Business & Policy

BSP orders banks to report cyber gaps and security spending

Covered financial institutions must report unresolved vulnerabilities, cyber incidents, and detailed cybersecurity spending to the BSP.

The Bangko Sentral ng Pilipinas (BSP) is the Philippines’ central bank and supervises banks and other financial institutions operating in the country.

Banks and other covered financial institutions must report unresolved cybersecurity vulnerabilities, cyber incidents, and detailed security spending to the Bangko Sentral ng Pilipinas (BSP) under new reporting rules issued October 1.

Memorandum No. M-2026-047 sets the submission rules for the Cybersecurity Controls Self-Assessment (CCSA), which institutions must complete through the BSP’s Advanced SupTech Engine for Risk-based Compliance, or ASTERisC.

The requirement covers BSP-supervised institutions with Moderate or Complex IT Profiles, as well as others specifically designated by the central bank.

The first assessment is due 60 calendar days from the memorandum’s issuance, or November 30. Subsequent submissions are due annually by March 31 following the end of the reference year.

The BSP is asking institutions to provide their latest vulnerability assessment and penetration-testing report for electronic payment and financial services systems. They must also submit monitoring reports covering outstanding information-security and cybersecurity audit issues, unresolved vulnerabilities involving critical applications and infrastructure, their age and severity, and expected resolution timelines.

Institutions must provide cyber incident statistics for the previous year, including incident classification and severity, the number of incidents, and the total amount involved where available.

The assessment also gives the BSP a detailed view of how much institutions are spending on technology security. It asks for enterprise-wide, IT, and cybersecurity budgets for 2024, 2025, and 2026, along with actual IT and cybersecurity expenditures.

Cybersecurity spending is broken down into areas including security tools, vulnerability management and penetration testing, security operations centers, personnel, training, cloud services, outsourcing, and compliance and risk management.

Other parts of the assessment examine governance, risk management, security controls, incident response and recovery, staffing, and cyber threat intelligence.

The BSP, however, said the absence of a particular control does not automatically result in a lower maturity score because institutions will be assessed based on their overall cybersecurity practices.

The reporting requirement implements Circular No. 1232, issued in April, which introduced the BSP’s Cybersecurity Maturity Framework. The framework has four levels — Foundational, Established, Managed, and Optimized — with institutions expected to reach different levels depending on the complexity of their IT operations.

The BSP will validate submitted assessments and make the results available to the respective institutions through ASTERisC.

Source: Bangko Sentral ng Pilipinas

Leave a Reply

Your email address will not be published. Required fields are marked *