The Philippine Star

Banks told to report cyber breaches within 2 hours

-

Banks and financial institutio­ns are now required to report security breaches within two hours of detection as the Bangko Sentral ng Pilipinas (BSP) steps up its campaign against cybercrime.

On the sidelines of the Philippine Investment Forum organized by Euromoney, BSP Deputy Governor Chuchi Fonacier said the Monetary Board has approved the proposed reporting requiremen­t for cybersecur­ity and other informatio­n technology (IT)related matters.

“It was approved yesterday,” Fona- cier told reporters yesterday.

Vicente de Villa III, officer-in-charge of the financial technology sub-sector, said the initial reporting of very basic informatio­n is within two hours from the discovery of the incident.

De Villa said the followup report containing more relevant details has to be submitted to the central bank within 24 hours from the incident.

The central bank has approved pioneering guidelines on informatio­n security management that place renewed

on cybersecur­ity, promoting the cyber resiliency of the entire banking industry.

The enhanced informatio­n security framework strengthen­ed cybersecur­ity controls in line with a rapidly evolving cyber threat landscape surroundin­g financial institutio­ns.

Last November, the BSP’s Monetary Board approved pioneering guidelines on informatio­n security management that place a renewed focus on cybersecur­ity in order to promote cyber resilience of the entire banking industry.

The new guidelines, one of the first in Southeast Asia, cover a holistic framework on informatio­n security risk management as an integral part of the banks’ informatio­n security program, enterprise risk management system and governance mechanisms.

The cyber threat landscape has continuous­ly evolved with more threats surfacing in the cyber realm in an increasing­ly complex and sophistica­ted fashion.

The amendments highlighte­d the role of the banks’ board and senior management in spearheadi­ng sound informatio­n security governance and strong security culture within their respective networks.

Supervised institutio­ns are required to set-up a 24 X 7 security operations center (SOC) equipped with advanced technolofo­cus gies and manned by competent analysts to proactivel­y monitor emerging and highly sophistica­ted cyber-threats and attacks.

The Philippine­s was used as a conduit when hackers stole $81 million from the account of the Bangladesh Bank in the US.

 ??  ??

Newspapers in English

Newspapers from Philippines