Cybersecurity as a Shared Responsibility: GCash Forensics Leader Calls for Company-Wide Security Culture
Key Takeaways
- •GCash executive Timothy John Cristobal stated that cybersecurity should be embedded into every business initiative from the outset and treated as a shared responsibility across all departments rather than solely the security team's domain.
- •Cristobal identified employees as the weakest link in digital defense and called for corporate awareness programs that go beyond compliance checklists to help staff understand the rationale behind security policies.
- •He advocated for continuous offensive security practices, such as simulating adversarial tactics, noting that static periodic audits are insufficient against a rapidly evolving threat landscape.
- •Cristobal observed that monetary compensation alone is inadequate for retaining cybersecurity professionals, who are more motivated by understanding how their work protects organizational assets and infrastructure.
- •The panel concluded that cybersecurity is fundamentally tied to preserving organizational trust, which serves as the foundation of modern digital commerce and long-term business expansion.

As enterprises accelerate technology adoption to remain competitive, executive leadership confronts a core challenge: reconciling rapid operational scaling with strong digital defense.
At the BusinessWorld Cybersecurity Summit 2026, GCash Assistant Vice-President and Head of Forensics & Offensive Security Timothy John Cristobal addressed the evolving relationship between enterprise risk management and business growth during the event's fourth panel discussion.
GCash, operated by Globe Fintech Innovations Inc. (Mynt), is the Philippines' largest mobile wallet platform, serving tens of millions of users — a scale that places its security practices under particular scrutiny as digital payments adoption surges across Southeast Asia.
Mr. Cristobal pushed back against a prevailing attitude in fast-paced corporate environments, where security protocols are often dismissed as friction that impedes operations.
"There is some sort of mindset that cybersecurity is actually a blocker [of business growth]," Mr. Cristobal observed.
He argued that sustainable enterprise expansion depends on embedding robust security frameworks into every business initiative from the outset.
Cybersecurity, he stressed, must be treated as a continuous discipline woven across all departments — not confined to the security team alone.
"It should be a responsibility for everybody, not just for the cybersecurity team," Mr. Cristobal emphasized. "We believe that if it's just the cybersecurity team, we'll have trouble catching up."
Building organizational resilience demands shared accountability at every operational tier, from software developers writing code to business development teams negotiating commercial agreements. When security responsibility is distributed company-wide, vulnerabilities can be detected and resolved early in the project lifecycle, averting technical bottlenecks before they escalate.
Yet cultivating this culture hinges on addressing human behavior — long considered the softest target in digital defense.
"People are always the weakest link. No matter how you strengthen the system or get the latest technology, it's always going to be the people," Mr. Cristobal said.
Corporate awareness programs, he argued, must transcend routine compliance checklists and instead help employees grasp the rationale behind security policies.
"Once you get successful in that campaign, you need to have the people understand the meaning behind it," Mr. Cristobal explained. "What's important is if employees see the value of what they're doing and how they're protecting the company."
When staff recognize that their individual actions safeguard the organization, security evolves from a mandated obligation into an embedded corporate value.
Offensive Security
To stay ahead of a shifting threat landscape, Mr. Cristobal said organizations should continuously validate their defenses through real-world pressure testing and proactive vulnerability discovery.
While traditional defensive approaches center on perimeter monitoring, offensive security takes a proactive stance — simulating adversarial tactics to expose hidden system weaknesses before malicious actors can exploit them.
In a fast-changing digital environment, static periodic audits fall short of ensuring lasting protection. Sustaining enterprise integrity calls for continuous testing and threat simulation so that defenses evolve in step with emerging attack vectors.
Retaining Talent
Sustained offensive security operations depend heavily on recruiting and retaining highly skilled technical professionals. This challenge is compounded by a well-documented global cybersecurity workforce gap that has persisted for years, intensifying competition for qualified practitioners.
On the question of talent retention, Mr. Cristobal noted that monetary compensation alone is insufficient to keep cybersecurity teams engaged.
"For talents in cybersecurity nowadays, more than compensation, they are trying to see value in what they're doing," he said.
Security professionals, he observed, are most motivated when they can draw a clear line between their day-to-day responsibilities and the broader mission of protecting organizational assets, critical infrastructure, and institutional trust.
The panel agreed that cybersecurity is inextricably linked to preserving organizational trust — the foundational currency of modern digital commerce. By reframing security as a prerequisite for commercial growth, cultivating shared responsibility across the workforce, continuously pressure-testing systems through offensive security, and retaining talent through meaningful work, organizations can shift digital defense from a perceived growth barrier into a catalyst for long-term expansion.
— Krystal Anjela H. Gamboa