NewsMacroGCash Chief Risk Officer Outlines Cybersecurity Strategy and Crisis Response Principles

GCash Chief Risk Officer Outlines Cybersecurity Strategy and Crisis Response Principles

Author: Bworldonline·

Key Takeaways

  • GCash's cybersecurity strategy rests on three pillars: technology investment for fraud prevention, customer education as a first line of defense, and public-private sector collaboration.
  • GCash partnered with the Cybercrime Investigation and Coordinating Center to shut down 3,200 merchants involved in illegal gambling earlier this year.
  • Beroña's three crisis response principles require organizations to acknowledge incidents quickly, communicate verified facts separately from information still under investigation, and provide concise actionable guidance.
  • The crisis commander should be an executive with agile decision-making, communication, and coordination skills who oversees organizational response rather than leading technical investigations.
  • Organizations should communicate publicly about incidents before investigations conclude to prevent rumors from overtaking official messaging and eroding stakeholder trust.
GCash Chief Risk Officer Outlines Cybersecurity Strategy and Crisis Response Principles

As cyber threats grow more sophisticated and disruptive, countering them demands coordinated leadership and clear communication, according to GCash Chief Risk Officer Ingrid Rose Ann Beroña.

GCash, operated by Globe Fintech Innovations Inc. (Mynt), is the Philippines' largest mobile wallet platform, processing billions of transactions annually and serving tens of millions of users. As digital payment adoption accelerates across the country — driven in part by the Bangko Sentral ng Pilipinas' push to digitize a majority of retail transactions — the security of platforms like GCash has become increasingly critical to the broader financial system.

Speaking during the summit's second panel discussion, Ms. Beroña detailed how organizations can prepare for and respond to cyber crises. In her current role, she oversees GCash's entire enterprise risk governance framework, encompassing business assurance management, business continuity, and organizational resilience.

A Three-Pillar Cybersecurity Framework

Ms. Beroña outlined three key pillars on which GCash anchors its cybersecurity strategy: investing in technology to prevent fraud, educating customers to serve as the first line of defense against scams, and fostering partnerships spanning the public and private sectors.

The first pillar involves leveraging technology to strengthen security controls and proactively counter evolving cyber threats. "We have built a lot of security controls to ensure that our consumers are safe in the app because our number one priority is trust and security," she said.

Among these controls is GCash DoubleSafe, a security feature that uses selfie scans to protect user accounts from unauthorized access. Biometric safeguards like this have become increasingly common across Southeast Asian fintech platforms as social engineering attacks targeting mobile wallet users continue to rise. However, Ms. Beroña stressed that even the most advanced technologies cannot fully shield users when cybercriminals succeed in exploiting human behavior.

"No matter how many locks we place in our systems, our technology, or our app, if you give away the keys to those locks, fraudsters can still get in. This is part of why GCash and other financial institutions never ask for your MPIN or OTP," she said.

The third pillar emphasizes collaboration among businesses, regulators, law enforcement agencies, and technology partners. Ms. Beroña cited GCash's joint effort with the Cybercrime Investigation and Coordinating Center earlier this year to crack down on illegal gambling, an operation that led to the shutdown of 3,200 merchants involved in the activity.

"We are all in this together. We need to ensure that the private sector, the government, and even external partners work together to combat fraud and cyberattacks while ensuring that everybody is safe in this digital space," she advocated.

Crisis Response: Be Fast, Be Clear, Be Concise

Beyond threat prevention, Ms. Beroña shared three guiding principles for organizations responding to any crisis, including cyber incidents: be fast, be clear, and be concise. These principles align with widely recognized cybersecurity incident response frameworks that prioritize rapid containment and transparent stakeholder communication.

"Being fast doesn't necessarily mean resolving the issue immediately. It means being fast in acknowledging that there is an incident because identification and acknowledgement are your buttons for activating a crisis command center or crisis management program," she explained.

Her second principle centers on communicating clearly by distinguishing verified facts from information still under investigation. "People need to understand what the facts are and be able to separate what is factual from what is still under investigation," she said, noting that transparency enables organizations to communicate responsibly with customers, regulators, the media, and other stakeholders.

"My third principle is to be concise and work toward action. People need to understand what they have to do, how they should execute their responsibilities, and how to properly escalate issues while they are happening," Ms. Beroña continued.

The Role of the Crisis Commander

At GCash, the crisis commander role is built around these same three values. According to Ms. Beroña, this individual is tasked with coordinating the organization's overall response rather than leading the technical investigation itself. This separation of coordination from technical investigation reflects established incident response practices that distinguish between operational remediation and strategic decision-making.

"Your crisis commander should be an executive who has, first, agile decision-making skills; second, very good communication skills; and third, very good coordination skills," she said.

The crisis commander oversees coordination among incident response teams, executives, and corporate communications, ensuring that decision-makers receive accurate information and that established response procedures are followed, she added.

Ms. Beroña also underscored the importance of acknowledging incidents before speculation and rumors overtake official communication. "It's very important to acknowledge an incident, and timing is equally important," she said. "If your consumers are already experiencing the impact of the issue and rumors are circulating, this means you're late in acknowledging it."

Organizations, she argued, should not wait until investigations conclude before communicating publicly. "When you communicate that externally, whether to consumers or other stakeholders, you don't need to have the complete story or narrative. There's nothing wrong with saying, 'We do have an issue, but you don't have to worry because we're already on top of it and we're doing something about it,'" Ms. Beroña said.

— Jomarc Angelo M. Corpuz