An analysis by cyber-security company Proofpoint has concluded that significant swathes of Australia’s financial sector may be wide open to even basic cyber attacks.
Pointing to a recent warning by the Reserve Bank of Australia (RBA) that future cyber threats are inevitable, Proofpoint ANZ area vice-president Crispin Kerr warned that such attacks have the potential to upset the broader balance of power within Australia’s financial sector.
“As highlighted by the RBA in its latest Financial Stability Report, risks from cyber attacks are on the rise and, given the potential network effects, they are also a growing risk for financial stability,” Mr Kerr said.
According to Proofpoint’s data, 44 per cent of APRA-registered, Australian-owned authorised deposit-taking institutions (ADIs) had no domain-based message authentication, reporting and conformance (DMARC) record in place.

DMARC is a common email validation protocol used to prevent domain names from being misused, as it authenticates the senders’ identity before delivering any messages.
Proofpoint concluded that this leaves the remaining 56 per cent particularly vulnerable to email fraud and domain impersonation threats.
Mr Kerr insisted that DMARC remains the only sure way to eliminate domain spoofing.
“Those financial services organisations that have the strictest level of DMARC implemented will achieve higher success rates in blocking malicious threats and stopping fraudsters from impersonating their brands, potentially saving these financial institutions millions of dollars in the process,” he predicted.
Of the Australian ADIs that Proofpoint said had a DMARC record, less than 10 per cent were fully compliant.
Mr Kerr said that this was concerning, as email continues to be the weapon of choice for financially minded cyber criminals.
“Threat actors typically conduct attacks via email by impersonating trusted brands such as banks using the correct logos, format, and wording, mimicking communications to customers, partners and suppliers that might be expected from that organisation,” he explained.
About the author