NewsMacroBusinessWorld Cybersecurity Summit Urges Shift to Cyber Resilience as AI-Powered Threats Rise

BusinessWorld Cybersecurity Summit Urges Shift to Cyber Resilience as AI-Powered Threats Rise

Author: Bworldonline·

Key Takeaways

  • The CICC executive director called for Philippine organizations to transition from prevention-focused cybersecurity to cyber resilience plans that maintain operational continuity when attacks inevitably breach defenses.
  • Experts warned that sophisticated security strategies frequently fail because frontline employees responsible for implementation do not understand the underlying purpose of the measures.
  • Chief information security officers emphasized that ultimate accountability for cyber incidents rests with CEOs and top leadership, who can delegate responsibility but not accountability.
  • Speakers highlighted that AI serves simultaneously as a defensive tool for analyzing threats and an offensive weapon for cybercriminals, requiring organizations to establish proper baselines for AI-driven security.
  • The closing keynote argued that trust is more valuable than data in the digital economy, as all digital transactions, governance, and innovation depend on public confidence in information protection.
BusinessWorld Cybersecurity Summit Urges Shift to Cyber Resilience as AI-Powered Threats Rise

By Bjorn Biel M. Beltran, Special Features and Content Assistant Editor

Cybersecurity has become a perpetual defensive struggle in which understanding the adversary matters as much as knowing one's own capabilities. The question facing organizations today is how to defend against adversaries armed with ever-evolving technology supercharged by artificial intelligence (AI).

That premise anchored the BusinessWorld Cybersecurity Summit, held under the theme "Toward Stronger Digital Defenses" — an urgent call to reexamine the Philippines' protections against emerging cyber threats.

Lucien C. Dy Tioco, executive vice-president of BusinessWorld, opened the event by stressing the need for a united front against AI-powered cyberattacks and the protection of the country's rapidly expanding digital economy.

"The Philippines is home to millions of businesses, with micro, small, and medium enterprises making up 99% of all businesses in the country," Mr. Dy Tioco said in his welcome remarks. "These enterprises are continuing their digital transformation, making cybersecurity a technical safeguard that enables economic growth, innovation, and public confidence."

"Every investment in cybersecurity is an investment in trust. Every collaboration strengthens our collective resilience. Every conversation we sustain in this respect brings us one step closer to a digital economy that is secure, innovative, and inclusive," he added.

Atty. Renato "Aboy" A. Paraiso, executive director of the Cybercrime Investigation and Coordinating Center (CICC), delivered the opening keynote, calling for a shift from pure prevention to holistic cyber resilience. While traditional cybersecurity seeks to stop attacks and mitigate risks, resilience ensures that organizations maintain operational continuity and limit damage when — not if — attacks breach their defenses.

"While cybersecurity is designed to prevent attacks, cyber resilience, on the other hand, ensures that when an attack gets through, as some inevitably will, organizations can continue operating, minimize the damage, recover quickly, and emerge stronger from the experience," he said.

"Every business should have a practical cyber-resilience plan so that it can respond effectively when an attack happens," he added.

The CICC operates under the Office of the President and was created by the Cybercrime Prevention Act of 2012 (Republic Act No. 10175) to coordinate national cybercrime response across law enforcement, intelligence, and regulatory agencies.

Putting Cyber Resilience into Action

The summit's first panel discussion examined developments in regulatory frameworks, national security policies, and operational execution worldwide.

Gilbert T. Trinchera, technology consulting partner at R.G. Manabat & Co. (KPMG in the Philippines), argued that organizations must move beyond merely checking off compliance items and instead focus on risk management and regulatory convergence across jurisdictions.

"Regulatory convergence should be our goal, and we should align it to our ultimate vision, which is to maintain trust. This is the current universal currency that everybody understands, regardless of industry or jurisdiction," he said.

In the Philippines, data protection obligations are anchored in the Data Privacy Act of 2012 (Republic Act No. 10173), which established the National Privacy Commission, while the Cybercrime Prevention Act addresses offenses such as illegal access, data interference, and identity theft.

Atty. Jay-R C. Ipac, managing partner at Divina Law, emphasized that high-level security strategies frequently fail when frontline employees do not understand their purpose.

"The usual failure in implementing sophisticated cybersecurity measures," he said, "is that the people who will be implementing it on the ground do not really understand what they're doing in the first place. We have to make them understand why we are doing this."

Leadership During Security Incidents

The second panel shifted the focus to leadership during high-stakes security incidents.

"Assume a breach is not a possibility, but an inevitability. Crisis command is a leadership discipline, not a technical one," said Dennis Matthew F. Opiso, chief information security officer (CISO) at JG Summit Holdings, Inc.

Engr. Luis A. Jacinto, president and founding member of the Information Security Officers Group, stated plainly that while operational tasks may be delegated to specialized teams, ultimate accountability lies with top leadership.

"The ultimate responsibility and accountability goes to the CEO; he can delegate the responsibility, but not the accountability," he said.

Mar Apuhin, CISO at GT Capital Holdings, Inc., cautioned companies about the risks of premature public speculation and vague internal directives during an active breach.

"The biggest mistake [during an attack] is communicating before facts are verified," he said. "It is also a mistake to provide vague guidance to internal teams, employees, and customers. The main message should be transparency grounded in verified facts and what the laws require."

Technical and Human Controls

The third panel examined the technical and human controls necessary to protect modern organizations.

Catherine Anne Paleracio, CISO at Tonik, emphasized that security controls should function as business enablers rather than operational barriers, and that such controls must leverage AI.

"For security professionals, AI is helpful to do the analysis of big data, even for analyzing behavior. But at the same time, cybercriminals are using the same technology. So, we need to put a proper baseline for the AI to function. It doesn't know what to do right away. We have to teach it," she said.

An organization's defense is only as strong as its weakest link — and those links are frequently its own people. Mark Anthony P. Almodovar, executive director for Risk Services — Cybersecurity and Privacy at PwC Philippines, underscored the importance of enforcing proper access protocols.

"Access control is the most basic and most fundamental control in information security. Remember the people aspect. Most of the time, they are reluctant. Most of the time, only when they experience it, when they are compromised, when they lose money, their accounts have been taken over, that's the time when they will start implementing it," he said.

Cybersecurity as a Business Enabler

The summit's fourth panel, titled "Cybersecurity as a Business Enabler: Leveraging Security for Growth," explored how security drives enterprise valuation and market confidence.

Alexis Bernardino, principal CXO advisor and head of CXO Advisory at PLDT Enterprise, described how cybersecurity has evolved beyond a revenue-protection measure into a guarantor of business continuity.

"Nowadays, it is no longer about digital transformation," he said. "The issue is no longer cybersecurity. What we need to envision is digital resilience, that our organization will still function, be up and running even though we are under duress or under attack."

Alan Reyes, president and CEO of Hexcore Labs and general manager of Lightstream8 Corp., urged leaders to frame security in terms of commercial risk management rather than technical complexity.

"Cybersecurity, at its core, is nothing more than risk management. Business people understand risk management but not firewalls, endpoint protections and things like that," he said.

Trust, Preparedness, Collaboration

In the closing keynote, Cybersecurity Council of the Philippines Chairman Dr. Donald Lim called for building a safer digital nation, arguing that technology and policy alone cannot secure the country without leaders who prioritize trust, preparedness, and collaboration.

"Technology alone cannot make a nation secure. Even the best policies cannot make a nation secure," he said.

He concluded by redefining value for the digital era: "People say that data is the new oil. I would agree to disagree. In today's economy, trust is more valuable than data. People only transact when they trust. Citizens only embrace digital government when they trust that their information is protected. Businesses only innovate when customers believe their privacy is respected. The real product we are protecting is not information; it is confidence. Because when trust disappears, everything else begins to slow down."

The BusinessWorld Cybersecurity Summit was presented by BusinessWorld Publishing Corp., together with GCash and Maya, with the support of sponsors JuanHand, X10 Technologies, and TCS; partner organizations Asian Consulting Group, Asia Society of the Philippines, British Chamber of Commerce of the Philippines, French Chamber of Commerce and Industry in the Philippines, Management Association of the Philippines, Philippine Chamber of Commerce and Industry, Philippine Franchise Association, and the Philippine Retailers Association; creative partner ConSync Digital; and media partner The Philippine STAR.