A new cybersecurity regulation from the Bangko Sentral ng Pilipinas is putting banks on notice, but global cybersecurity firm Kaspersky is making the case that compliance alone won’t cut it.
Under BSP Circular No. 1232, the central bank has replaced its old rating system with the Supervisory Assessment Framework (SAFr), which introduces the Cybersecurity Control Self-Assessment (CCSA) as a key compliance tool. All BSP-supervised financial institutions are now required to regularly measure and report on the strength of their cybersecurity practices.
“The Philippine government is taking concrete steps to raise the bar for cybersecurity across the financial system, and banks must move with the same urgency. Compliance is no longer a box to tick. Institutions that use the CCSA to drive real improvements will not only meet regulatory expectations but will be far better positioned to defend their customers against the growing threat landscape,” said Heng Lee, Kaspersky’s director of government affairs and public policy for Asia Pacific.
More Than Half of Organizations Are Already Behind
Kaspersky pointed to a 2025 report by the Security Operations Center Capability Maturity Model (SOC-CMM) showing that 58 percent of organizations globally are already falling short of their own security maturity targets. The firm expects the new BSP framework to surface the same pattern among local banks once the self-assessments begin.
Four Ways Banks Can Get More Out of the CCSA
Kaspersky laid out practical steps for banks that want to make the requirement actually count.
First, treat CCSA results as action items. When the assessment reveals a gap, whether in SOC maturity, detection capabilities, or incident response readiness, it needs to be addressed, not just disclosed.
Second, go beyond the baseline. The CCSA sets a floor, but internationally recognized tools like the SOC-CMM measure security maturity more granularly across people, processes, and technology. Banks that benchmark against both will have a clearer picture of where they actually stand.
Third, fix the reactive trap. Many security operations centers are built to respond to alerts rather than prevent incidents, processing high volumes of notifications without addressing the root cause of poor detection quality. Kaspersky said institutions that use the CCSA to identify and correct this pattern will see the most meaningful gains.
Fourth, rethink how performance is measured. Speed, specifically how fast alerts are triaged or incidents closed, should not be the only metric. Detection quality and overall program resilience matter just as much, and these, Kaspersky noted, also serve as the strongest evidence of genuine compliance under the new framework.
For more information, visit kaspersky.com.