NewsMacroWhy cybersecurity governance has become a business imperative

Why cybersecurity governance has become a business imperative

Author: Bworldonline·

Key Takeaways

  • Over 60% of complaints received by the Cybercrime Investigation and Coordinating Center involve scams, highlighting the widespread impact of cybercrime on ordinary citizens in the Philippines.
  • Philippine companies processing personal data of EU residents must comply with the GDPR, and the NIS2 Directive has expanded cybersecurity obligations across additional sectors with stricter incident-reporting requirements.
  • The Bangko Sentral ng Pilipinas is among the country's most active cybersecurity regulators, building on the Data Privacy Act of 2012 and the Cybercrime Prevention Act of 2012 as the foundational legal framework.
  • AI adoption in the Philippines has outpaced legislation, with several bills introduced but no comprehensive legal framework yet defining accountability for AI use.
  • Panelists emphasized that organizations should develop internal AI governance policies and cybersecurity measures rather than waiting for formal legislation to be enacted.
Why cybersecurity governance has become a business imperative

By Mhicole A. Moral, Special Features and Content Writer

Organizations now operate in a digital economy where technology powers nearly every part of business activity. As dependence on interconnected systems deepens, cybersecurity and data protection have become increasingly important elements of long-term business strategy.

These issues set the tone for the first panel discussion at the BusinessWorld Cybersecurity Summit, titled “Navigating Cybersecurity Laws and Compliance.” The panel examined how global cybersecurity regulations are affecting Philippine organizations and why compliance alone is no longer enough to strengthen cybersecurity.

Cybercrime Investigation and Coordinating Center Assistant Secretary and Deputy Executive Director Alvin M. Navarro said cybersecurity goes far beyond protecting businesses because its effects reach government institutions, national security, and ordinary citizens.

“Among the general population, the dark side of exploiting cyber weaknesses is felt through scams. More than 60% of all the complaints we receive come from scams. Imagine the losses, the anxiety, and the suffering that people go through,“ he explained.

Mr. Navarro said digital transformation remains a government priority because it improves the delivery of public services. However, he stressed that cybersecurity must be embedded at every stage of that transformation.

“We need to make sure that cybersecurity is embedded into our digital transformation: first, to improve public service; second, to make sure that all systems and processes that are intended to deliver those public services are robust and safe,” he added. “If all of these things fail, it’s not only the economy that will falter. It will affect political stability and our survival as a nation.”

Gilbert T. Trinchera, technology consulting partner at R.G. Manabat & Co. (KPMG in the Philippines), said cybersecurity is entering a phase in which multiple forces no longer operate separately but instead converge across organizations.

Drawing from KPMG’s latest cybersecurity considerations released earlier this year, Mr. Trinchera said eight major forces are reshaping cybersecurity now and in the years ahead: artificial intelligence, geopolitics, regulation, hyperconnectivity, non-human identities, supply chain dependencies, post-quantum cryptography, and autonomous security.

“These forces are not just operating individually in silos; they are converging, and that’s why it’s becoming an important imperative across the entire enterprise, whether you’re a government institution or a private industry. This is a huge consideration for everyone because the goal is not to perfect all compliance checklists, but simply to understand where we are, to be proactive and risk-averse, and definitely to ensure we consistently show our trust to our clients and stakeholders,” he explained.

DivinaLaw Managing Partner Jay R C. Ipac said two of the most influential regulations affecting local companies today are the European Union’s General Data Protection Regulation (GDPR) and the European Union’s NIS2 Directive. The GDPR’s extraterritorial scope means Philippine companies that process the personal data of EU residents must comply regardless of where they are based, while the NIS2 Directive, which entered into force in 2023, expanded cybersecurity obligations to a broader range of sectors and imposed stricter incident-reporting requirements across the EU.

Although some frameworks remain in draft form, Mr. Ipac said they show how cybersecurity discussions have expanded beyond technical compliance to organizational resilience.

He also cited the Bangko Sentral ng Pilipinas as one of the country’s most active regulators in cybersecurity governance, noting that financial institutions face rapid technological change and increasingly sophisticated digital threats. The BSP’s oversight builds on the Philippines’ existing legal foundation, which includes the Data Privacy Act of 2012 (Republic Act No. 10173) and the Cybercrime Prevention Act of 2012 (Republic Act No. 10175), laws that established the country’s baseline obligations for data protection and the prosecution of cybercrime.

Kristoffer Rada, head of corporate affairs at Maya Philippines Inc., said cybersecurity laws around the world now place accountability on boards of directors and senior management instead of limiting responsibility to technical teams.

“The focus is now shifting from prevention alone to operational resilience, the ability to detect, respond, recover, and continue to deliver essential services,” he emphasized.

Technology alone, however, is not sufficient. Customer awareness remains equally important, which is why the company pairs technological safeguards with public education campaigns.

“Regulation should be risk-based and outcome-based, so that institutions are accountable for results while retaining the room to adopt better technology. Also, transparency should be timely, accurate, and useful to people. Finally, cybersecurity must be collaborative. Threat intelligence, scam prevention, and incident coordination, together with consumer education, require government and industry to work together,” Mr. Rada explained.

From technical responsibility to business governance

The growing influence of international regulations has also changed how organizations define cybersecurity leadership.

Mr. Ipac said many organizations still delegate cybersecurity almost entirely to chief information security officers or information technology departments. While companies often put policies in place and complete documentation, those preparations frequently prove inadequate when a real cyber incident occurs.

“The biggest misconception is still looking at cybersecurity as a tech issue. All stakeholders should have a genuine interest in making sure [cybersecurity] is at the top of all companies’ agendas in their digitized business,” he said. “Your people are your best assets. You have to be able to create a cybersecurity culture, not just awareness, but the resilience that the public trusts.”

Mr. Navarro said business leaders should have enough technological understanding to make informed decisions while taking ownership of their organization’s future. A major part of that responsibility is maintaining strong cybersecurity throughout the organization.

“Cybersecurity has assumed a proportion, such that it not only affects businesses immensely but also impacts national security without question,” he explained.

Artificial intelligence raises the stakes

Organizations are using artificial intelligence (AI) to improve efficiency and strengthen defenses, but the same technology is also giving cybercriminals new ways to launch attacks, manipulate information, and exploit unsuspecting users.

The panelists said this has widened the gap between technological innovation and regulation, placing more responsibility on organizations to establish governance before new laws take effect.

Mr. Trinchera said the Philippines remains in a period where AI adoption has moved faster than legislation. Several AI-related bills have been introduced, but organizations currently operate without a comprehensive legal framework that clearly defines accountability for AI use.

“The implication is that, if anyone is using AI, whether it’s for good or bad, they do not have a sense of accountability and obligation. It’s merely a playground,” he explained.

He added that Filipinos’ widespread use of social media, digital platforms, online marketplaces, and emerging technologies creates additional opportunities for AI-driven scams, disinformation campaigns, phishing attempts, and other cyber threats.

Without sufficient awareness and governance, he said, technology can speed up the spread of harmful content while making cyberattacks more convincing and harder to detect.

“Regulatory convergence should be our goal, and we should align it to our ultimate vision, which is to maintain trust. This is the current universal currency that everybody understands, regardless of industry or jurisdiction,” he emphasized.

Mr. Navarro said legislation is trying to keep pace with AI, although the legislative process naturally moves more slowly than technological development. In the meantime, he encouraged organizations to create internal policies governing AI use based on their own operational requirements and cybersecurity risks.

Organizations, he said, can already develop practical governance measures that define responsible AI use while addressing security gaps specific to their operations.

“There’s no legislation yet, but it’s not entirely hopeless. It’s not a situation where our hands are tied. From our organizations, we can already develop the policy that is more specific to our needs, to the security issues or gaps that we face,” Mr. Navarro stated.

Maya, meanwhile, has been using artificial intelligence as a tool for identifying suspicious financial transactions across its large transaction volume.

Mr. Rada said technology presents both opportunities and risks. Policies and frameworks remain important, but they produce meaningful results when they work together with the government.

“[There should be] collaboration between the public and private sector. We [should] work very closely with the policymakers, with legislators, and the enforcers, because that’s the only way that we can catch up in terms of coming up with a rational policy,” he explained.