8.4 Financial Sector Security
Financial systems are the highest-value cyber targets in the country. Engineers building or integrating with them must respect BSP, AMLC, NPC, and PCI DSS regimes. This lesson maps the major obligations and the threats they were written to stop.
Threat Landscape
| Threat | Typical Vector | Loss Driver |
|---|---|---|
| Phishing / Smishing | SMS or email impersonating bank | Account takeover |
| SIM swap | Telco social engineering | OTP interception |
| Card skimming | Compromised POS or ATM | Card-present fraud |
| BEC | Spoofed executive email | Wire fraud |
| Cash-out via mules | Stolen e-wallet credentials | Funds out of system |
| Insider abuse | Bank employee with privileges | Direct embezzlement |
Major Regulatory Anchors
| Regulation | Scope | Engineer Impact |
|---|---|---|
| BSP Circular 982 | Cybersecurity for BSP-supervised institutions | Risk-based controls, board reporting |
| BSP Circular 1140 | Operational Risk Management | Resilience, DR, third-party risk |
| BSP IT Risk Mgmt | All BSFIs | Annual IT risk assessment |
| AMLA (RA 9160) and IRR | KYC, suspicious transactions | Onboarding, SAR pipeline |
| Data Privacy Act (RA 10173) | Personal data | Consent, breach notification |
| PCI DSS 4.0 | Card data | Encryption, tokenization, segmentation |
| RA 11765 | Financial Products and Services Consumer Protection | Disclosure, complaint handling |
Core Controls Engineers Must Build
- **Strong customer authentication** - device binding, OTP, biometric, transaction signing.
- **Velocity and anomaly checks** - rules and ML for unusual transfers.
- **Tamper-evident logging** - signed audit trail of every privileged action.
- **Segregation of duties** - maker-checker on movement of funds.
- **Tokenization** - never store raw PAN in your DB.
- **Time-bounded sessions** - especially on mobile apps.
- **Mandatory breach drill** - tabletop at least annually, technical exercise quarterly.
Discussion
Loading…