
In the weeks following the Medibank incident in late 2022, every CRO and CISO in Australian financial services was in front of their board with the same set of questions. The incident itself was a cyber event. What the boards were asking about was broader: what would happen to their own carrier's operations if a similar event struck, and how much of the answer would they be finding out for the first time.
The 2022 Medibank incident was a sector-defining moment for operational risk in Australian financial services. Board attention to operational resilience shifted in a way that a decade of compliance documentation had not achieved. The question moved from "do we have a plan?" to "can our operations actually run under a major incident?" In Australia, CPS 230, in force since 1 July 2025, reflects the sharpened regulatory environment that followed. In New Zealand, equivalent expectations exist under regulatory governance requirements for licensed insurers. Operational resilience is no longer a compliance exercise that sits in a filed document. It is a strategic question that boards now own.
The lesson from the Medibank incident is not primarily about cyber security. It is about operations design. Every carrier read the incident as a cyber event - and it was. What it also demonstrated was what happens to the operations of a major insurer when a significant incident disrupts the systems and infrastructure that those operations depend on.
Three consequences surface in any major incident affecting carrier operations. First: staff cannot access the systems they use to process claims, manage policies, and serve customers. Second: third-party dependencies - BPO providers, platform vendors, data services - may be disrupted by the same event or by the carrier's incident response. Third: the coordination infrastructure that keeps operations running may itself be part of what the incident has disrupted.
Most operations discover these gaps during the event. The carriers who did not discover them in 2022 had made different design choices before 2022.
The distinction that separated the carriers with better answers in the board sessions of late 2022 from those with worse answers was not speed of cyber response. It was operations design.
Carriers who had pre-positioned second sources - partners already fluent on their systems, with tested activation procedures - had a different answer to "what happens to claims processing?" than those whose continuity plan depended on arrangements that had never carried real load. Designed-in resilience is a condition of the operations before the incident. Improvised resilience is what happens when the gaps are discovered under pressure.
The board expectation post-2022 is that the answer to the operations question is already known. The carriers who are still discovering it under pressure are those whose resilience design has not caught up with the board's expectation.
The operations continuity track in a major incident requires different things from the cyber forensics track. It requires a second source that is already operating on the carrier's systems, not one that needs onboarding before it can function. It requires activation procedures that do not assume the primary infrastructure is still available. And it requires that the arrangement has been tested under conditions that include the variables a real event introduces, not just the controlled variables of a scheduled exercise.
A second source that requires a training runway before it can process claims is a documented commitment that cannot be met at activation speed. In a major incident, activation speed is the only variable that matters. The plan that runs at three times the documented recovery time is the plan that was not built for the event. It was built for the review.
ISSI operates as a warm second source on the platforms ANZ carriers already run. Because platform fluency on CyberLife, wmA, and Ingenium already exists, there is no ramp period before load can be carried. ISO 22301-class business continuity protocols and audit-passed credentials provide the operational evidence that boards, and regulators, are now asking for. If operational resilience design is active in your organisation, it is worth thirty minutes.
Sources: APRA Quarterly Life Insurance Performance Statistics (2025); APRA Quarterly Insurance Performance Statistics (September 2025)