Contributor: Raghav Iyer S, Senior IT Security Analyst, ManageEngine
The Philippines’ shift toward digital banking has made financial services more convenient for consumers, but it has also created a security problem that banks cannot solve by protecting their core systems alone.
As more banking activities move online, employees are accessing systems through laptops, desktops and mobile devices from offices, homes and other locations. Each of those devices creates another point that banks need to monitor and secure.
The scale of the country’s digital shift makes the issue harder to ignore.
Digital payments accounted for 57.4% of total monthly retail payment transactions by volume in 2024, up from 52.8% a year earlier, according to the Bangko Sentral ng Pilipinas (BSP). Digital payments also represented 59% of retail payment value.
The numbers show how quickly digital channels have become part of everyday financial activity. They also mean banks are dealing with a much larger digital environment than they were a few years ago.
For cybersecurity teams, that raises a fairly straightforward question: How do you know that every device connecting to the bank is safe?
Attackers don’t always need to break into the bank

IMAGE CREDIT: Magnific
A bank’s core infrastructure may have multiple layers of protection. An employee’s laptop may not.
That difference can make endpoints attractive targets.
A phishing message, stolen password or unpatched device can give an attacker an initial foothold. From there, the attacker may try to obtain additional credentials, access sensitive information or move to other parts of the network.
Ransomware and malware remain familiar threats, while social engineering continues to exploit one of the hardest things for any security system to control: human behavior.
The amount of compromised information circulating online also adds to the problem. PwC reported that more than 52 million personal credentials were exposed through data breaches during the third quarter of 2025.
Not every compromised credential will lead to a successful attack. But for banks, even a small number of successful account compromises can result in financial losses, operational disruption and damage to customer trust.
That is why endpoint security needs to be considered alongside the protection of banking applications, networks and databases.
Knowing the device matters
Banks have also been strengthening how they authenticate users as digital transactions become more sophisticated.
The BSP has been looking at stronger authentication methods, including biometrics and device-bound passkeys, particularly as the limitations of SMS-based one-time passwords become more apparent for higher-risk transactions.
Authentication, however, is only one part of the picture.
A bank may be able to establish that a particular employee is attempting to access a system. It also needs to know whether the device being used is properly secured.
Is the operating system up to date? Are security patches installed? Is the device encrypted? Does it comply with the bank’s policies? Has anything unusual been detected on it?
Those details can be difficult to track when endpoint management and cybersecurity are handled through separate systems.
For large banks with thousands of devices, the problem becomes one of visibility as much as technology.
One view of the endpoint environment

IMAGE CREDIT: Magnific
This is where unified endpoint security comes in.
The approach brings device management and security functions closer together, giving IT and cybersecurity teams a more complete view of the devices connected to an organization’s environment.
The idea is fairly practical: instead of discovering a problem only after an incident, security teams should be able to identify vulnerable or non-compliant devices before they become a bigger issue.
Raghav Iyer S, Senior IT Security Analyst at ManageEngine, argues that this type of visibility is becoming increasingly important for financial institutions as their digital environments expand.
ManageEngine offers endpoint management and security capabilities through its Endpoint Central platform, including vulnerability management, patching, security configuration and threat response. The company says its platform is designed to bring these functions together rather than requiring IT and security teams to manage them separately.
For banks, the attraction is less about having another dashboard and more about being able to answer basic security questions quickly.
If a vulnerability affects thousands of devices, for example, security teams need to know which devices are affected and how quickly they can be patched.
If a device begins behaving suspiciously, they need to be able to identify it and determine whether it should remain connected to the network.
That becomes much harder when information is scattered across different systems.
Remote work adds another layer

IMAGE CREDIT: Magnific
The traditional idea of a corporate security perimeter has also become less useful.
Bank employees do not necessarily work from a branch or corporate office every day. Remote and hybrid arrangements mean devices can connect to financial systems from outside the traditional workplace.
Cloud applications and mobile devices add another layer to the environment.
Security controls therefore have to work wherever employees are working, without making the systems so cumbersome that people start looking for ways around them.
That balance matters.
A security policy that employees cannot realistically follow can create a different kind of risk. The objective should be to make secure behavior the easier option while maintaining the controls banks need around sensitive systems and information.
Security teams can’t rely on periodic checks
Another challenge is that an endpoint can change between security reviews.
A device that was fully patched and compliant during an audit may be missing an update weeks later. A previously trusted application may become compromised. A new vulnerability may emerge after the last security assessment.
That makes continuous monitoring increasingly important.
For banks, endpoint information can provide security teams with a running picture of device health and compliance rather than a snapshot taken during an audit.
Automation can also help.
Routine work such as deploying patches, checking configurations and enforcing policies can consume significant amounts of an IT team’s time. Automating some of these tasks allows security professionals to spend more time investigating suspicious activity and dealing with incidents that require human judgment.
Why this matters beyond the IT department
Endpoint security may sound like an internal technology issue, but the consequences can reach customers.
A compromised employee device can potentially expose sensitive information. A ransomware attack can disrupt services. Weak security controls can create compliance problems. And a major breach can undermine confidence in a bank even after the technical problem has been fixed.
For Philippine financial institutions, that makes endpoint security part of a much bigger conversation about operational resilience.
The country’s rapid adoption of digital payments is unlikely to reverse. The BSP’s latest figures already show that digital channels account for more than half of retail payment activity.
The challenge now is keeping pace with the security demands that come with that growth.
For ManageEngine, that means giving endpoint security a more prominent place in the way banks approach cybersecurity.
For banks more broadly, the lesson is simpler: protecting digital banking does not end with securing the systems customers see. It also means paying attention to the devices and people connecting to those systems every day.
