NBU Compliance — Cybersecurity for the Ukrainian Financial Sector

NBU Compliance Services.
We help banks, fintechs, and financial institutions meet the requirements of the National Bank of Ukraine. We work with NBU Regulations № 1, 73, 95, 99, 143, and 178 — from gap analysis to full implementation and audit readiness.

Cybersecurity Governance
Cybersecurity Governance

2009

since then, we have been continuously improving our skills and expertise, evolving into highly skilled cybersecurity professionals.

500+

successfully completed large-scale projects in the realm of cybersecurity.

200+

thrilled clients who have experienced our services and have full confidence in us. 

20+

a squad of exceptionally skilled professionals specializing in information security and technical audits. We are not big, but robust and friendly. 

NBU Regulations We Work With:

NBU Regulation № 95 — Information Security Management System for Banks

The foundational regulation governing information security in Ukrainian banks. Defines requirements for an ISMS aligned with ISO 27001 principles — risk management, controls, governance, monitoring.

NBU Regulation № 99 — Cloud Services for Banks


Cybersecurity Architecture Development and Review

Regulates how banks may use cloud providers (AWS, Azure, GCP). Covers risk assessment of vendors, data classification, contractual safeguards, and ongoing monitoring of cloud security.

NBU Regulation № 73 — Operational Risk Management


Cybersecurity Governing Documents Development

Cybersecurity Governing Documents Development

Sets requirements for managing operational risk (including cyber risk) in banks. Covers risk identification, assessment methodology, risk register, business continuity, and reporting to NBU.

NBU Regulation № 143 — Cybersecurity for the Non-Banking Financial Sector


ISO Implementation

Extends cybersecurity requirements to non-banking financial institutions — insurance companies, payment systems, credit unions, and others under NBU supervision. Aligns with bank-level expectations.

NBU Regulation № 178 — External Assessments and Incident Reporting

Defines requirements for periodic external cybersecurity assessments and procedures for reporting cyber incidents to NBU. Covers timing, scope, and notification thresholds.

NBU Regulation № 1 — Bank ID Security

Sets cybersecurity requirements for the Ukrainian BankID electronic identification system — protection of identity data, authentication standards, and integration security for participating institutions.

Cybersecurity Training Program Development and Delivery

Our team is skilled in designing and delivering tailor-made training and awareness materials for your staff, focusing on specific cybersecurity issues.

Cybersecurity Awareness Phishing Campaigns

Cybersecurity Awareness Phishing Campaigns


Cybersecurity Awareness Phishing Campaigns


We conduct comprehensive Phishing/Vishing campaigns to raise awareness and ensure your organization is prepared for such threats.

Virtual CISO Services


Virtual CISO Services

Virtual CISO Services



We offer Virtual CISO services, providing leadership and guidance in establishing or maintaining a security vision, strategy, and program. Our aim is to align your security compliance, architecture, and governance to help your organization manage business risk effectively.

weProvide-icon
audit3a Cybersecurity Governance
weProvide-hand

“Partnering with us on NBU compliance means gaining a trusted advisor who understands both the regulations and the realities of the Ukrainian financial sector.”

weProvide-decor

Team portfolio

title-str

Our certificates

title-str

FAQ

What is the difference between cybersecurity risk management and traditional risk management?

How often should an organization conduct cybersecurity risk assessments?

What role do employees play in cybersecurity risk management?

How can small businesses implement effective cybersecurity risk management with limited resources?

What are some common mistakes organizations make in cybersecurity risk management?

How does cybersecurity risk management relate to compliance with data protection regulations?

Where to start?

Where to start?

For more information, reach out to us now.

Active Audit Agency provides extensive cybersecurity services for businesses, ensuring robust protection and compliance for organizations of various sizes.

Active Audit Agency provides extensive cybersecurity services for businesses, ensuring robust protection and compliance for organizations of various sizes.

footer-logo

You can copy our materials only after making sure that your services are safe.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.