NewsMacroCybersecurity Leaders Outline Essentials of Crisis Command at BusinessWorld Cybersecurity Summit 2026

Cybersecurity Leaders Outline Essentials of Crisis Command at BusinessWorld Cybersecurity Summit 2026

Author: Bworldonline·

Key Takeaways

  • Cybersecurity leaders at the BusinessWorld Cybersecurity Summit 2026 urged organizations to treat breaches as inevitable and prioritize response preparedness over prevention alone.
  • Crisis command should be designated before an incident occurs, with panelists noting that ambiguous leadership during high-pressure situations can severely hamper response efforts.
  • Organizations must preserve compromised systems as digital evidence by isolating them from networks rather than shutting them down, as forensic data is critical for investigations, insurance claims, and legal proceedings.
  • Under the Philippines' Data Privacy Act of 2012, organizations are required to notify the National Privacy Commission within 72 hours of discovering a personal data breach, and financial institutions face additional reporting requirements from the Bangko Sentral ng Pilipinas.
  • Panelists stressed that organizations should fully assess the scope of an incident before communicating publicly, as releasing unverified information can create misinformation and damage credibility.
Cybersecurity Leaders Outline Essentials of Crisis Command at BusinessWorld Cybersecurity Summit 2026

By Jomarc Angelo M. Corpuz, Special Features and Content Writer

Crises in the modern era increasingly unfold in a domain far removed from the natural disasters, economic shocks, societal upheavals, and military conflicts that dominated previous decades. Since the internet reshaped global commerce at the turn of the century, cyberspace has become the arena where governments, institutions, and private enterprises conduct their affairs — and where attacks can compromise operations and erode public trust within minutes. The Philippines, where digital adoption has accelerated rapidly across banking, retail, and government services, has not been immune to this shift, making the governance of cyber incidents an increasingly board-level concern.

Against this backdrop, cybersecurity demands strong leadership, clearly defined governance, and coordinated decision-making, departing from the long-held assumption that it falls exclusively within the purview of information technology departments. This perspective aligns with globally recognized frameworks such as the U.S. National Institute of Standards and Technology (NIST) Cybersecurity Framework and the zero trust model, both of which emphasize resilience and response alongside prevention.

These themes took center stage during the second panel discussion at the BusinessWorld Cybersecurity Summit 2026, titled "Being a Crisis Commander in the Event of a Cyber-Attack." Cybersecurity and risk leaders from JG Summit Holdings, Inc., one of the Philippines' largest conglomerates spanning food, real estate, banking, and aviation; GCash, the country's dominant mobile wallet platform handling millions of daily transactions; GT Capital Holdings, Inc., a major diversified conglomerate; the Information Security Officers Group (ISOG), a Philippine industry association of cybersecurity professionals; and Accenture, a global professional services firm, shared strategies for strengthening organizational preparedness and navigating cyber crises.

Assume Breach Is Inevitable

Dennis Matthew F. Opiso, Chief Information Security Officer of JG Summit Holdings, urged organizations to confront an uncomfortable reality: regardless of how sophisticated their security systems become, cyber incidents are inevitable. The true measure of preparedness, he argued, is not whether an organization can thwart every attack, but how effectively it responds when one succeeds.

"The most useful sentence in this entire panel is: assume a breach is not a possibility, but an inevitability," he said. "Most organizations nod at that sentence, then keep budgeting, planning, and organizing as if prevention were the whole job. The gap between what we say we believe and what we actually prepare for is the gap where incidents become disasters."

Drawing on his experience securing JG Summit's diverse business sectors, Mr. Opiso observed that each industry defines operational disruption differently. A temporary outage in one business may be tolerable, while in another, it could bring critical operations to a halt. Every enterprise, he said, will eventually face its own "bad day," and he called for a broader conception of crisis management — one that places leadership at the center of incident response.

"Crisis command is a leadership discipline, not a technical one. The commander's job during an incident is not to read logs," Mr. Opiso said. "It is to make decisions with incomplete information, keep the response aligned with business continuity, and keep people calm enough to do their jobs."

He further advised organizations to regularly rehearse their incident response playbooks, designate in advance who will assume command during a crisis, and ensure that communications, legal, operations, and technology teams each understand their responsibilities should a breach materialize.

Clearly Defined Plans and Authority

Building on that foundation, Mafi Caringal, Managing Director of Accenture Advanced Technology Centers in the Philippines, stressed that organizations should trust the plans they have already developed rather than reacting impulsively once an incident strikes.

"Number one, invoke the plan because you need to start the command. Make sure that the people who rightfully know what to do are there. Second, scope. Do the initial analysis. Don't try to do threat hunting and solve everything. Scope the incident first. Then trigger notifications because, with your plans and your runbooks, it's all defined there. Trigger the necessary notifications, including legal privilege," she explained.

The emphasis on legal notifications reflects obligations under the Philippines' Data Privacy Act of 2012 (Republic Act No. 10173), which requires organizations to notify the National Privacy Commission within 72 hours upon discovery of a personal data breach. For financial institutions, the Bangko Sentral ng Pilipinas (BSP) imposes additional reporting requirements under its Information Technology Risk Management and Cybersecurity guidelines, underscoring why legal involvement must be triggered early in the response process.

Equally critical, Ms. Caringal said, is eliminating ambiguity in leadership. Because cyber incidents unfold under intense pressure and at unpredictable moments, clearly defined authority is essential to mounting an effective response.

"It has to be clearly called out who that commander is because, when an attack does happen, either everyone assumes somebody else is in charge, or there are simply too many commanders. This is a very high-stress situation," she emphasized.

Mr. Opiso echoed this view, noting that the designated commander may differ depending on organizational structure. In some companies, it may be the chief information security officer; in others, the chief information officer, chief financial officer, or another senior executive. What ultimately matters, he stressed, is that the decision has been settled before an incident occurs.

Preserving Digital Evidence

The panelists also addressed the technical dimensions of crisis response. Ms. Caringal cautioned against prematurely deleting compromised files or shutting down affected systems merely to restore operations as quickly as possible.

"From a technical perspective, not preserving evidence is a major mistake, especially if you later want to solve the incident, prevent it from happening again, and strengthen your plans and your zero trust architecture. We need that evidence. Sometimes people immediately say, 'Delete it,' or 'Shut it down,' but we need that information from a technical standpoint," she said.

Information Security Officers Group (ISOG) President and Founding Member Engr. Luis A. Jacinto reinforced this point, warning that well-intentioned actions taken during the initial hours of an incident can severely complicate subsequent investigations.

"If you wipe the device, you lose all your forensic data, and that's one of the worst things that you could do," he said.

Rather than immediately powering off compromised systems, Mr. Jacinto recommended isolating them from the network while preserving evidence that investigators can later use to determine how attackers gained entry and to prevent similar intrusions from recurring. Preserved evidence can also be critical for insurance claims, regulatory inquiries, and potential legal proceedings following a breach.

Mr. Jacinto also advocated for a whole-of-organization approach to crisis response, entailing coordination among executives, technology teams, governance officers, legal counsel, corporate communications, and operational leaders. Even so, he maintained that accountability must remain concentrated at the highest echelon of the organization.

"The CEO is ultimately responsible, and the CEO is ultimately accountable," Mr. Jacinto said. "However, the CEO can delegate the responsibility, but not the accountability."

Understanding Before Communicating

The panel further emphasized that technical readiness must be matched by disciplined communication — particularly during the first hours of an incident, when verified information remains scarce.

Mar Apuhin, Chief Information Security Officer at GT Capital Holdings, underscored that the immediate priority should be grasping the full scope of the situation before communicating either internally or externally.

"So, this is a very high-stress situation. In our case at GT Capital, the default is the CISO. There's no doubt about that. So, the main goal, perhaps, is getting accurate information by convening the team, the leadership team, the [executive committee], and then activating the incident response. If you guys outsource it to a third party, don't forget them. Those will be the source of verified information. And then, we don't speculate," he said.

Mr. Apuhin expanded on this approach, stating that organizations should first evaluate the scope and potential impact of an incident before convening the crisis communications committee or incident response team. Once leadership has been assembled, the next step is to escalate the matter to senior executives who will oversee business decisions while technical teams continue their investigation.

Because cyber incidents often evolve rapidly and with limited information, he encouraged organizations to be transparent about what they know while resisting the temptation to fill information gaps with assumptions.

"Assess the blast impact, what's happening. But understand, during the first hour, you don't have much information yet. Assess what we do. Be frank. This is what I only know for the time being, what we're doing. And this is what we're going to do next," he said.

"The biggest mistake is communicating before facts are verified. We're speculating, guys. Number two, that will result in creating misinformation or a credibility issue in your case," Mr. Apuhin added.

Mr. Jacinto shared a similar perspective, arguing that communications during a cyber crisis should be carefully controlled until information has been confirmed. While stakeholders deserve timely updates, organizations must avoid releasing incomplete or inaccurate information that could generate confusion or unnecessary alarm.

"There is certain information that you're not supposed to release immediately. We're not saying you're not going to release it, but you're not supposed to release it because it has not been confirmed," he stated.

In a cyberspace environment where information travels as swiftly as the threats themselves, leadership, preparation, and coordinated decision-making may ultimately serve as an organization's strongest defenses against an inevitable breach.