BSP cybersecurity & resilience

Strengthen confidence in financial services.

Translate applicable supervisory expectations into a prioritised programme for technology risk, authentication, fraud controls and operational resilience.

Discuss BSP cybersecurity

Designed for your context

The right support
for the decision ahead.

For BSP-supervised financial institutions and financial-services teams preparing for examination, technology change or stronger fraud and security controls.

What we deliver

Scope tailored to your organisation

Regulatory gap assessment

Assess applicable BSP cybersecurity requirements, including Circular 1213 where relevant, against current controls.

IT risk management

Develop governance, risk assessment and control-monitoring practices.

Authentication advisory

Assess appropriate phishing-resistant authentication options, including passkeys/FIDO2 and related implementation dependencies.

Fraud management design

Support the design and governance of fraud management capabilities and account-protection measures.

Resilience planning

Map relevant Financial Services Cyber Resilience Plan priorities into the improvement roadmap.

Examination preparation

Organise control evidence, management reporting and remediation tracking for supervisory reviews.

Tangible outputs

Leave with more
than recommendations.

  • Applicable-requirements gap assessment
  • IT risk and control roadmap
  • Authentication and fraud-control recommendations
  • Resilience action plan
  • Examination evidence preparation

A clear path to progress

  1. 01

    Confirm applicable requirements

  2. 02

    Assess risk and controls

  3. 03

    Prioritise improvements

  4. 04

    Prepare evidence and review

Philippine context & engagement boundaries

Supervisory scope, circular applicability and current transition or compliance dates must be validated with the institution. No historic deadline or universal technology prescription is assumed.

Questions worth asking

How is the engagement scoped?

We start with your priorities, operating context and current capabilities. The proposal sets out deliverables, responsibilities, dependencies and acceptance criteria.

Can this connect with other Gardoce services?

Yes. Related advisory, security, architecture and implementation work can be coordinated, with each workstream’s scope and ownership made explicit.

Every engagement starts with a clear scope, agreed responsibilities and practical outcomes.

Start with a conversation

What needs to move
forward in your organisation?

Tell us the decision, risk or operational challenge you are facing. We will help define a sensible next step.

Discuss your priorities