Maya says customer trust is reshaping cybersecurity in digital finance

TechnologyFinTechMaya says customer trust is reshaping cybersecurity in digital finance

Maya executives say stronger customer controls, operational resilience, and regulation that can keep pace with evolving threats are becoming central to trust in digital financial services.

As Filipinos increasingly use apps to move, save, borrow, and manage money, cybersecurity is becoming more visible in the financial experience itself. Security is no longer confined to the systems operating behind the scenes, but increasingly includes the controls customers can use directly and the policies and processes designed to keep services available when threats emerge.

At the recent BusinessWorld Cybersecurity Summit, Maya executives said this shift is changing how financial institutions approach security, what customers should expect, and how regulation needs to evolve. For digital finance providers, the challenge is not only to prevent attacks but also to build systems, processes, and customer tools that can respond when risks change.

Giving customers more control

Maya has increasingly placed security controls directly in the hands of users. Through its in-app security features, customers can immediately freeze or unfreeze cards and manage how those cards are used, while biometric authentication, fraud monitoring, and other safeguards continue to operate in the background.

Maya credit cards also use dynamic CVVs, adding another layer of protection for online transactions. Together, these tools reflect the company’s view that cybersecurity is becoming part of the product experience rather than a separate back-office function.

“For us in Maya, cybersecurity is not some back-office product, it’s really part of the product,” said Kristoffer Rada, head of corporate affairs at Maya. “As more people depend on digital financial services every day, maintaining trust becomes a responsibility shared by financial institutions, regulators, government and the broader ecosystem.”

Maya cybersecurity
Kristoffer Rada, head of corporate affairs at Maya, says cybersecurity is increasingly becoming part of the product experience as more customers rely on digital financial services.

Regulation that can keep pace with changing risks

Rada said effective cybersecurity policy increasingly needs to balance strong safeguards and institutional accountability with the ability to respond to rapidly evolving technologies and risks. Rather than focusing only on compliance with individual rules, he said the broader objective should be to protect customers, maintain continuity of service, strengthen accountability, and ensure institutions are prepared to respond and recover when incidents occur.

“Technology evolves so fast. The rules that apply this year may no longer be applicable and could become archaic in five years,” Rada said. “Whatever technology evolves, you have to evaluate using the same standard because the risks are the same.”

He added that technology-neutral and risk-based standards can help regulation remain relevant even as specific tools and platforms change. For that approach to work, however, closer coordination across government and industry is also needed.

Cyber risks increasingly cut across banking supervision, data privacy, telecommunications, consumer protection, and law enforcement. Maya said this makes timely information sharing, coordinated scam prevention, and clear regulatory expectations increasingly important as threats move across institutions and sectors.

“Cyber threats do not stop at the boundaries of one company, one regulator or one country,” Rada said. “The stronger the coordination across the ecosystem, the better we can protect customers and maintain confidence in digital services.”

Building resilience across the enterprise

Jan Martin Encina, director of information security at Maya, said organizations also need to treat cybersecurity as an enterprise-wide responsibility rather than something owned solely by IT teams. This means making resilience part of business operations, governance, infrastructure, and workforce practices.

“Cybersecurity is no longer just an IT issue; it is a business imperative, a national security priority and a fundamental component of public trust,” Encina said.

Jan Martin Encina, director of information security at Maya, says organizations need to treat cybersecurity as an enterprise-wide responsibility rather than an issue handled solely by IT teams.

According to Encina, stronger cyber resilience requires organizations to move beyond reactive defenses toward continuous monitoring, stronger identity and access management, resilient infrastructure, regular security testing, and well-established incident-response capabilities. These measures are intended not only to reduce the likelihood of successful attacks, but also to help institutions continue operating and recover more effectively when incidents occur.

People remain part of the security equation

Technology alone is not enough to address cyber risk. Maya said sustained employee awareness and customer education remain important as cybercriminals increasingly combine technical attacks with social engineering and other tactics designed to exploit human behavior.

Encina also emphasized the importance of public-private partnerships, cross-border cooperation, and threat-information sharing as attacks become more sophisticated and interconnected. This broader coordination is particularly important in financial services, where scams and cyber incidents can move quickly across institutions and digital platforms.

“Ensuring that personal data is collected, stored and processed responsibly is not only a regulatory requirement, but also a moral obligation to the citizens and customers we serve,” Encina said.

Cybersecurity as part of customer trust

Maya also works with regulators and law-enforcement agencies including the Bangko Sentral ng Pilipinas, the Department of Information and Communications Technology’s Cybercrime Investigation and Coordinating Center, the Department of Justice, and the Philippine National Police.

For Maya, cybersecurity increasingly operates across several fronts at once: giving customers greater control over their accounts and cards, strengthening defenses within the enterprise, preparing systems to remain resilient during incidents, and supporting a regulatory environment that can adjust as technology and threats evolve. The common thread across those efforts is trust, which becomes more important as consumers rely more heavily on digital platforms for everyday financial activity.

In Summary

Maya says cybersecurity in digital finance increasingly depends on customer-facing controls, resilient infrastructure, stronger identity and access management, continuous monitoring, employee and customer education, and closer collaboration across government and industry. Its security features include card freeze and unfreeze controls, biometric authentication, fraud monitoring, and dynamic CVVs for credit cards.

Maya executives also argue that regulation should be technology-neutral and risk-based so it can remain relevant as threats evolve. The company works with agencies including the BSP, DICT-CICC, DOJ, and PNP as part of broader efforts to strengthen consumer protection and confidence in digital financial services.

Related Posts