TBC Bank: Cyber Health Framework

Recognized in the Category:

Additional Info

Nominee’s NameGigi Gurielidze
Nominee’s Job Title or RoleHead of Information Security Department
Company / OrganizationTBC Bank
Company size10,000-14,999 employees
CountryGeorgia
World RegionEurope
Websitetbcbank.ge

NOMINATION HIGHLIGHTS

TBC Bank is Georgia’s leading universal bank, with around 40% market share across core businesses such as loans, deposits, and payments, and ~1.3 million digital monthly active users in a country of ~4 million people. At this scale, risk and compliance are not supporting functions – they are the operating backbone that protects customers, continuity, and regulatory confidence.

In 2025, while accelerating digital delivery, we faced a classic risk-and-compliance challenge: security controls and tools existed, but assurance was fragmented across systems and teams. Evidence quality and interpretation were inconsistent, making it hard to demonstrate control effectiveness reliably, compare critical systems, and prioritize remediation with confidence. Oversight could not consistently answer basic questions: Where is the highest risk concentration? Which systems are improving? Which controls are truly implemented versus assumed?

We implemented the Cyber Health Assessment Framework to convert scattered activities into a repeatable, auditable risk and compliance program. Aligned to OWASP SAMM, ISO 27001, NIST CSF, and National Bank of Georgia cyber and operational risk requirements, it provides one consistent way to assess each critical system across its lifecycle (Governance, Design, Implementation, Verification, Operations) and produce a comparable maturity view. The distinctive element is evidence-first assurance: we measure both control maturity and the strength of proof behind it – shifting oversight from “we believe” to “we can demonstrate.”

Phase 1 (Jan–Dec 2025) was delivered by a lean core team of four specialists and assessed 68 of 124 critical systems (55%) across 14 tribes, reaching 97% coverage of critical servers and 85% of critical business software solutions. Each assessed system now has a standardized, repeatable evidence pack and a scored risk view that can be reviewed quarterly, tracked over time, and used to drive decisions.

The program is built to drive outcomes, not reports. It embeds owner accountability through formal system dashboards, executive-level portfolio reporting, and a remediation commitment window for high-priority gaps—turning findings into owned delivery plans. Measured results already show material reduction of critical exposures in cloud and container production environments, strengthening resilience and regulatory readiness. By February 2026, remediation has been executed across the assessed scope and supporting evidence captured; re-scoring is in progress, and interim validation indicates broad maturity uplift across systems.

cybersecurity_awards_2026_gold