Facilitate APRA Compliance with VMware Cloud Foundation 9
Financial services institutions (FSIs) are constantly navigating the dual demands of accelerating innovation while maintaining strong governance, risk management, and regulatory compliance - especially in light of evolving APRA (Australian Prudential Regulation Authority) requirements.
VMware Cloud Foundation (VCF) 9 provides a unified platform that empowers FSIs to meet these demands. With industry leading lateral security, advanced compliance and ransomware recovery capabilities integrated into a secure, single and unified platform, alongside a variety of high availability topologies to meet the most stringent recovery objectives, VCF supports both operational resilience and regulatory alignment.
As more organisations adopt VCF, or gain entitlements to its full feature set, this blog explores key ways to maximise VCF to meet APRA compliance objectives - whilst enabling the agility your business needs.

1. Business Context Foundations
Compliance frameworks like CPS230 emphasise understanding business context and critical processes to system dependencies to improve operational decision-making and collaboration. VCF 9 includes tagging capabilities and automates discovery and maintenance of app dependencies, providing the foundation needed to simplify resilience and compliance. Consider the benefit of adopting the following:
-
Virtual asset and Configuration Items (CI) discovery using flow analysis and discovery of services on VMs and containers (via Istio)
-
Integration with your broader ITSM tools, like ServiceNow
-
AI-based app discovery continuously discovering app dependencies – not relying on static data from the CMDB
-
Discover unexpected or misplaced sensitive data in transit and trigger appropriate governance workflows
-
Dynamic app dependency dashboards provide visibility of infrastructure health relevant to given applications.
2. Desired State Modern Infrastructure (IaaS)
VCF 9 now includes an integrated out of the box Kubernetes platform service to run both containers and modern VMs (VM Service), using a K8s declarative control plane to maintain desired state configuration. This brings the benefits of virtualisation to K8s and containers.
Whilst this feature is targeted at the app modernisation agenda, it has inherent security outcomes by avoiding configuration drift and the “tech debt” associated with long lived infrastructure resources. Enabling modern GitOps practices also improves the agility of the infrastructure to adapt to disruptive business demands and app changes.
3. Define and Monitor Service Tolerances and Metrics
Traditional approaches to monitoring infrastructure have evolved. Shipping verbose logs and relying on data intensive correlation engines is a thing of the past. VCF 9 now enables your OpenTelemetry (OTel) and Site Reliability Engineering (SRE) initiatives – allowing you to define and expose key metrics and thresholds via a much-improved API alongside VKS standard packages such as Telegraf and Prometheus which are included within VCF. This allows you to monitor for system conditions and events that may equate to an operational risk.
Additionally, the building blocks that make up the VCF platform itself have been unified into the new VCF Operations experience. This not only makes it easier to integrate into VCF to consume metrics through a unified API, but also speeds up troubleshooting with features such as Intelligent Search and better UI performance. The native VCF Operations dashboard has also been refined based on customer feedback, reducing the need for custom dashboards.
4. Make Zero Trust Network Security As Easy as VPC
Setting up best-in-class network security for new use cases, whether on-premises or in public cloud, typically involves specialist engineers and service tickets. Achieving the same with VCF 9 just got a whole lot easier.
Through VCF 9’s virtual private cloud (VPC) self-service networking and VPC-Aware lateral security you can curate advanced network security services for your platform engineers, developers and project teams to stand-up by themselves based on templated configurations and policies within guardrails you set.
The Security Segmentation Report alongside those tag-based policies and a declarative model, allows for lateral security to be deployed “as-code” with app releases, delivering a continuous DevSecOps zero trust network architecture.
5. Manage Supplier Concentration Risk
From a regulatory perspective we are seeing a focus on public cloud, data sovereignty and service provider concentration risk. The portability of VCF 9 to and from data centres and public cloud, enabled by VCF Operations HCX, offers a battle tested technical solution to that problem space. This provides a useful mitigation solution to plausible disruption scenarios that an organization might need to respond to now and into the future - beyond traditional disaster recovery scenarios.
6. Compliance Automation
VCF Operations now continuously monitors runtime settings against security configuration baselines, flagging drift the moment it appears and autocorrecting it where policy allows, maintaining desired state of the VCF infrastructure.
The new Security Operations console in VCF 9 overlays live attack-surface maps with real-time compliance scores, giving SecOps one place to spot vulnerabilities, unexpected traffic flows, prioritise patches, and verify remediation before an audit does. Compliance posture can be queried via the unified API in support of compliance-as-code initiatives - automating auditing efforts.
7. Web Application and API Security
The VCF modern distributed load balancer (AVI), includes a very powerful Web Application firewall (WAF) to detect and block threats to Web apps and APIs. It can be set up to allow generalists to self-serve advanced security inside VCF virtual private clouds (VPCs). AVI WAF adds security to the application tier alongside the network security provided by vDefend as part of a zero-trust strategy.
8. Eliminate DIY Developer Ecosystem Risk
Instead of building your own modern apps ecosystem using in the region of 40 DIY open-source tools that you then must manage and patch, you can remove all that complexity. VCF now includes many of the common open-source components relied upon by developers, pre-hardened and life-cycled. As an advanced service, Tanzu Platform running on top of VCF further reduces dependencies on self-managed open source, allows apps to be easily patched and reduces the risk of adversary dwell time through fast periodic repaving of apps and tooling.
Finally, for data services, VCF Data Services Manager is an integrated “Database-as-a-Service” solution that automates the lifecycle of hardened versions of popular open source databases like PostgreSQL (including pgvector) and MySQL.
9. Artificial Intelligence – Shadow AI Avoidance
The proliferation of Generative AI (GenAI) introduces new operational risks for FSIs, including data privacy, intellectual property protection from ‘shadow’ AI, and the threat of malicious data model poisoning, all relevant to CPS 230. VMware Private AI offers a secure platform on VCF for running models on a private network. VCF provides the necessary sovereignty, access, and governance controls to protect high-value private AI models and meet emerging compliance requirements.
10. Native Data Protection
There have been many data protection improvements to vSAN with the release of the updated vSAN Express Storage Architecture (ESA). This includes improved native snapshots with reduced stun times and immutable snapshot replication in support of ransomware recovery. There is a lot to unpack with vSAN ESA and so we encourage you to find out more.

Conclusion
VMware Cloud Foundation 9 is a unified platform that directly supports Financial Services Institutions (FSIs) in meeting APRA's CPS 230 (& CPS234) requirements by embedding advanced security, compliance automation, and operational agility. It simplifies the path to operational resilience by streamlining areas like business contextual awareness, zero-trust networking, and secure Private AI, transforming risk management into proactive governance.
Call to Action
-
Schedule a Deep Dive: Contact your Broadcom representative to explore how VCF9 can specifically address your strategic compliance and resilience needs with a reduced TCO versus alternative approaches
-
Conduct a VCF9 readiness assessment of your existing VMware environment to map out your steps to a more resilient foundational infrastructure
-
Learn about VCF9 advanced features. Consult the linked references for details.

References