iwantcoding.com
🔥 Daily 👥 Rooms 🏆 Top Log in Sign up

8.4 Financial Sector Security

Financial systems are the highest-value cyber targets in the country. Engineers building or integrating with them must respect BSP, AMLC, NPC, and PCI DSS regimes. This lesson maps the major obligations and the threats they were written to stop.

Threat Landscape

ThreatTypical VectorLoss Driver
Phishing / SmishingSMS or email impersonating bankAccount takeover
SIM swapTelco social engineeringOTP interception
Card skimmingCompromised POS or ATMCard-present fraud
BECSpoofed executive emailWire fraud
Cash-out via mulesStolen e-wallet credentialsFunds out of system
Insider abuseBank employee with privilegesDirect embezzlement

Major Regulatory Anchors

RegulationScopeEngineer Impact
BSP Circular 982Cybersecurity for BSP-supervised institutionsRisk-based controls, board reporting
BSP Circular 1140Operational Risk ManagementResilience, DR, third-party risk
BSP IT Risk MgmtAll BSFIsAnnual IT risk assessment
AMLA (RA 9160) and IRRKYC, suspicious transactionsOnboarding, SAR pipeline
Data Privacy Act (RA 10173)Personal dataConsent, breach notification
PCI DSS 4.0Card dataEncryption, tokenization, segmentation
RA 11765Financial Products and Services Consumer ProtectionDisclosure, complaint handling

Core Controls Engineers Must Build

  1. **Strong customer authentication** - device binding, OTP, biometric, transaction signing.
  2. **Velocity and anomaly checks** - rules and ML for unusual transfers.
  3. **Tamper-evident logging** - signed audit trail of every privileged action.
  4. **Segregation of duties** - maker-checker on movement of funds.
  5. **Tokenization** - never store raw PAN in your DB.
  6. **Time-bounded sessions** - especially on mobile apps.
  7. **Mandatory breach drill** - tabletop at least annually, technical exercise quarterly.

Discussion

Loading…