BSP Introduces Risk-Based Cybersecurity Framework, Mandates Stricter Self-Assessments for Banks

 

The Bangko Sentral ng Pilipinas has initiated a structural reset in how it monitors cyber risk across the financial system, replacing a static compliance model with a framework built on continuous evaluation and accountability.

At the center of this shift is Eli M. Remolona Jr., who authorized reforms designed to strengthen off-site surveillance and risk assessment as digital vulnerabilities become more complex and pervasive. The move acknowledges a fundamental reality: cybersecurity can no longer be audited occasionally. It must be tested, measured, and refined as an ongoing discipline.

Circular No. 1232 formalizes the transition from the outdated IT Rating System to the Supervisory Assessment Framework, or SAFr. Unlike its predecessor, which relied heavily on periodic scoring, SAFr operates as a risk-sensitive model that evaluates institutions based on how well they anticipate, absorb, and respond to cyber threats in real time.

To support this architecture, the central bank introduced two key instruments. The Cybersecurity Maturity Framework establishes a globally aligned structure for evaluating defensive capabilities, while the Cybersecurity Control Self-Assessment functions as a diagnostic tool, enabling institutions to measure their current posture and identify gaps. Together, these tools shift responsibility closer to the institutions themselves. Instead of waiting for regulatory findings, banks are expected to generate their own evidence of resilience.

This approach mirrors how modern aviation handles safety. Airlines do not rely solely on external inspections. They run continuous internal checks, simulations, and system reviews to prevent failure before it occurs. The BSP is applying a similar philosophy to financial infrastructure.

Under the new rules, BSP-supervised financial institutions must conduct periodic and data-intensive self-assessments as part of their core risk management systems. These exercises are not meant to be procedural. They are intended to surface weaknesses using broader datasets and more nuanced variables, pushing institutions to move beyond surface-level compliance.

The framework also introduces a four-tier classification system that reflects cybersecurity maturity. Institutions are categorized as foundational, established, managed, or optimized. Those at the lower end typically exhibit fragmented controls and inconsistent risk integration. At the highest level, organizations deploy advanced technologies and adaptive systems capable of detecting and mitigating threats before they escalate.

Importantly, the BSP does not impose a uniform target across all institutions. The model is calibrated to risk exposure and operational complexity, recognizing that a universal standard would be impractical. However, the direction is clear. Continuous improvement is no longer optional, regardless of size.

Compliance requirements have likewise been tightened. Financial institutions must submit an annual IT profile within 25 days after the close of the reference year. Entities with moderate to complex technology environments are also required to file their Cybersecurity Control Self-Assessment by March 31 of the following year.

Implementation will be supported by the BSP’s Advanced SupTech Engine for Risk-based Compliance platform, known as ASTERisC, which will handle submissions and streamline oversight processes. To facilitate the transition, institutions are given a limited window, with initial CCSA submissions due within two months after the release of detailed guidelines.

Taken together, these changes signal a deliberate move away from checklist supervision toward a model that demands evidence of real-world readiness. In a financial system increasingly shaped by digital exposure, the BSP is effectively redefining cybersecurity as a continuous operational obligation rather than a periodic regulatory exercise.

Comments