2026-02-16 | CRMD Circular Letter No. 01Added · Updated
The strategy establishes a five-year framework for SBP regulated entities to strengthen cyber resilience through five strategic priorities: Strengthen, Mature, Enhance, Develop, and Evolve. It mandates the development of a cyber-testing framework, the implementation of a risk-based cybersecurity maturity assessment, and the creation of a standardized IT/cyber incident reporting framework. The document requires regulated entities to enhance disaster recovery plans, improve cybersecurity governance including CISO roles, and establish a threat intelligence sharing platform leading to the creation of FinCERT. Additionally, it outlines actions to mature financial market infrastructures with a two-hour recovery time objective and develop a cyber workforce competency roadmap.
More like this from SBP
SBP published 6 documents in the last 30 days. We email you each new one the day it's published.