Financial institutions are not short on cybersecurity policies, frameworks, or regulatory requirements. Turning those requirements into a living risk management program can be challenging. Organizations need a program that can keep pace as technology environments expand, cloud adoption grows, third parties are added, and external exposures change. Especially as the threat landscape continues to evolve.
Bank Negara Malaysia’s current Risk Management in Technology, or RMiT, Policy Document reflects that reality. Issued and effective on 28 November 2025, it establishes minimum requirements for managing technology and cyber risk across governance, technology operations, cybersecurity, digital services, third-party service providers, cloud services, audit, assurance, and gap analysis. It also makes clear that larger, more complex, highly digitalized, or highly interconnected institutions are expected to adopt more robust controls proportionate to their exposure.
Bitsight can help financial institutions operationalize several of these expectations by providing continuous, outside-in visibility into their cybersecurity posture and the broader digital and third-party ecosystem around them. Institutions still need to enforce controls, policies, security operations, internal testing, and regulatory responsibilities. Bitsight provides an intelligence and measurement layer that can help teams identify risk, prioritize action, monitor change, and communicate progress.
RMiT raises the bar for continuous monitoring
Traditional technology risk programs often rely heavily on periodic reviews. An organization completes an assessment, collects documentation, records the results, and repeats the process later. Those activities remain important, but they cannot show what happens between assessments. Threats don't wait for assessment intervals. By the time the next formal assessment takes place, the organization’s actual exposure may look very different. As vendors and technology continue to evolve, it is vital to ensure your security posture evolves with those changes.
RMiT requires financial institutions to include continuous monitoring within their Technology Risk Management Framework so material risks can be detected and addressed in a timely manner. It also requires institutions to maintain an accurate, up-to-date technology risk profile. This requires more than policies and questionnaires. It requires objective information that can be monitored over time and used to determine when risk has moved outside established tolerance.
Turning cyber risk into measurable governance
Boards and senior management need to understand what has changed, why it matters, whether the organization remains within its risk appetite, and what is being done about it. Under RMiT, the board must establish and approve the institution’s technology risk appetite and corresponding tolerances. It must also receive regular updates on technology risk and cyber threats, while senior management remains responsible for the day-to-day management of technology and cyber risk.
Bitsight’s outside-in security performance data, risk vectors, trends, benchmarks, and reporting can help translate externally observable cybersecurity risk into a view that is easier for risk committees, executives, and board members to understand.
Financial institutions can use these insights to track areas such as:
- Changes in their externally observable security posture
- Critical internet-facing vulnerabilities
- New or previously unknown external assets
- Severe findings that remain unresolved beyond remediation targets
- The percentage of critical vendors outside established risk tolerances
- Material changes across cloud and customer-facing digital infrastructure
These metrics cannot set the institution’s risk appetite or make risk acceptance decisions but they are able to provide evidence that can help leadership understand where risk lies, and how to anticipate threats.
Improving visibility across the external attack surface
It is difficult to manage technology risk without an accurate understanding of the environment being protected. Cloud adoption, subsidiaries, mergers and acquisitions, developer infrastructure, outsourced hosting, third-party services, and shadow IT can all create assets that sit outside traditional internal inventories. RMiT requires institutions to establish controls for shadow IT and ensure that systems, including digital services, are not operating with known vulnerabilities, outdated platforms, or end-of-life technology. It also requires continuous monitoring and timely implementation of security patches. Bitsight Security Posture Management (SPM) combines external attack surface management, threat intelligence, and governance reporting to help organizations discover, prioritize, mitigate, govern, and communicate risk across their digital infrastructure. SPM can provide visibility across assets, subsidiaries, cloud environments, and third parties while applying threat and business context to support prioritization.
This outside-in perspective can help institutions:
- Confirm their externally visible digital footprint
- Identify assets that may not appear in internal inventories
- Detect exposed services and externally observable vulnerabilities
- Find outdated software and security configuration weaknesses
- Prioritize exposures using threat and business context
- Track whether remediation is improving external security posture
External attack surface intelligence should complement authenticated vulnerability scanning, internal asset inventories, configuration management databases, endpoint telemetry, cloud-native tools, and system-owner validation. It does not replace them.