Security threats targeting banks are becoming harder to detect, and cybersecurity firm Kaspersky said the Bangko Sentral ng Pilipinas’ (BSP) new self-assessment requirement could help financial institutions close long-standing security gaps if they treat it as more than a compliance exercise.
Under BSP Circular No. 1232, the central bank replaced its old cybersecurity rating system with the Supervisory Assessment Framework (SAFr), which includes the Cybersecurity Control Self-Assessment (CCSA). The new framework requires BSP-supervised financial institutions (BSFIs) to regularly assess and report the strength of their cybersecurity controls.
“The Philippine government is taking concrete steps to raise the bar for cybersecurity across the financial system, and banks must move with the same urgency,” said Heng Lee, director of government affairs and public policy for Asia Pacific at Kaspersky. “Compliance is no longer a box to tick. Institutions that use the CCSA to drive real improvements will not only meet regulatory expectations but will be far better positioned to defend their customers against the growing threat landscape.”
Kaspersky said the new BSP requirement comes at a critical time as banks face increasing cyber risks, including phishing attacks, account takeovers, ransomware, and fraud targeting digital banking users. The company cited a 2025 report by the Security Operations Center Capability Maturity Model (SOC-CMM), which found that 58% of organizations globally are failing to meet their own cybersecurity maturity targets.
The cybersecurity firm said many banks still rely on security operations centers designed mainly to react to attacks instead of preventing them. This often results in security teams processing large volumes of alerts without addressing weak detection systems or poor response processes.
Kaspersky said banks should use the CCSA findings as a roadmap for improvement instead of simply submitting reports for compliance. The company added that banks can gain a clearer view of their security posture by combining the BSP framework with international assessment tools such as SOC-CMM, which evaluates cybersecurity maturity across people, processes, and technology.
The company also urged financial institutions to rethink how they measure cybersecurity performance. According to Kaspersky, speed alone, such as how quickly alerts are closed, should not define success. Detection quality, resilience, and the ability to stop attacks before damage occurs are becoming more important as digital banking adoption grows in the Philippines.