NotizieMacroIl BusinessWorld Cybersecurity Summit sollecita il passaggio alla resilienza informatica mentre aumentano le minacce basate sull’IA

Il BusinessWorld Cybersecurity Summit sollecita il passaggio alla resilienza informatica mentre aumentano le minacce basate sull’IA

Autore: Bworldonline·

Punti chiave

  • L’Executive Director del CICC ha invitato le organizzazioni filippine a passare da una cybersecurity focalizzata sulla prevenzione a piani di resilienza informatica che garantiscano continuità operativa quando gli attacchi superano inevitabilmente le difese.
  • Gli esperti hanno avvertito che strategie di sicurezza sofisticate falliscono spesso perché i dipendenti in prima linea, responsabili dell’implementazione, non comprendono lo scopo delle misure.
  • I CISO hanno sottolineato che la responsabilità ultima degli incidenti informatici ricade sui CEO e sulla leadership apicale, che possono delegare i compiti ma non la responsabilità.
  • I relatori hanno evidenziato che l’AI è al tempo stesso uno strumento difensivo per l’analisi delle minacce e un’arma offensiva per i cybercriminali, rendendo necessario stabilire baseline adeguate per la sicurezza basata sull’AI.
  • Il keynote conclusivo ha sostenuto che nella digital economy la fiducia è più preziosa dei dati, poiché tutte le transazioni digitali, la governance e l’innovazione dipendono dalla fiducia nella protezione delle informazioni.
Il BusinessWorld Cybersecurity Summit sollecita il passaggio alla resilienza informatica mentre aumentano le minacce basate sull’IA

By Bjorn Biel M. Beltran, Special Features and Content Assistant Editor

La cybersecurity è diventata una lotta difensiva permanente, in cui comprendere l’avversario conta tanto quanto conoscere le proprie capacità. La domanda che le organizzazioni si pongono oggi è come difendersi da avversari dotati di una tecnologia in continua evoluzione e potenziata dall’intelligenza artificiale (AI).

Su questo presupposto si è aperto il BusinessWorld Cybersecurity Summit, tenuto con il tema "Toward Stronger Digital Defenses" — un appello urgente a riconsiderare le protezioni delle Filippine contro le minacce informatiche emergenti.

Lucien C. Dy Tioco, executive vice-president di BusinessWorld, ha aperto l’evento sottolineando la necessità di un fronte unito contro gli attacchi informatici alimentati dall’AI e di proteggere la rapida espansione dell’economia digitale del Paese.

"The Philippines is home to millions of businesses, with micro, small, and medium enterprises making up 99% of all businesses in the country," Mr. Dy Tioco ha dichiarato nel suo discorso di benvenuto. "These enterprises are continuing their digital transformation, making cybersecurity a technical safeguard that enables economic growth, innovation, and public confidence."

"Every investment in cybersecurity is an investment in trust. Every collaboration strengthens our collective resilience. Every conversation we sustain in this respect brings us one step closer to a digital economy that is secure, innovative, and inclusive," ha aggiunto.

Atty. Renato "Aboy" A. Paraiso, executive director del Cybercrime Investigation and Coordinating Center (CICC), ha tenuto il keynote inaugurale chiedendo un passaggio dalla pura prevenzione alla resilienza informatica olistica. Ha spiegato che, mentre la cybersecurity tradizionale mira a fermare gli attacchi e a mitigare i rischi, la resilienza consente alle organizzazioni di mantenere la continuità operativa e limitare i danni quando — non se — gli attacchi superano le difese.

"While cybersecurity is designed to prevent attacks, cyber resilience, on the other hand, ensures that when an attack gets through, as some inevitably will, organizations can continue operating, minimize the damage, recover quickly, and emerge stronger from the experience," ha detto.

"Every business should have a practical cyber-resilience plan so that it can respond effectively when an attack happens," ha aggiunto.

The CICC operates under the Office of the President and was created by the Cybercrime Prevention Act of 2012 (Republic Act No. 10175) to coordinate national cybercrime response across law enforcement, intelligence, and regulatory agencies.

Mettere in pratica la resilienza informatica

Il primo panel del summit ha esaminato gli sviluppi dei quadri normativi, delle politiche di sicurezza nazionale e dell’esecuzione operativa a livello mondiale.

Gilbert T. Trinchera, technology consulting partner presso R.G. Manabat & Co. (KPMG in the Philippines), ha sostenuto che le organizzazioni devono andare oltre il semplice spuntare le voci di compliance e concentrarsi invece sulla gestione del rischio e sulla convergenza normativa tra giurisdizioni.

"Regulatory convergence should be our goal, and we should align it to our ultimate vision, which is to maintain trust. This is the current universal currency that everybody understands, regardless of industry or jurisdiction," ha detto.

In the Philippines, data protection obligations are anchored in the Data Privacy Act of 2012 (Republic Act No. 10173), which established the National Privacy Commission, while the Cybercrime Prevention Act addresses offenses such as illegal access, data interference, and identity theft.

Atty. Jay-R C. Ipac, managing partner di Divina Law, ha sottolineato che le strategie di sicurezza di alto livello falliscono spesso quando i dipendenti in prima linea non ne comprendono lo scopo.

"The usual failure in implementing sophisticated cybersecurity measures," ha aggiunto, "is that the people who will be implementing it on the ground do not really understand what they’re doing in the first place. We have to make them understand why we are doing this."

Leadership durante gli incidenti di sicurezza

Il secondo panel ha spostato l’attenzione sulla leadership durante incidenti di sicurezza ad alto rischio.

"Assume a breach is not a possibility, but an inevitability. Crisis command is a leadership discipline, not a technical one," ha detto Dennis Matthew F. Opiso, chief information security officer (CISO) di JG Summit Holdings, Inc.

Engr. Luis A. Jacinto, presidente e membro fondatore dell’Information Security Officers Group, ha chiarito che, sebbene i compiti operativi possano essere delegati a team specializzati, la responsabilità ultima resta alla leadership apicale.

"The ultimate responsibility and accountability goes to the CEO; he can delegate the responsibility, but not the accountability," ha detto.

Mar Apuhin, CISO di GT Capital Holdings, Inc., ha avvertito le aziende sui rischi della speculazione pubblica prematura e delle direttive interne vaghe durante una violazione in corso.

"The biggest mistake [during an attack] is communicating before facts are verified," ha detto. "It is also a mistake to provide vague guidance to internal teams, employees, and customers. The main message should be transparency grounded in verified facts and what the laws require."

Controlli tecnici e umani

Il terzo panel ha esaminato i controlli tecnici e umani necessari per proteggere le organizzazioni moderne.

Catherine Anne Paleracio, CISO di Tonik, ha sottolineato che i controlli di sicurezza dovrebbero fungere da abilitatore del business e non da barriera operativa, e che tali controlli devono sfruttare l’AI.

"For security professionals, AI is helpful to do the analysis of big data, even for analyzing behavior. But at the same time, cybercriminals are using the same technology. So, we need to put a proper baseline for the AI to function. It doesn’t know what to do right away. We have to teach it," ha detto.

La difesa di un’organizzazione è forte quanto il suo anello più debole, e spesso questi anelli sono le persone stesse. Per questo, le organizzazioni devono fare tutto il possibile per rafforzare e far rispettare ai propri dipendenti i corretti protocolli di accesso, come ha osservato Mark Anthony P. Almodovar, executive director for Risk Services — Cybersecurity and Privacy presso PwC Philippines.

"Access control is the most basic and most fundamental control in information security. Remember the people aspect. Most of the time, they are reluctant. Most of the time, only when they experience it, when they are compromised, when they lose money, their accounts have been taken over, that’s the time when they will start implementing it," ha detto.

Il quarto panel del summit ha esplorato "Cybersecurity as a Business Enabler: Leveraging Security for Growth", discutendo di come la sicurezza influenzi la valutazione dell’impresa e la fiducia del mercato.

Alexis Bernardino, principal CXO advisor e head of CXO Advisory di PLDT Enterprise, ha spiegato come la cybersecurity si sia evoluta da semplice misura di protezione dei ricavi a strumento che garantisce la continuità operativa.

"Nowadays, it is no longer about digital transformation," ha detto. "The issue is no longer cybersecurity. What we need to envision is digital resilience, that our organization will still function, be up and running even though we are under duress or under attack."

Alan Reyes, presidente e CEO di Hexcore Labs e general manager di Lightstream8 Corp., ha invitato i leader a considerare la sicurezza in termini di gestione del rischio commerciale piuttosto che di gergo tecnico complesso.

"Cybersecurity, at its core, is nothing more than risk management. Business people understand risk management but not firewalls, endpoint protections and things like that."

Fiducia, preparazione, collaborazione

A chiusura del summit, il Chairman del Cybersecurity Council of the Philippines, Dr. Donald Lim, ha tenuto un keynote chiedendo un Paese digitale più sicuro, sostenendo che tecnologia e politiche da sole non possono mettere in sicurezza il Paese senza leader che diano priorità a fiducia, preparazione e collaborazione.

"Technology alone cannot make a nation secure. Even the best policies cannot make a nation secure," ha detto.

Ha concluso ridefinendo il valore nell’era digitale: "People say that data is the new oil. I would agree to disagree. In today’s economy, trust is more valuable than data. People only transact when they trust. Citizens only embrace digital government when they trust that their information is protected. Businesses only innovate when customers believe their privacy is respected. The real product we are protecting is not information; it is confidence. Because when trust disappears, everything else begins to slow down."

The BusinessWorld Cybersecurity Summit was presented by BusinessWorld Publishing Corp., together with GCash and Maya, with the support of sponsors JuanHand, X10 Technologies, and TCS; partner organizations Asian Consulting Group, Asia Society of the Philippines, British Chamber of Commerce of the Philippines, French Chamber of Commerce and Industry in the Philippines, Management Association of the Philippines, Philippine Chamber of Commerce and Industry, Philippine Franchise Association, and the Philippine Retailers Association; creative partner ConSync Digital; and media partner The Philippine STAR .