Cuscal is Australia's largest independent end-to-end payments and regulated data provider outside the Big Four banks, operating since 1966 and publicly listed on the ASX since 2024. As an Authorised Deposit-taking Institution, it runs critical payments infrastructure serving banks, fintechs, and corporates - meaning the attack surface is broad and the stakes are systemic: real-time payment rails, card issuing and acquiring pipelines, fraud monitoring systems, digital wallets, and Consumer Data Right (CDR) services all sit within scope.
The threat model is concrete. Payment infrastructure and CDR are high-value targets for credential stuffing, API abuse, transaction fraud, and data exfiltration. Cuscal enabled over 60% of Australia's financial institutions on the New Payments Platform on day one in 2018 - so any compromise in real-time payments or fraud monitoring has cascading impact across the sector. The company launched Australia's first ATM in 1977 and has maintained nearly six decades of operational uptime across increasingly digitised rails.
Security teams here work at the intersection of payments engineering and regulatory compliance. Domains span fraud analytics, payment security architecture, identity and access management for CDR data-sharing ecosystems, and infrastructure hardening for always-on transaction processing. The environment pairs ADI-grade capital strength with fintech-speed delivery - a combination that demands both rigour and adaptability from security practitioners.





