Securing Australia's Superannuation Gateway: How Oban Stays Compliant and Protected with RedBear

Introducing

Oban Solutions doesn’t appear to be a critical infrastructure provider. The Melbourne-based fintech runs a tight team, operates out of Kew, and has none of the institutional weight of the banks and superannuation giants it sits alongside in Australia’s financial system. But its obligations are identical to theirs.

Oban builds and operates the gateway infrastructure that connects superannuation funds, insurers, payroll providers, and businesses to Australia’s financial plumbing:

  • SuperStream gateways,
  • SBR2 ATO compliance connections,
  • payments infrastructure, and
  • insurance messaging.

All of it runs on technology Oban owns and controls. The company is the only Australian business to be Drummond-certified for the OASIS AS4 conformance profile. Its customers include ANZ, Future Super, Superhero, and GESB.

Brett Christie founded Oban in 2013 after selling his previous company, Syncsoft, a superannuation administration software business he’d run for nearly 30 years, to Link Group. Several of the team came with him. Some have worked alongside Brett for more than three decades.

Despite its size, Oban’s strength lies in the depth of experience within the business, something Brett says has been fundamental to its success.

‘Our obligations are exactly the same as Westpac’s. We don’t get off light – we still have to jump through the same hoops all the big players have to jump through. It’s a ticket to the dance. If you don’t do it, we can’t operate on the gateway.’

Brett Christie, CEO, Oban Solutions

The Situation

Nine gateway providers operate in Australia’s superannuation ecosystem. Westpac is one of them. So is Oban. The compliance obligations are the same for both.

To hold its gateway accreditation with the industry governance body, Oban must maintain ISO 27001 and ISM (Information Security Management) certifications, meet its obligations under the Security of Critical Infrastructure (SOCI) Act, and, more recently, comply with CPS230 – the prudential standard governing operational risk management in financial services. Regular audits assess all of it.

For Brett, the biggest misconception is that smaller providers face lighter regulatory obligations. The reality is quite the opposite.

Before RedBear, Oban relied on an external IT provider that had moved the business onto AWS – not as a considered cloud strategy, but to exit its own data centre. Costs climbed. More problematically, the provider offered no regular security reporting. For a business facing structured compliance audits, that was a significant gap. Oban needed a partner that genuinely understood AWS and security, and could produce the documented evidence an audit demands.

Enter RedBear

In 2018, both companies had stands at the ASFA conference in Adelaide. Oban’s head of technical, David Clear, stopped at RedBear’s booth and started talking to RedBear’s CTO, Jem Richards. The conversation moved quickly. This was early days for cloud in the managed services sector, and providers who could talk AWS and security together – not one or the other – were scarce.

Shortly after the conference, Oban visited RedBear’s Melbourne office. Brett had looked at larger providers. He ruled them out quickly.

‘Getting a big player would be like getting a sledgehammer to crack the nut. RedBear was right at that sweet point – not too big, not too small, and a lot more cost-effective than the alternatives we looked at.’

Brett Christie, CEO, Oban Solutions

From that first office meeting, Doug Woodford and Jem Richards became Oban’s main contacts. They’ve stayed that way across five-plus years. No account managers, no being passed down the chain.

RedBear started with an AWS Well-Architected Review, moved into security assessments and annual penetration testing, and the engagement grew into a full MSSP arrangement. RedBear now operates as Oban’s outsourced security function. Monthly reporting is a standard deliverable – structured, documented evidence of Oban’s security posture that goes directly into the compliance and audit process.

For Oban, one of the most immediate improvements was the introduction of consistent, audit-ready reporting that demonstrated the state of its security environment every month.

‘One of the things we have with RedBear, which is very useful, particularly with our audits, is our monthly report. We weren’t getting that from the previous provider.’

Brett Christie, CEO, Oban Solutions

CPS230 has added a further dimension to the relationship. The standard requires Oban to attest to the security practices of its own suppliers formally. RedBear’s ISO 27001 certification, currently in progress, will significantly reduce that burden once complete.

‘Once RedBear’s ISO 27001 certification is done, that’ll make our life a lot easier come audit time.’

Brett Christie, CEO, Oban Solutions

‘It’s about having a trustworthy set of eyes. That’s the key point. What we get from RedBear is sufficient to keep those walls apart – and it means we can stay focused on what we do, rather than pulling resources away from our core business to handle security work ourselves.’

– Brett Christie, CEO, Oban Solutions

The Outcomes

A small business cannot build an internal security function that meets the compliance demands Oban faces. The economics don’t work.

RedBear provides Oban specialist coverage at a fraction of the cost, and frees the team to focus on the gateway infrastructure their customers depend on.

Specific outcomes include:

  • Gateway accreditation maintained across SOCI, ISO 27001, ISM, and CPS230 obligations
  • Monthly security reporting that supports the audit process with documented evidence
  • Annual penetration testing provides independent validation of the environment
  • Attack surface reduction across cloud configurations and legacy systems
  • ISO 27001 certification in progress at RedBear, set to reduce Oban’s supplier audit burden under CPS230

For Brett, the value of the partnership extends well beyond compliance. It gives Oban the confidence to focus on its core business, knowing its security is in trusted hands.

Ready to Simplify Compliance and Strengthen Security?

Managing compliance obligations in a regulated environment? RedBear helps organisations stay secure, audit-ready, and focused on what they do best.

CLOSE MENU