Complying with the TCRMG in Cambodia

How Thales Helps with the NBC’s Technology and Cyber Risk Management Guidelines (TCRMG) Compliance in Cambodia

What are the Technology and Cyber Risk Management Guidelines (TCRMG) in Cambodia?

The Technology and Cyber Risk Management Guidelines (TCRMG) issued by the National Bank of Cambodia (NBC) are a set of regulatory standards that require banks and financial institutions (BFIs) in Cambodia to strengthen their technology risk and cybersecurity posture across governance, operations, and resilience. The latest version, released in 2025, replaces the 2019 version and explicitly introduces “technology risk” and “cyber risk” into a single, mandatory, assessable framework for BFIs.

APAC

    Help BFIs identify, assess, monitor, and mitigate operational, regulatory, and cyber risks arising from digital channels, IT infrastructure, third party vendors, and cloud services. 

    Apply to all licensed Banking and Financial Institutions (BFIs) in Cambodia and expects controls to be proportionate to the complexity and risk profile of each institution.

    COMPLIANCE BRIEF

    Complying with the Technology and Cyber Risk Management Guidelines in Cambodia

    Learn how Thales enables organisations in Cambodia to address the TCRMG requirements in five of the chapters.

    Get the Compliance Brief

    How Thales Help with The Technology and Cyber Risk Management Guidelines in Cambodia

    Thales’ solutions can help organizations address the requirements in five of the chapters by simplifying compliance and automating security with visibility and control, reducing the burden on security and compliance teams.

    TCRMG Compliance Solutions

    TCRMG Compliance Solutions

      Application Security

      Protect applications and APIs at scale in the cloud, on-premises, or in a hybrid model. Our market leading product suite includes Web Application Firewall (WAF), protection against Distributed Denial of Service (DDoS) and malicious BOT attacks, and security for APIs.

      Data Security

      Discover and classify sensitive data across hybrid IT and automatically protect it anywhere, whether at rest, in motion, or in use, using encryption tokenization and key management. Thales solutions also identify, evaluate, and prioritize potential risks for accurate risk assessment as well as identify anomalous behavior, and monitor activity to verify compliance, allowing organizations to prioritize where to spend their efforts.

      Identity & Access Management

      Provide seamless, secure and trusted access to applications and digital services for customers, employees and partners. Our solutions limit the access of internal and external users based on their roles and context with granular access policies and Multi-Factor Authentication that help ensure that the right user is granted access to the right resource at the right time.

      Address the TCRMG requirements

        How Thales helps:

        • Classify and assign specific sensitivity levels for data when you are defining your data stores and your classification profiles for different types of data sets.
        • Identify the current state of compliance and document gaps.
        • Discover and classify potential risk for all public, private and shadow APIs.
        • Provide data activity monitoring for structured and unstructured data across cloud and on-prem systems.

        How Thales helps:

        • Safeguard critical network assets from DDoS attacks and Bad Bots while continuing to allow legitimate traffic.

        Solutions:

        Application Security

        DDoS Protection

        How Thales helps:

        • Manage authentication and access control by supporting Multi-Factor Authentication and displaying access log reports.
        • Set up access control policies based on user roles, responsibilities, and risks with Adaptive Access Control.
        • Protect personal data from unauthorized access, monitor what has been changed and who is accessing.
        • Centralize authentication and policy enforcement for cloud access scenarios, helping organizations apply consistent access controls.
        • Provide ongoing monitoring of database traffic, monitoring who the users are accessing them, and provide timely alerts.
        • Protect the root-of-trust of a cryptographic system within a highly secure environment.
        • Pseudonymize sensitive data once it is created and make sure cleartext data will not be processed or stored by unauthorized and to prevent exposure of real data applications and personnel.
        • Protect sensitive data with real-time alerting or user access blocking of policy violations.
        • Protect data in motion with high-speed encryption.

        How Thales helps:

        • Limit access to systems and data based on roles and context with policies.
        • Apply contextual security measures based on risk scoring.
        • Enable continuous monitoring to capture and analyze all data store activity, providing detailed audit trails that show who accesses what data, when, and what was done to the data.
        • Offer the separation of duties between the security administrator and the system administrator inside servers, ensuring the system admins or privileged accounts do not have access to sensitive encryption keys, while the security administrators do not have access to the data.
        • Centralize access policies and enforcement to multiple hybrid environments in a single pane of glass.
        • Enable a consistent and policy-driven approach to identification, authentication, and authorization of all users to their IT assets, data, and services.
        • Manage all users, including the workforce, contractors, third-party users such as customers, suppliers, logistics, and B2B or B2C type users.
        • Offer “least privilege” access rights where the minimum sufficient permissions are granted to legitimate users.
        • Adopt robust user authorization and authentication based on the criticality of IT assets by defining the right access policies, step-up authentication, and enforcing phishing-resistant authenticators.

        How Thales helps:

        • Support cryptography algorithms such as Advanced Encryption Standard (AES) 256bits, RSA 3072 bits, and are designed for a post-quantum upgrade to maintain crypto-agility.
        • Manage encryption keys, provide granular access control and configure security policies.
        • Centralize key lifecycle management, including generation, rotation, destruction, import, and export.
        • Ensure secure deletion by removing keys from CipherTrust Manager, digitally shredding all instances of the data.
        • Protect cryptographic keys in a FIPS 140-3 Level 3 environment.
        • Easily back up and duplicate sensitive cryptographic keys securely to the FIPS 140-3 Level 3 certified backup HSM.
        • Manage and protect all secrets and sensitive credentials.
        • Protect data in motion with high-speed encryption.

        How Thales helps:

        • Classify and assign specific sensitivity levels for data when you are defining your data stores and your classification profiles for different types of data sets.
        • Identify the current state of compliance and document gaps.
        • Provide data activity monitoring for structured and unstructured data across cloud and on-prem systems.
        • Monitor data access activity over time to set up alerts on activity that can put financial institutions at risk.
        • Detect and report non-compliant, risky, or malicious data access behavior across all your data repositories enterprise-wide to accelerate remediation.
        • Categorize and prioritize by real risks with risk scoring rather than anomalies.
        • Adopt transparent and continuous encryption that protects sensitive data.
        • Securely manage encryption keys for on-premises FDE storage.
        • Ensure secure deletion by removing keys from CipherTrust Manager, digitally shredding all instances of the data.

        How Thales helps:

        • Identify the current state of compliance and document gaps.
        • Encrypt data at rest on-premises, across clouds, and in big data or container environments.
        • Pseudonymize sensitive data once it is created and make sure cleartext data will not be processed or stored by unauthorized and to prevent exposure of real data applications and personnel.
        • Protect the root-of-trust of a cryptographic system within FIPS140-3 Level 3 - a highly secure environment.
        • Protect data in motion with high-speed encryption. $Protect data in use by leveraging confidential computing.
        • Examine application and database traffic automatically to create a profile of baseline normal activity.
        • Gain full sensitive data activity visibility, track who has access, audit what they are doing and document.
        • Pinpoint risky data access activity for all users, including privileged users.
        • Protect data with real-time alerting or user access blocking of policy violations.

        How Thales helps:

        • Deploy MFA to ensure proper customer authentication and authorization when changing transaction limits or performing other sensitive account activities.
        • Deploy MFA, leveraging FIDO authentication, strong device binding, transaction signing, risk-based authentication, and cryptographic protections (e.g. Run-time Application Self-Protection) throughout the authentication execution.
        • Provide FIDO authentication that validates the authenticity of the website domain during the login process, ensuring that customers are interacting only with the genuine financial institution site and preventing credential phishing or redirection attacks.
        • Support time-bound OTP generation that aligns with OATH/OCRA standard.
        • Deploy OTP that is cryptographically bound to specific transaction details (transaction signing), ensuring that it can only be used for the intended transaction.
        • Perform all transactions and data exchanges over TLS minimally, with additional end-to-end encryption layer for sensitive information, such as user’s key and/or password.
        • Encrypt all sensitive data at both client and host applications prior to transmission using AES-256 or equivalent encryption standards.
        • Implement mutual TLS to authenticate the connection between endpoints and the server that hosts the solution.
        • Deliver high security efficacy by blocking threats such as SQL injection, XSS, and other OWASP Top 10 vulnerabilities with WAF.
        • Safeguard critical network assets from DDoS attacks and Bad Bots while continuing to allow legitimate traffic.
        • Provide instant protection against both volumetric and application-layer DDoS attacks in one solution.
        • Leverage 63 global PoPs to absorb large attacks, avoiding costly hardware or over-provisioning—elastic defense scales automatically.

        How Thales helps:

        • Provide robust customer authentication and identity verification processes, including multi-factor authentication (MFA) for activation of digital services, passive liveness that is compliant to iBETA PAD Level 2.
        • Support time-bound OTP generation that aligns with OATH/OCRA standard.
        • Deploy strong device binding to ensure the user’s credentials or cryptographic keys are securely linked to the device.
        • Identify behavioral or anomaly detection mechanisms, events such as new device access or unusual location changes, triggering immediate customer notification or further verification actions from the Bank’s resource.
        • Enable MFA validation for registering a new or replacement mobile number, device change, or processing personal particulars updates. Additional identity verification or part of KYC procedures may be applied when necessary to ensure authenticity.
        • Apply systematic risk management controls to detect multiple successive high-volume transactions or abnormal transaction patterns, enabling proactive fraud mitigation.
        • Include secure session handling, automatic timeouts, and protection against session hijacking or replay attacks.
        • Detect and limit repeated failed login or MFA authentication attempts to prevent brute-force and credential-stuffing attacks.
        • Safeguard critical network assets from DDoS attacks and Bad Bots while continuing to allow legitimate traffic.
        • Inspect all traffic, detect and prevent web-based attacks with WAF.
        • Provide a highly secure environment that is resistant to phishing, malware, and man-in-the-middle attacks with a combination of
        • Strong Customer Authentication (SCA), Risk Management solution, FIDO authentication, device binding, and Run-time Application Self-Protection (RASP).
        • Ensure accuracy and reliability in customer authentication through the advanced biometric verification with a low False Acceptance Rate (FAR).

        How Thales helps:

        • FIPS 140-2 Level 3 root of trust for credentials and keys.
        • Support cryptography algorithms such as Advanced Encryption Standard (AES) 256bits, RSA 3072 bits, and are designed for a post-quantum upgrade to maintain crypto-agility.
        • Detect and limit repeated failed login or MFA authentication attempts to prevent brute-force and credential-stuffing attacks.
        • Deploy MFA to ensure proper customer authentication and authorization when changing transaction limits or performing other sensitive account activities.
        • Identify behavioral or anomaly detection mechanisms, events such as new device access or unusual location changes, triggering immediate customer notification or further verification actions from the Bank’s resource.
        • Apply systematic risk management controls to detect multiple successive high-volume transactions or abnormal transaction patterns, enabling proactive fraud mitigation.
        • Adjust access permissions based on real-time or near real-time user behavior and contextual factors.
        • Apply Strong Customer Authentication (SCA) to all financial and high-risk non-financial transactions. It leverages FIDO authentication, biometrics, or OTP-based validation to ensure the authenticity of the user, device, and transaction integrity.
        • Adopt SCA that requires users to review and confirm transaction details (e.g. payee information, amount, and destination account).
        • Offer multiple MFA options that are more secure than SMS OTP, such as OTP/OATH authenticator, FIDO authenticator, and Risk-Based Authentication.
        • Fully support transaction signing, whereby the authentication code is uniquely tied to the confirmed beneficiary and transaction amount.
        • Deploy Mobile Secure Messenger – a secure channel for sending push notifications.

        How Thales helps:

        • Provide a hardened, tamper-resistant environment for secure cryptographic processing, key generation and protection, encryption, and more to address the CSCF requirements.
        • Protect cryptographic keys in a FIPS 140-2 Level 3 environment.

        Solutions:

        Data Security

        Hardware Security Modules

        How Thales helps:

        • Retain full control and ownership of the sensitive data by controlling encryption keys access via Cloud Key Management, negating the risk of data being released to third party with the Hold-Your-Own-Key (HYOK) approach.
        • Secure sensitive data for migration by encrypting data-at-rest on-premises, across clouds, and in big data or container environments.
        • Allow encrypted data to be migrated between different clouds, removing any reliance on specific formats used by different cloud providers; customers are not locked to a single cloud.
        • Ensure secure deletion by removing keys from CipherTrust Manager, digitally shredding all instances of the data.
        • Pseudonymize sensitive information in databases.
        • Enable relationship management with suppliers, partners or any third-party user; with clear delegation of access rights.
        • Minimize privileges by using relationship-based fine-grained authorization.

        How Thales helps:

        • Classify and assign specific sensitivity levels for data when you are defining your data stores and your classification profiles for different types of data sets in the cloud.
        • Provide data activity monitoring for structured and unstructured data across cloud.
        • Secure sensitive data and maintain complete governance and control of sensitive data and the associated encryption keys and policies with Bring-Your-Own-Encryption (BYOE), Hold-Your-Own-Key (HYOK) and Bring-Your-Own-Key (BYOK) approaches, as well as a centralized multi-cloud key management.
        • Offer transparent encryption and access control for data residing.
        • Encrypt sensitive data once it is created and make sure cleartext data will not be processed or stored by unauthorized applications and personnel.
        • Allow root users to do their job without abusing data by privileged user access controls.
        • Accelerate threat detection and ease forensics with data access audit logging.
        • Employ strong, standards-based encryption protocols, such as the Advanced Encryption Standard (AES) for data encryption and Elliptic Curve Cryptography (ECC) for key exchange.
        • Simplify key management across on-premises and multi-cloud deployments by centralizing control on the FIPS140-2 Level 3 environment.
        • Employ a Role-Based Access Control (RBAC) to control access to Hardware Security Modules (HSMs) and broader key management systems to ensure that only authorized personnel can perform specific administrative or cryptographic tasks, maintaining a strict separation of duties.
        • Enable relationship management with suppliers, partners or any third-party user; with clear delegation of access rights.
        • Minimize privileges by using relationship-based fine-grained authorization.

        How Thales helps:

        • Monitor API activity, track usage, detect anomalies, and identify potential unauthorized access attempts.
        • Offer advanced API Verification capabilities to strengthen your defenses against potential vulnerabilities.
        • Safeguard your login endpoints from credential stuffing, brute force attacks, and account fraud.
        • Detect and prevent cyber threats with web application firewall, ensuring seamless operations and peace of mind.
        • Enable complete visibility and help in singling out enterprise-wide attack campaigns.

        How Thales helps:

        • Offer FIPS 140-2 Level 3 root of trust for credentials and keys.
        • Provide future-proof and standardize quantum-safe digital signature algorithms.
        • Generate digital signatures seamlessly using standardized quantum-safe public key cryptography and includes key management capabilities for stateless and stateful key types, complying with SP 800-208 requirements.
        • Manage seeds and private keys securely with HSMs.
        • Access to these HSMs is tightly controlled, with strong multi-factor authentication and detailed audit trails for all operations.
        • Secure sensitive data and critical applications by storing, protecting, and managing cryptographic keys – high assurance, tamper-resistant, network-attached appliances offering market-leading performance.
        • Backup easily and duplicate keys securely for compliance as well as safekeeping in case of emergency, failure or disaster.

        Solutions:

        Data Security

        Hardware Security Modules

        How Thales helps:

        • Pseudonymize sensitive data once it is created and make sure cleartext data will not be processed or stored by unauthorized and to prevent exposure of real data applications and personnel.
        • Utilize Hardware Security Modules (HSMs) with FIPS 140-2 Level 3 validation as the root of trust.
        • Secure access to decrypted data across environments due to centralized management.
        • Maintain control in the cloud and cloud providers never have access to token vaults or keys.

        Solutions:

        Data Security

        Hardware Security Modules

        Tokenization

        Other key data protection and security regulations

        PCI HSM

        Global

        MANDATE | ACTIVE NOW

        The PCI HSM specification defines a set of logical and physical security compliance standards for HSMs specifically for the payments industry. PCI HSM Compliance certification depends on meeting those standards.

        DORA

        Global

        REGULATION | ACTIVE NOW

        DORA aims to strengthen the IT security of financial entities to make sure the financial sector in Europe is resilient in the face of the growing volume and severity of cyber-attacks.

        Data Breach Notification Laws

        Global

        REGULATION | ACTIVE NOW

        Data breach notification requirements following loss of personal information have been enacted by nations around the globe. They vary by jurisdiction but almost universally include a “safe harbor” clause.

        GLBA

        Americas

        REGULATION | ACTIVE NOW

        The Gramm-Leach-Bliley Act (GLBA)--also known as the Financial Services Modernization Act of 1999--requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data.

        Contact a Compliance Specialist

        Contact Us