Saturday, July 25, 2026

BSP tells financial firms to prepare for AI-powered cyberattacks

The Bangko Sentral ng Pilipinas (BSP) has urged banks and other supervised financial institutions to strengthen their cybersecurity controls as advanced artificial intelligence systems make cyberattacks faster, more adaptive, and easier to scale.

In Memorandum No. M-2026-034 dated July 6, the central bank warned that frontier AI systems could identify software vulnerabilities, generate methods of exploitation, and execute multi-stage attacks with minimal human intervention.

Although access to these systems remains restricted, the BSP said similar capabilities could eventually be used against financial institutions, third-party service providers, and critical infrastructure.

“Cybersecurity is essential to maintaining trust in the financial system. By encouraging financial institutions to strengthen their cyber defenses and preparedness, we help protect consumers, safeguard financial services, and support confidence in an increasingly digital economy,” BSP deputy governor Lyn I. Javier said.

The memorandum called on BSP-supervised institutions to maintain updated inventories of Internet-facing assets, cloud services, user identities, critical applications, software dependencies, and third-party and open-source components.

Financial institutions were also advised to adopt micro-segmentation and zero-trust security controls, accelerate software patching, replace end-of-life systems, and limit unnecessary internet exposure.

For administrative and privileged accounts, the BSP recommended multi-factor authentication using hardware security keys, smart cards, or hardware-backed certificate-based authentication.

It also advised institutions to discontinue password-only and SMS- or push-based authentication for such accounts because of AI-assisted social engineering risks.

The central bank encouraged the use of AI-powered defensive tools for patch management, continuous threat hunting, exposure management, and security orchestration.

It also recommended virtual patching to block potential attack paths while underlying software is being updated.

Banks and other financial institutions were told to review their business continuity and incident response plans to prepare for disruptions caused by AI-enabled attacks.

The guidance supplements existing BSP rules on information technology and cybersecurity risk management.

Supervised institutions were also advised to develop AI governance frameworks suited to the scale and complexity of their AI systems and overall risk profiles.

- Advertisement -spot_img

RELEVANT STORIES

spot_img

LATEST

- Advertisement -spot_img