Build Faster, Secure Smarter: Why Philippine Organizations Must Rethink Software Risk
Key Takeaways
- •Fastly research found that software bugs contributed to 54% of cyber incidents across Asia-Pacific in 2025, compared with 43% attributed to cyber attackers.
- •Asia-Pacific enterprises with more than 10,000 employees experienced an average of 57 incidents last year, above the overall average of 40.
- •Gartner has warned that by 2027, more than 40% of AI-related data breaches will stem from the improper use of generative AI.
- •Among organizations that describe themselves as AI-first, 31% remain unclear about who owns incident response responsibilities.
- •Philippine DICT initiatives, including the Bug Bounty Program and Cybersecurity Posture Assessment Laboratory, reflect a growing national emphasis on early risk detection and mitigation.

By Rachel Ler
Digital transformation was once approached cautiously in many Philippine boardrooms. Today, that enthusiasm is being matched by real investment — if anything, decision-makers want to deploy software and launch new applications faster than ever. Fueling this appetite for speed is the rise of artificial intelligence (AI), particularly AI-assisted development, which helps engineering teams automate repetitive tasks and substantially shorten development timelines.
Yet amid the push for speed, leaders should be scrutinizing whether they are building these systems securely. A rushed deployment, a vulnerable software dependency, or an overlooked configuration change can introduce risks just as significant for Philippine organizations as they are elsewhere in Asia-Pacific. New research from Fastly found that software bugs contributed to 54% of cyber incidents in 2025, compared with 43% attributed to cyber attackers, across Asia-Pacific. Even so, many organizations continue to plan their cybersecurity strategies and risk mitigation around the assumption that the greatest threats are external.
The AI Acceleration Challenge
Investing in ransomware detection, phishing prevention, and other cyber defenses remains essential, but addressing cyber risk no longer stops at the network edge. As organizations increasingly adopt AI-assisted development tools, they also need stronger governance and security guardrails to ensure software is built safely and in line with the National AI Strategy 2.0.
This is not because AI-generated code is inherently unsafe. Rather, AI enables development teams to produce code faster than ever before, making it easier for vulnerabilities, insecure dependencies, or configuration errors to reach production when security is treated as an afterthought.
The challenge is exacerbated by today's complex digital environments. Modern applications rely on application programming interfaces, are hosted across multiple cloud platforms, integrate with third-party services, and are deployed through automated deployment pipelines. While this connectivity creates new opportunities for innovation, it also means that small mistakes which once might have been identified before release can now move into production environments faster.
Organizational size compounds the risk. Fastly's research found that Asia-Pacific enterprises employing more than 10,000 people experienced an average of 57 incidents last year, compared with the overall average of 40. As organizations grow, so does the complexity of their technology environments, increasing both the likelihood that errors occur and the speed at which they spread.
The consequences are not limited to downtime. They can affect customer trust and business continuity. In critical cases where a software defect or misconfiguration results in a personal data breach, the Data Privacy Act of 2012 may require organizations to notify the National Privacy Commission.
Why Bring Security to the Table?
Cybersecurity was traditionally seen as distinct from software development, with reviews typically conducted near the end of development processes — well beyond the stage at which major architectural and technical decisions were made. This approach is becoming increasingly unsustainable. Many of today's security risks stem from within source code, infrastructure configurations, software dependencies, and AI-enabled development workflows.
Even among organizations that describe themselves as AI-first, governance remains a challenge: Fastly's research found that 31% remain unclear about who owns incident response responsibilities.
The demands of today require organizations to bring security closer to where software is designed and built. Straightforward steps — stronger code review processes, automated testing, vulnerability assessments, and clear guidelines for the use of AI-generated code — ensure that developers perform their due diligence and that organizations can be confident risks are identified and addressed before deployment.
Governance is equally important, because uncertainty around ownership costs valuable time during critical moments. Organizations need clear policies that define how AI tools are used, how sensitive data is handled, and who is responsible when incidents occur. This will position organizations to transform cybersecurity from a reactive, control function into a strategic capability that enhances faster innovation and stronger resilience.
The Way to Strengthen Cyber Resilience
Building security into software from the start is not a new concept, but the cost of overlooking it is becoming harder for Philippine organizations to ignore. Gartner has warned that by 2027, more than 40% of AI-related data breaches will stem from the improper use of generative AI. This is not a distant risk to be addressed in the future; it is a governance challenge that organizations need to tackle today.
This focus aligns with the broader push toward proactive cybersecurity. Initiatives from the Department of Information and Communications Technology (DICT), including its Bug Bounty Program, Cybersecurity Posture Assessment Laboratory, and DICT Trusted Assessment Provider framework, reflect a growing national emphasis on early risk detection and mitigation. They also underscore that resilience and innovation are neither mutually exclusive nor competing priorities — they naturally go hand in hand.
A genuine secure-by-design approach shapes AI integration into workflows and development pipelines. It scaffolds strong access controls, continuous monitoring, and clear governance throughout their lifecycle. At the same time, embedding security into development enables organizations to move faster with greater confidence by reducing costly rework, preventing avoidable disruptions, and allowing teams to scale new capabilities more safely.
Building Trust in the AI Era
There is no denying that the organizations that succeed are those that move quickly. But if products are released faster only to be reworked later, is the organization truly moving ahead of the competition? Is it genuinely reducing operational risk? Is it enabling its experts to innovate and scale new capabilities if much of their time is spent firefighting?
As AI continues to reshape how software is built, leaders need to rethink what speed really means. The goal is not simply to release faster, but to build digital capabilities that can scale securely, reliably, and sustainably. Achieving this will require more than defending against external attackers — it will require organizations to address the vulnerabilities that emerge within the systems businesses create.
By embedding security into development from the start, teams gain the confidence to innovate faster without compromising resilience. In the AI era, the future will, ultimately, belong to organizations that treat security as a foundation from the beginning.
Rachel Ler is the area vice-president for Asia (ASEAN, Greater China & Korea), Fastly.