BSP cybersecurity framework refers to the set of “technical controls” developed and promoted by the Bangko Sentral ng Pilipinas (BSP) to protect the Philippine financial system. The rise of digital banking, e-money, and open finance laid the foundation for widespread digital financial adoption in the Philippines. In recent years, the Bangko Sentral ng Pilipinas (BSP) has responded to the increasing cyber threats by strengthening its supervisory expectations through enhanced IT risk management and cybersecurity regulations applicable to all BSP-Supervised Financial Institutions (BSFIs). Through issuances such as BSP Circular No. 982 and BSP Circular No. 857, the BSP formalised mandatory information security standards and accountability,
This guide explains the regulatory foundations of the BSP cybersecurity framework, including key issuances such as BSP Circular No. 982 and BSP Circular No. 857, and how they shape BSP cybersecurity requirements for banks and fintechs. It also examines the role of the BSP in cyber defence, whether the framework is mandatory, how it aligns with international standards, and what happens if a financial institution fails to meet BSP cybersecurity compliance requirements in the Philippines.
What is the BSP Cybersecurity Framework?
The BSP Cybersecurity Framework is a set of mandatory security rules, technical controls, IT risk management requirements, and cyber resilience guidelines that Philippine banks and BSP-supervised financial institutions (BSFIs) have to follow in order to protect sensitive information, customer data, financial information, and digital transaction infrastructure.
Main objectives of the BSP cybersecurity framework:
- Improve banks’ and financial institutions‘ ability to prevent, detect, respond to, and recover from cyberattacks.
- Ensure you properly identify, assess, and manage cybersecurity risks.
- Improve incident response within the system by encouraging timely reporting and coordinated action.
- Build strong cybersecurity across the financial sector by regular cyber resilience testing, including simulation exercises and stress testing.
- Balance financial technology with cybersecurity controls and consumer protection measures.
These objectives establish a sound BSP IT risk management program, enforcing BSP IT security regulations, and strengthening cyber protection through continuous monitoring and defence mechanisms.
What is the role of the BSP in Cyber Defence?
The BSP’s role in cyber defence is:
- Lead regulator: The BSP develop and issues clear cybersecurity policies and regulatory frameworks across all BSP-supervised financial institutions (BSFIs). It ensures all BSFIs align with regulations and globally recognised best practices.
- Operation coordinator: The BSP acts as the lead Computer Emergency Response Team (CERT) for the Philippine financial sector. It coordinates responses to major cyber incidents and promotes collaboration between banks, financial institutions, and stakeholders to promote cybersecurity.
- Supervisor: The BSP monitors and assesses how well financial institutions are complying with cybersecurity requirements through platforms like ASTERisC (Advanced SupTech Engine for Risk-Based Compliance).
- Industry collaboration: BSP encourages real-time information sharing on cyber threats.
- Encourage cybersecurity practices: The BSP encourages regular cybersecurity exercises such as incident response simulations, training, and awareness programs to improve cybersecurity postures in the Philippines.
What is BSP Circular 982?
BSP Circular No. 982 is a central part of the BSP cybersecurity framework guidelines. issued in 2017 for BSP-Supervised Financial Institutions (BSFIs). It mandates that:
- Non-banking financial institutions and other supervised entities establish and maintain information security and IT risk management programs that are suitable for their size, risk profile, complexity of operations, and technology.
- BSIFs to implement a comprehensive Information Security Risk Management Framework that specifically covers IT infrastructure and operations, electronic banking, digital financial services, and payment systems, information assets and data protection, access controls and identity management, outsourced and third-party service providers, and incident detection, response, and reporting mechanisms.
- Board of Directors (BoD) and Senior Management to ensure security governance, clear accountability, and allocation of adequate resources for cybersecurity.
- Periodic risk assessments and VAPT(vulnerability assessments & penetration testing) to identify weaknesses and address cybersecurity threats.
- Incident reporting by BSIFs to the BSP in case of major cybersecurity incidents and compliance with the regulatory frameworks.
What is BSP Circular 857?
BSP Circular No. 857 was issued by Bangko Sentral ng Pilipinas in 2014. It ensures that customers of banks and other financial institutions are treated fairly and properly protected. The circular sets minimum standards for protecting consumer information and handling customer data securely. This aligns with BSP cybersecurity requirements for banks, as protecting customer data is a core part of cyber risk mitigation. Finally, it sets out basic principles and ethical business practices governing BSFIs’ conduct.
Is the BSP Cybersecurity Framework Mandatory?
Yes, the Bangko Sentral ng Pilipinas (BSP) have a mandatory cybersecurity framework, but this must be issued by official circulars and regulations, e.g. BSP Circular No. 982.
This circular defines the need to have extensive cybersecurity and IT risk management programs by BSP-supervised financial institutions. Such programs should be equipped with continuous vulnerability and threat testing in order to identify and respond proactively to risks.It also requires incident reporting of cyber threat which means that institutions have to report material cybersecurity incidences to BSP and handle external responses where needed.
In addition, more recent efforts include the Cybersecurity Maturity Framework (CMF) alongside the Cybersecurity Control Self-Assessment (CCSA), which is based on these former rules. They take effect as mandatory compliance requirements once officially released in the form of BSP circulars; this strengthens and extends the requirements of Circular 982.
Does the BSP Cybersecurity Framework align with Global Standards?
Yes. BSP’s cybersecurity and IT risk management requirements align with global cybersecurity standards and best practices, including:
- The BSP’s cybersecurity initiatives, Circular 982 and related guidelines, are built on a risk-based foundation, which aligns with ISO/IEC 27000 series – ISO 27001 on information security management systems and ISO 27002 on security controls, and the NIST Cybersecurity Framework.
- The 2024–2029 Financial Services Cyber Resilience Plan (FSCRP) explicitly aligns with the National Cybersecurity Plan 2028 of the Philippines, which is designed around internationally accepted cybersecurity principles.
- BSP’s expansion of the Advanced SupTech Engine for Risk-Based Compliance (ASTERisC) enables real-time reporting, risk analytics, and standardised assessment of cybersecurity programs help BSP to compare local BSFIs against global industry norms.
What happens if a bank fails to comply with BSP Cybersecurity Rules?
Non-compliance with BSP cybersecurity requirements and the cybersecurity framework carries consequences:
| Type of Violation | Maximum Monetary Penalty |
| Violation of any BSP law, rule, or regulation, including cybersecurity and IT risk management requirements | Up to ₱100,000,000 per violation |
| Failure to correct a cited cybersecurity or regulatory deficiency, resulting in a continuing violation | Up to ₱1,000,000 per day until the violation is remedied |
| Engaging in unsafe or unsound banking practices due to inadequate cybersecurity controls or IT risk management failures | Up to ₱100,000,000 per violation |
| Committing a violation that results in financial gain or allows the institution to avoid financial loss | Up to three (3) times the profit gained or loss avoided |
| Directors or officers found personally responsible for regulatory or cybersecurity violations | Up to ₱100,000,000 per violation |
A single unresolved finding can cost up to ₱1,000,000 per day until it’s fixed.
Don’t wait for a BSP examiner to find the gap first — get a penetration test that maps directly to Circular 982’s Information Security Risk Management Framework. Request a Quote →
How can Qualysec help
Qualysec helps banks and fintechs meet BSP IT risk management and cybersecurity requirements. Our approach is structured, practical, and measurable. The Bangko Sentral ng Pilipinas is raising expectations for governance, continuous monitoring, and risk-based security controls. Financial institutions need security solutions they can rely on. With experience across multiple industries, Qualysec delivers regulatory-aligned penetration testing, vulnerability management, and compliance-driven security assessments. Our services help organizations strengthen security while meeting BSP compliance requirements.
- Regulatory-Aligned Penetration Testing: Expert penetration testing services in web applications, mobile applications, APIs, networks, and cloud instances. Assists with complying with BSP cybersecurity regulations for banks and other digital financial institutions.
- Vulnerability Assessment Programs: Vulnerability assessments are in tandem with the principles of BSP technology risk management. They enable institutions to rank, identify, and mitigate IT and cyber risks to the extent of their effects, probability, and exposure.
- Cloud & Infrastructure Security Reviews: Checks on cloud setups, access controls, and network security architecture. Ensures they comply with BSP IT security rules and the protection of secure digital banking processes.
- API Security Testing: In the case of fintechs and digital banks, we test application code and APIs. This mitigates the risks connected to data breaches, transaction fraud, and account takeovers.
- Audit Ready Reporting: The assessment report and technical findings are prepared for audits. They are congruent with global best practices and BSP IT risk management expectations.
- Ongoing Testing: Reinforces the long-term correspondence of the BSP cyber resilience framework. Qualysec offers re-testing, remedies verification, and a planned growth roadmap to assist in constant cybersecurity compliance.
Conclusion
The BSP cybersecurity framework is not a compliance checklist. It is a hardiness plan to the Philippine financial ecosystem. The Bangko Sentral ng Pilipinas has changed cybersecurity into a board-level role through regulations like BSP Circular No. 982 and BSP Circular No. 857. These regulations have turned cybersecurity into a technical role. In the case of a bank and a financial technology (fintech), compliance refers to the creation of a system that pre-empts threats, reacts decisively, and recovers with confidence. It requires consistent testing, responsible leadership, and controls.
Frequently Asked Questions (FAQs)
Are BSP cybersecurity compliance regulations mandatory?
Yes. Banks and all BSP-Supervised Financial Institutions are expected to adopt BSP Circular No. 982 and other associated rules. This includes fintechs and issuers of e-money. These rules are binding stipulations. Otherwise, regulatory authorities may impose financial fines, operational restrictions, and stricter controls.
Who should manage cybersecurity in a financial institution?
The Board of Directors and the senior management holds accountability. The BSP anticipates the leadership to actively participate in the management of cybersecurity, governance frameworks, and provision of sufficient resources. The issue of cybersecurity is handled as a global responsibility of the organisation, instead of being a role of IT departments.
What frequency of cybersecurity testing should there be?
The process of cybersecurity testing ought to be risk based. The institutions are supposed to perform vulnerability tests and pen-testing at frequent intervals, as well as monitoring of the important systems on an ongoing basis. It must be based on the number of risks and their exposure to the system, as well as the complexity of operations.
What kind of cyber incidents shall be reported to BSP?
Material attack on cyber that impacts customer data, monetary transactions, system accessibility, or regulatory requirements should be disclosed. The institutions are supposed to provide an initial notification within the deadline mandated and proceed with elaborated reports that justify the effect, the cause of the effect and the remedial actions.
What would happen once the BSP cybersecurity guidelines are not met?
Failure to comply may result in huge fines, continuous fines on continued problematic behavior, and business sanctions. In severe instances, the BSP can subject to an increased surveillance or action against the accountable officers and this may impact on the operations as well as the credibility of the institution.
See what BSP-ready evidence actually looks like. Download our sample Vulnerability Assessment Report.






