THE BANGKO SENTRAL ng Pilipinas (BSP) is proposing to require all banks and nonbanks to conduct a self-assessment of their cybersecurity maturity amid growing concernsTHE BANGKO SENTRAL ng Pilipinas (BSP) is proposing to require all banks and nonbanks to conduct a self-assessment of their cybersecurity maturity amid growing concerns

Cybersecurity self-assessment for banks, nonbanks proposed by BSP

2026/02/26 00:31
3 min read

THE BANGKO SENTRAL ng Pilipinas (BSP) is proposing to require all banks and nonbanks to conduct a self-assessment of their cybersecurity maturity amid growing concerns over increasing cyber risks.

This, as the central bank seeks to strengthen the financial system through its supervised financial institutions (BSFI) against rapidly evolving threats in cyberspace.

“Digital financial and payment services and platforms continue to evolve rapidly, with innovative solutions emerging to enhance customer experience, improve operational efficiency, expand accessibility, and strengthen market competitiveness,” the central bank said in the exploratory note of the draft circular.

“However, these developments are accompanied by a corresponding increase in cyberthreats, which heighten risks to both financial institutions and their customers,” it added.

According to the central bank, the Cybersecurity Control Self-Assessment (CCSA) will allow BSFIs to enhance their offsite surveillance and risk assessments for information and cybersecurity.

“This initiative aims to enhance the financial sector’s resilience against  evolving cyberthreats by enabling BSFIs to assess their cybersecurity maturity against established best practices and develop a roadmap toward their target maturity level,” the BSP said.

BSP Deputy Governor Lyn I. Javier earlier noted that more frequent, more scalable and targeted cyberthreats are endangering the financial system’s digital shift, with the improving interconnectivity enabling more cybercriminals to exploit its weak points.

Based on the latest central bank report, social engineering such as phishing scams, account takeover and identity theft accounted for 76% of the total amount lost to financial fraud in the first half of 2025, making it the top cyberthreat of the local banking system.

This was followed by hacking, which made up 13% of the total losses, and card-not-present fraud with 8%.

Under the draft circular, the BSP clarified that the CCSA will not replace the current Supervisory Assessment Framework for cybersecurity and information security. 

Instead, it will serve as an additional requirement alongside the annual information technology (IT) profile that financial institutions were previously required to submit 25 days after the end of each reference year.

“Rather, these tools are designed to complement existing supervisory mechanisms by enabling BSFIs to identify areas for improvement and systematically track progress toward their desired maturity level,” the BSP said. 

The central bank also noted that the CCSA will use a Cybersecurity Maturity Framework (CMF) to measure the BSFI’s maturity level, based on the CCSA results, and its target maturity level aligned with its IT risk profile.

The assessment tool features capability-based questions to evaluate the BSFI’s maturity in specific control areas, as well as survey questions to gather further insights for policy development and regulatory guidance.

NBFIs’ maturity levels could be classified as foundational, established, managed or optimized, according to the BSP.

The level will be evaluated based on their information security governance, information security risk management, security control implementation, and cyberthreat intelligence and collaboration.

Both the CMF and the CCSA will then be integrated in the Advanced Suptech Engine for Risk-based Compliance, which the BSP said “may be periodically reviewed and enhanced to ensure a dynamic and responsive assessment process.”

“The result shall provide the BSFI’s current maturity and inform of the possible areas requiring intervention or a plan for improvement to achieve their target maturity,” the BSP added.

BSFIs with a moderate and complex IT profile will be mandated to electronically submit their respective CCSAs to the BSP yearly on or before March 31, following the end of the reference year. — Katherine K. Chan

Market Opportunity
CyberConnect Logo
CyberConnect Price(CYBER)
$0.556
$0.556$0.556
-0.59%
USD
CyberConnect (CYBER) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Rand Capital Announces $0.29 per Share Cash Dividend for First Quarter 2026

Rand Capital Announces $0.29 per Share Cash Dividend for First Quarter 2026

BUFFALO, N.Y.–(BUSINESS WIRE)–Rand Capital Corporation (Nasdaq: RAND) (“Rand” or the “Company”), a business development company providing alternative financing
Share
AI Journal2026/02/26 05:16
UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future

UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future

The post UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future appeared on BitcoinEthereumNews.com. Key Highlights Microsoft and Google pledge billions as part of UK US tech partnership Nvidia to deploy 120,000 GPUs with British firm Nscale in Project Stargate Deal positions UK as an innovation hub rivaling global tech powers UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future The UK and the US have signed a “Technological Prosperity Agreement” that paves the way for joint projects in artificial intelligence, quantum computing, and nuclear energy, according to Reuters. Donald Trump and King Charles review the guard of honour at Windsor Castle, 17 September 2025. Image: Kirsty Wigglesworth/Reuters The agreement was unveiled ahead of U.S. President Donald Trump’s second state visit to the UK, marking a historic moment in transatlantic technology cooperation. Billions Flow Into the UK Tech Sector As part of the deal, major American corporations pledged to invest $42 billion in the UK. Microsoft leads with a $30 billion investment to expand cloud and AI infrastructure, including the construction of a new supercomputer in Loughton. Nvidia will deploy 120,000 GPUs, including up to 60,000 Grace Blackwell Ultra chips—in partnership with the British company Nscale as part of Project Stargate. Google is contributing $6.8 billion to build a data center in Waltham Cross and expand DeepMind research. Other companies are joining as well. CoreWeave announced a $3.4 billion investment in data centers, while Salesforce, Scale AI, BlackRock, Oracle, and AWS confirmed additional investments ranging from hundreds of millions to several billion dollars. UK Positions Itself as a Global Innovation Hub British Prime Minister Keir Starmer said the deal could impact millions of lives across the Atlantic. He stressed that the UK aims to position itself as an investment hub with lighter regulations than the European Union. Nvidia spokesman David Hogan noted the significance of the agreement, saying it would…
Share
BitcoinEthereumNews2025/09/18 02:22
Silver & Silver Provides Guidance on Protecting Social Security Disability Claims During the Application Process in Vineland, NJ

Silver & Silver Provides Guidance on Protecting Social Security Disability Claims During the Application Process in Vineland, NJ

Vineland, NJ Silver & Silver, a law firm based in Pennsylvania, is sharing essential guidance for individuals navigating the Social Security Disability application
Share
AI Journal2026/02/26 05:18