Integrated Cybersecurity Capability Maturity Assessment Across Ten Domains Using C2M2 V2.1 in the Digital Banking Sector
Authors
| Issue | Vol. 1 No. 1 (2025) |
| Published | 7 August 2026 |
| Section | Articles |
Abstract
The rapid adoption of digital banking and public cloud infrastructure has significantly increased the cybersecurity exposure of financial institutions, particularly through application programming interface (API) vulnerabilities, privileged-access weaknesses, third-party dependencies, and inadequate protection of backup data. Conventional compliance audits generally rely on binary assessments and therefore provide limited insight into the institutional maturity and consistency of cybersecurity practices. This study evaluates the cybersecurity capability maturity of PT Bank Finansial Digital (BFD) across ten cybersecurity domains using the Cybersecurity Capability Maturity Model (C2M2) Version 2.1. A hybrid maturity-to-compliance assessment approach was applied by integrating the C2M2 evaluation results with the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) Version 1.1, NIST Privacy Framework 1.1, and Indonesian Law No. 27 of 2022 concerning Personal Data Protection. The assessment was conducted using the official C2M2 HTML-Based Self-Evaluation Tool based on organizational documentation and technical configuration evidence as of May 23, 2026. The results show that seven of the ten assessed domains achieved Maturity Indicator Level 2 (MIL 2), whereas ACCESS, RESPONSE, and THIRD-PARTIES remained at MIL 1. Ten critical capability gaps classified as Partially Implemented were identified, with the RESPONSE domain representing the most significant weakness. Major findings included the absence of centralized privileged access management and multi-factor authentication, incomplete assessment of cloud sub-vendors, insufficiently formalized incident escalation procedures, outdated cloud incident-response procedures, and disabled encryption for data at rest in the Network-Attached Storage backup environment. These deficiencies potentially increase operational, privacy, regulatory, and reputational risks. A six-month remediation roadmap consisting of technical hardening, policy formalization, and crisis validation is therefore proposed to support the organization in achieving a consistent MIL 2 maturity level.
Keywords: C2M2 V2.1, Cybersecurity Maturity, Digital Banking, NIST CSF, NIST Privacy Framework, Personal Data Protection
