Skip to content
Client access

Compliance

SBS Resolution No. 504-2021: what it means for your cybersecurity program

Peru’s SBS regulation on information security and cybersecurity requires a management system backed by evidence that controls work. What it requires, who it applies to and where technical testing fits.

Kamaya Secure team 5 min read

SBS Resolution No. 504-2021 approved Peru’s Regulation for Information Security and Cybersecurity Management, issued by the Superintendency of Banking, Insurance and Private Pension Funds (SBS). It took effect on July 1, 2021 and replaced Circular G-140-2009, which for more than a decade had been the information security reference for Peru’s financial system.

The underlying shift is clear: the regulation moves away from “controls in place” and requires a management system that periodically shows those controls are effective against real threats. For banks, finance companies, municipal and rural savings banks, insurers, pension fund managers and e-money issuers, that has concrete consequences for budget, governance and operations.

Key takeaways

  • The regulation requires an SGSI-C (Information Security and Cybersecurity Management System) proportional to the company’s size and complexity.
  • It defines three regimes: general, simplified and reinforced, depending on the type of entity and its market relevance.
  • It calls for a cybersecurity program based on an international framework, reporting of significant incidents to the SBS and strong authentication on digital channels.
  • Periodic internal and external assessments and testing are how a company shows its SGSI-C actually works.

Who it applies to

The regulation distinguishes three regimes (Article 4):

RegimeEntitiesWhat it involves
GeneralBanks, finance companies, municipal and rural savings banks, pension fund managers, card and e-money issuers, cash-in-transit companies, Banco de la Nación and insurers with average assets of PEN 450 million or moreFull SGSI-C, cybersecurity program, authentication and third-party rules
SimplifiedInvestment banks, EDPYMEs, money transfer companies, COFIDE, Fondo MIVIVIENDA, Banco Agropecuario, surety companies, benefit funds and smaller insurersMinimum activities, performed at least annually
ReinforcedCompanies subject to an additional capital requirement for market concentrationAll of the above, plus a designated board member and an independent assessment of the SGSI-C

A general-regime company facing material limitations can ask the SBS to apply the simplified regime, supported by its size and complexity.

What it requires, in five blocks

1. Governance and responsibilities

The board approves the SGSI-C policies, resources and organization (Article 5). The risk committee —or a specialized information security and cybersecurity committee— approves the strategic plan and the training plan (Article 7). The company must have an information security and cybersecurity function and a multidisciplinary incident handling team with representatives from legal, technical and organizational areas (Article 8).

2. Minimum security measures

Article 12 lists the minimum measures: personnel security, physical and logical access control based on least privilege, operations security (including preventing the exploitation of vulnerabilities), communications security and network segregation, secure development with security testing before go-live, incident management, physical security, cryptography and information asset management.

For incident management, it explicitly requires a security operations service with detection and response capabilities, plus access to threat intelligence and knowledge bases on attacker techniques and tactics.

3. Cybersecurity program

Every company with a presence in cyberspace must maintain a permanent cybersecurity program (Article 14), with an assessment and an improvement plan based on an international reference framework that covers, at a minimum, identification, protection, detection, response and recovery. In practice, many entities choose the NIST Cybersecurity Framework, whose functions match that structure, complemented by ISO/IEC 27001 for the management system.

4. Incidents and authentication

  • Cybersecurity incidents with a significant adverse impact —information loss, fraud, reputational damage or service disruption— must be reported to the SBS as soon as they are identified, and the company must carry out a forensic analysis whose report remains available to the supervisor (Article 15).
  • Digital channel transactions involving payments, transfers to third parties or beneficiary registration require strong authentication, with independent factors and a cryptographically generated authentication code (Article 19).

5. Third parties, cloud and APIs

Outsourcing IT, security or data processing services requires assessing the provider’s threats and vulnerabilities and setting its responsibilities by contract (Article 22). Cloud services require specific policies, and certifications such as ISO/IEC 27001, 27017 and 27018 or a SOC 2 Type 2 report are taken as references (Articles 23 and 24). APIs that expose services to third parties must include, among other measures, secure development, code review and vulnerability assessments and penetration testing (Article 21).

Where technical testing fits

The regulation is not a one-time checklist. Article 13 requires the SGSI-C to undergo periodic assessments, reviews and tests to determine its effectiveness, through internal and external services, according to its level of complexity and the threats it faces. In practical terms:

RequirementTechnical evidence that supports it
Prevent exploitation of vulnerabilities (Art. 12)Vulnerability management and periodic penetration testing with retesting
Security testing before go-live (Art. 12)Application pentesting and source code review
Detection and response by the security operations service (Art. 12)Red Team or Purple Team exercises that measure detection times
Security of third-party-facing APIs (Art. 21)API pentesting and review of secure coding practices
Third-party risk (Art. 22)Technical assessments of services provided by third parties
Independent assessment under the reinforced regime (Art. 27)Assessment by an independent team with experience and international certifications

The supervisor’s question is not whether the company has a firewall or a SOC, but how it knows they work. Documented technical testing is that answer.

Common mistakes in achieving compliance

  • Treating the regulation as a documentation project rather than a system that is tested and improved.
  • Choosing an international framework on paper without the initial assessment required by Article 14.
  • Hiring pentests with minimal scopes that leave out digital channels, APIs and critical providers.
  • Not defining in advance what counts as a “significant incident” and how it is reported to the SBS.
  • Leaving fixed vulnerabilities without retesting: without verification, a fix is not evidence.

How we can help

At Kamaya Secure we combine regulatory assessment with technical testing: gap analysis against the regulation, cybersecurity program design, pentesting of applications, APIs and digital channels, and Red Team exercises that produce evidence useful to the risk committee and the supervisor. Learn more about our Compliance & Risk Management service and how we work with Banking & Fintech.

Informational article based on the text of SBS Resolution No. 504-2021 published by the SBS, including the amendments of SBS Resolution No. 1515-2021. Article titles and terms are our own translation of the Spanish original. This is not legal advice. Before making compliance decisions, check for later amendments and validate your case with your legal team.

Insights

More insights

OT/ICS

IT/OT segmentation in mining: where to start

The convergence of corporate and industrial networks opens paths an attacker can exploit. A six-step roadmap to bring order with IEC 62443 without stopping operations.

Kamaya Secure logo on an office wall

Want to apply this in your organization?

Tell us where you are today. Our team will help you define the right scope and next steps, with no commitment.

Chat on WhatsApp (opens in a new tab)