious invasions of privacy (live since June 2025) - meaning individuals can now sue directly - alongside new OAIC enforcement powers and criminal penalties for doxxing. Further reform tranches are expected. Underpinning it all, APP 11 requires organisations to take reasonable steps to protect personal information, and the Notifiable Data Breaches scheme requires assessment and notification of eligible breaches.


Where GoAnywhere helps: "Reasonable steps" is a moving standard, and regulators have made clear that sending personal information by unencrypted email, consumer file-sharing tools, or legacy FTP no longer qualifies. GoAnywhere replaces those habits with encrypted, policy-controlled transfer and secure ad hoc file sharing for the human-to-human exchanges that policy documents always miss. Automatic retention and secure-deletion workflows help you avoid holding personal information longer than needed - the single biggest amplifier of breach impact. And if the worst happens, granular audit trails let you determine quickly whose data was affected and what was actually taken, which is the difference between a precise, defensible notification and a worst-case public disclosure.


The honest conversation: platform security 

No serious discussion of file transfer in 2026 should ignore that MFT platforms across the industry - GoAnywhere included - have been targeted by sophisticated threat actors in recent years. That's exactly why deployment discipline matters: current patched versions, the DMZ gateway architecture, admin interfaces off the public internet, and MFA enforced. A well-deployed, well-maintained MFT platform with full audit visibility remains categorically safer than the alternative most organisations are actually running - scattered scripts, open FTP, and personal file-sharing accounts that no one monitors and no one patches. 


The bottom line

CPS 234, CPS 230, the SOCI CIRMP rules, and the reformed Privacy Act differ in scope and language, but they converge on the same expectations: know where your sensitive data goes, control who can move it, encrypt it on the way, keep evidence, and be able to answer for it - to APRA, to the ACSC, to the OAIC, and to your board. 

No software product makes you compliant on its own - compliance is a program, not a purchase. But a centralised MFT platform turns the hardest part of that program - governing data in motion - from hundreds of invisible, unmanaged flows into one controlled, auditable system.


Here to help

At Generic Systems Australia we have many years of experience helping Australian organisations install and configure the world’s leading MFT.  We’re standing by here in your time zone, ready to help you do the same. 


If you'd like to see how your current file transfer landscape stacks up against these four regimes, I'm happy to walk through it. The gap analysis is usually eye-opening - and it's a far better time to look now than after an incident or an audit finding.



This article is general information, not legal or compliance advice. Always have an appropriately-qualified subject matter expert assess your obligations against your own regulatory context.



bottom of page