Ontech ICTM by industry

ICT Management for Banks in Zambia

One platform for the assets, security monitoring, access controls, vendors and recovery plans behind every branch, ATM link and core system.

How can banks in Zambia manage ICT risk and compliance?

Banks in Zambia manage ICT risk by keeping complete inventories of systems and accounts, monitoring networks for threats, controlling privileged access, testing recovery plans and recording the evidence regulators ask for. The Bank of Zambia's Cyber and Information Risk Management Guidelines, 2023 set minimum expectations. Ontech ICTM brings these activities into one platform so the evidence is not scattered across spreadsheets.

Banks and other Bank of Zambia regulated entities work to a published baseline: the Cyber and Information Risk Management Guidelines, 2023 (Gazette Notice No. 668 of 2023). They are organised around the NIST functions of identify, protect, detect, respond and recover, and apply on an apply-or-explain basis. Banking and finance is also listed as a critical sector under the Cyber Security Act, 2025.

Ontech ICTM gives IT, security and risk teams a shared system for the work those rules imply: asset and account inventories, vulnerability testing records, incident registers, vendor dependencies and recovery exercises. It does not replace your core-banking stack or your regulatory reporting; it keeps the records those activities depend on.

ICT challenges in banking & financial services

Inventories that go stale

Branch servers, ATM connectivity, data-centre systems and user accounts are tracked in separate lists that are rarely current when an examiner asks.

Privileged and dormant accounts

Administrator rights granted for a project are never removed, and accounts of departed staff stay active.

Testing without a record

Vulnerability assessments and penetration tests happen, but the dates, findings and fixes are hard to show afterwards.

Hidden vendor dependence

Core-banking, card and connectivity providers are single points of failure that nobody has mapped.

Recovery plans on paper

Continuity and recovery plans exist as documents, with no record of whether recovery targets were met in a test.

How banking & financial services organisations use ICTM

Branch and ATM-link availability

ICMP checks on branch routers and ATM connectivity endpoints record uptime and latency and raise an alert after repeated failures; HTTP monitors check internet-banking and API endpoints, including their SSL certificates.

Account inventories and access reviews

Users and groups synchronised from Active Directory feed access reviews, while scheduled scans find dormant and orphaned accounts and can disable them automatically.

Time-limited privileged access

Administrators request elevated rights for a set period; the request needs approval and the rights expire on their own. Service-account password rotation is tracked.

Vulnerability and penetration testing records

Scheduled scans, web application tests and authenticated role-by-role tests for broken access control are kept with dates, severity-based remediation deadlines and SARIF, CSV or PDF exports.

Core-banking vendor dependencies

Each application's vendor dependencies are recorded with single-point-of-failure flags, contracted uptime and recovery targets, and a concentration-risk view across providers.

Incident repository

Security events from syslog and Windows event logs can be escalated into an incident register with severity, SLA-breach flags and root-cause analysis records.

PCI DSS 4.0 control mapping

Controls are mapped to the PCI DSS 4.0 and ISO/IEC 27001:2022 control sets, with AI-assisted suggestions a person approves, gap analysis and an audit-readiness score.

Recovery exercises for core systems

Business impact analyses set recovery time and recovery point targets; exercises record the actual results, and scheduled database backups are scored against their expected frequency.

Regulation that applies

Summaries based on the primary legislation and regulator publications. See the linked Zambia pages for detail and sources — this is general information, not legal advice.

Bank of Zambia Cyber and Information Risk Management Guidelines, 2023

Gazette Notice No. 668 of 2023. Apply to all Regulated Entities on an apply-or-explain basis. Among other things they expect a CISO independent of day-to-day IT operations (7.2.8), a security operations centre or at minimum a monitoring mechanism (7.2.13), inventories of assets and of user, privileged and remote-access accounts (8.1, 8.2.11), vulnerability assessments at least quarterly and annual penetration tests (9.1.10), immediate notification of medium or high incidents to the Bank (11.1.5) and an annual maturity assessment submitted to the Bank (para 13).

Cyber Security Act No. 3 of 2025

Lists banking and finance as a critical sector (s.8). The Zambia Cyber Security Agency designates critical information infrastructure by Gazette notice (s.9), and a controller of designated infrastructure must file a preliminary cyber incident report within twelve hours (s.17). The Act repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73).

Data Protection Act No. 3 of 2021

Data controllers and processors must register with the Data Protection Commissioner (s.19), appoint a data protection officer (s.48), notify the Commissioner within twenty-four hours of a security breach (s.49), and process and store personal data on a server or data centre in Zambia unless an exception applies (s.70).

What ICTM covers — and what it doesn't

ICTM does not connect to core-banking, card-management or payment-switch systems, and it does not file reports with the Bank of Zambia or the Zambia Cyber Security Agency; it organises the records and evidence your teams use. Penetration testing provided as a service may require a licensed provider under the Cyber Security Act, 2025 (s.42).

Benefits

Evidence in one place

Inventories, test results, incidents and recovery exercises sit in one system with dates and owners.

Visible access risk

Dormant, orphaned and elevated accounts are surfaced before an audit rather than during one.

Recovery you can demonstrate

Exercises record target versus actual recovery times for core systems.

Known vendor exposure

Dependencies and single points of failure are mapped per application.

Data kept local

ICTM can run on servers you control, with AI features on a locally hosted language model.

Rolling out ICTM

  1. Scope modules and roles

    Run ICTM as a hosted service or on servers you control, then set up role-based access so each team sees only the modules it needs.

  2. Connect your estate

    Add SSH credentials for servers and network devices, BMC endpoints for data-centre hardware, NetFlow or IPFIX exporters, and your Active Directory for account data.

  3. Record assets, vendors and plans

    Build the asset register, list technology vendors and contracts, and capture business impact analyses and recovery plans for core systems.

  4. Set up testing and frameworks

    Schedule vulnerability scans with remediation deadlines and map controls to the PCI DSS 4.0 and ISO/IEC 27001 control sets.

  5. Train and review

    Enrol staff in awareness courses and review access, risks and exercise results on a regular cycle.

Frequently asked questions

Do the Bank of Zambia's 2023 cyber guidelines apply to my institution?

The Cyber and Information Risk Management Guidelines, 2023 apply to all Regulated Entities, defined as financial service providers, payment systems, payment system businesses and credit reference agencies. They use an apply-or-explain approach: an entity that cannot apply a requirement in full must explain how it manages the risk instead. Confirm the position for your licence with the Bank of Zambia.

Can ICTM show a record of our vulnerability assessments?

Yes. ICTM runs scheduled vulnerability scans that match detected services to known CVEs, keeps every result with its date, and tracks each finding against a remediation deadline set by severity. The Guidelines expect vulnerability assessments at least quarterly and annual intelligence-led penetration tests by suitably accredited testers (section 9.1.10). ICTM supports that work but does not replace an accredited or licensed tester.

How does ICTM help with privileged and dormant accounts?

ICTM synchronises users and groups from Active Directory for access reviews, scans for dormant and orphaned accounts and can disable them on a schedule, and handles time-limited privilege elevation that needs approval and expires automatically. This supports the Guidelines' expectation that entities keep an inventory of users, system, privileged and remote-access accounts (section 8.2.11).

Does ICTM report incidents to the Bank of Zambia?

No. The Guidelines require the entity to inform the Bank of Zambia immediately when a medium or highly classified incident is discovered and before any media interaction, then submit a formal report with root-cause analysis (sections 11.1.5 and 11.1.6). ICTM keeps the incident register, related security events and root-cause analysis records your team uses to prepare those notifications.

Can our ICTM data stay in Zambia?

ICTM can be installed on servers you control, and its AI features can run on a locally hosted language model, so asset, security and compliance data does not need to leave your environment. That fits the Data Protection Act's rule that personal data is processed and stored on servers or data centres in Zambia (section 70) unless an exception applies.

See how banking & financial services teams use Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.