Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
National Credit Information Centre of Vietnam (CIC)

National Credit Information Centre of Vietnam (CIC) Vendor Cyber Rating & Cyber Score

cic.gov.vn

National Credit Information Centre of Vietnam (CIC) has been officially established as the Public Credit Registry of The State Bank of Vietnam (SBV) since 1999. CIC remains the main functions of a not-for-profit Public Credit Registry: Support SBV in performing its management, policy-making and supervising functions with the aims of ensuring the safety of the Vietnamese banking system; support credit institutions in preventing and minimizing credit risks; and support borrowers in accessing loan packages with the aims of promoting socio-economic development.


NCICV A.I CyberSecurity Scoring

NCICV
Company Information
Website:https://cic.gov.vn/
Employees number:5
Number of followers:0
NAICS:52
Industry Type:Financial Services
Homepage:cic.gov.vn
NCICV Risk Score (AI oriented)
Between 700 and 749
logo
NCICVFinancial Services
Updated:
01/09/2026
717/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
NCICV Global Score (TPRM)
xxxx
logo
NCICVFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

NCICVModerate
Current Score
717Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
717Before Incident
AUGUST 2026
717Before Incident
JULY 2026
716Before Incident
JUNE 2026
714Before Incident
MAY 2026
713Before Incident
APRIL 2026
711Before Incident
MARCH 2026
709Before Incident
FEBRUARY 2026
707Before Incident
JANUARY 2026
706Before Incident
DECEMBER 2025
704Before Incident
NOVEMBER 2025
702Before Incident
OCTOBER 2025
700Before Incident
SEPTEMBER 2025
797Before Incident
Breach
12 Sep 2025NCICV
Vietnam’s National Credit Information Center: Vietnam Cybersecurity Investment 2026: 15% Budget Law

Vietnam National Credit Information Center (CIC) Cyber Breach

697After Incident
CRITICAL-100
CIC1788252938
Vietnam Overhauls Cybersecurity After CIC Breach, Mandates 15% IT Spending One year after a devastating breach at Vietnam’s National Credit Information Center (CIC), the country is implementing sweeping cybersecurity reforms, including a new law, mandatory budget allocations, and a dedicated municipal monitoring center. The response triggered by the September 2025 attack that exposed sensitive financial data marks one of Southeast Asia’s most ambitious cybersecurity overhauls, blending regulatory, financial, and operational changes to address systemic vulnerabilities. ### The Breach That Sparked Reform In September 2025, Vietnam’s State Bank confirmed a deliberate cyberattack on the CIC, the national credit bureau holding loan histories, income data, and personal records for millions of borrowers. Unlike a typical data leak, the incident was classified as a national security failure, prompting a year-long policy overhaul. The breach occurred amid a broader surge in cyber threats: Vietnamese businesses reported 502 million leaked enterprise records and 6.5 million stolen personal accounts in Q3 2025 alone a 64% quarterly increase. ### Key Reforms Under the New Cybersecurity Law Vietnam’s Cybersecurity Law No. 116/2025/QH15, effective July 1, 2026, replaces the 2018 framework with a five-tier risk classification system that tailors compliance requirements based on data sensitivity. High-risk systems such as financial institutions and credit bureaus face stricter localization, authentication, and audit rules, while lower-risk systems operate under baseline controls. The law also introduces a 15% budget mandate, requiring state agencies and public-sector entities to allocate at least 15% of their IT and digital transformation budgets to cybersecurity. This hard floor aims to prevent agencies from deprioritizing security during budget cuts, turning it into a fixed compliance metric. ### Hanoi’s AI-Driven Cybersecurity Center In parallel, Hanoi’s Plan No. 149/KH-UBND (signed April 2026) establishes a Municipal Cybersecurity Center, slated for operation in Q2 2027. The center will use AI and big data for threat monitoring, incident response, and coordination with national authorities. However, Hanoi’s long-term workforce goals training high-level experts by 2030 and internationally competitive teams by 2045 highlight a gap between infrastructure rollout and skilled labor availability. ### International and Market Impact Vietnam’s reforms extend beyond domestic policy. In May 2026, the country ratified the UN Hanoi Convention against Cybercrime, formalizing cross-border cooperation to combat cyber threats. Meanwhile, the private sector is already adjusting: 78% of Vietnamese organizations expect cybersecurity budget increases in 2026, with AI investment as the top priority (36%), per PwC’s survey. For foreign tech vendors, the new law’s data localization requirements for high-risk sectors (e.g., banking, government) may necessitate in-country partnerships. The 15% spending mandate and tiered compliance system are also reshaping procurement, with financial institutions likely to face the earliest cost pressures. ### Regional Comparison Vietnam’s approach stands out in Southeast Asia for its mandatory budget floor and municipal monitoring center, contrasting with Singapore’s focus on critical infrastructure or Indonesia’s data protection laws. While enforcement outcomes remain uncertain, the reforms reflect a broader shift toward digital sovereignty, reducing reliance on foreign cyber infrastructure. ### Timeline of Key Milestones - Sept 2025: CIC breach confirmed; 502M+ records leaked in Q3. - Dec 2025: National Assembly passes Cybersecurity Law No. 116/2025/QH15. - Apr 2026: Hanoi signs Plan No. 149, launching municipal cybersecurity center project. - May 2026: Vietnam ratifies UN Hanoi Convention against Cybercrime. - July 2026: New cybersecurity law takes effect. - Q2 2027: Hanoi’s AI-driven cybersecurity center scheduled to open. With the July 2026 deadline approaching, Vietnam’s reforms signal a decisive pivot from reactive measures to a risk-based, structurally funded cybersecurity posture one that could set a precedent for the region.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive financial data (loan histories, income data, personal records)Systems Affected: National Credit Information Center (CIC)Operational Impact: National security failure; triggered policy overhaulBrand Reputation Impact: Significant (classified as national security failure)Identity Theft Risk: High (personal records exposed)
DATA BREACH
Loan historiesIncome dataPersonal recordsNumber Of Records Exposed: 502M+ enterprise records and 6.5M personal accounts (Q3 2025)Sensitivity Of Data: High (financial and personally identifiable information)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for NCICV ?
?
What was NCICV's A.I Rankiteo Cyber Score in August 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in July 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in June 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in May 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in April 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in March 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in February 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in January 2026 ?
?
What was NCICV's A.I Rankiteo Cyber Score in December 2025 ?
?
What was NCICV's A.I Rankiteo Cyber Score in November 2025 ?
?
What was NCICV's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on NCICV's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with NCICV ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view NCICV's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?