The Technology and Cyber Risk Management Guidelines (TCRMG) issued by the National Bank of Cambodia (NBC) are a set of regulatory standards that require banks and financial institutions (BFIs) in Cambodia to strengthen their technology risk and cybersecurity posture across governance, operations, and resilience. The latest version, released in 2025, replaces the 2019 version and explicitly introduces “technology risk” and “cyber risk” into a single, mandatory, assessable framework for BFIs.
Help BFIs identify, assess, monitor, and mitigate operational, regulatory, and cyber risks arising from digital channels, IT infrastructure, third party vendors, and cloud services.
Apply to all licensed Banking and Financial Institutions (BFIs) in Cambodia and expects controls to be proportionate to the complexity and risk profile of each institution.
Learn how Thales enables organisations in Cambodia to address the TCRMG requirements in five of the chapters.
Thales’ solutions can help organizations address the requirements in five of the chapters by simplifying compliance and automating security with visibility and control, reducing the burden on security and compliance teams.
TCRMG Compliance Solutions
Protect applications and APIs at scale in the cloud, on-premises, or in a hybrid model. Our market leading product suite includes Web Application Firewall (WAF), protection against Distributed Denial of Service (DDoS) and malicious BOT attacks, and security for APIs.
Discover and classify sensitive data across hybrid IT and automatically protect it anywhere, whether at rest, in motion, or in use, using encryption tokenization and key management. Thales solutions also identify, evaluate, and prioritize potential risks for accurate risk assessment as well as identify anomalous behavior, and monitor activity to verify compliance, allowing organizations to prioritize where to spend their efforts.
Provide seamless, secure and trusted access to applications and digital services for customers, employees and partners. Our solutions limit the access of internal and external users based on their roles and context with granular access policies and Multi-Factor Authentication that help ensure that the right user is granted access to the right resource at the right time.
Data Security
Identity & Access Management
Data Security
Data Security
Identity & Access Management
Application Security