The digital economy demands that organizations embed cybersecurity and data protection into long‑term strategy as technology underpins almost every operation.
At the opening session of a recent cybersecurity summit, experts examined how global regulations are shaping Philippine firms and argued that mere compliance no longer guarantees robust security.
Alvin Navarro, assistant secretary of the Cybercrime Investigation and Coordinating Center, emphasized that cyber threats affect government, national security and everyday citizens, noting that scams generate more than 60 % of complaints.
He warned that digital transformation must incorporate security at every stage, otherwise failures could destabilize the economy, political stability and national survival.
Gilbert Trinchera, technology consulting partner at a leading firm, identified eight converging forces—artificial intelligence, geopolitics, regulation, hyper‑connectivity, non‑human identities, supply‑chain dependencies, post‑quantum cryptography and autonomous security—that are reshaping the threat landscape.
He argued that organizations must move beyond checklists, adopt proactive risk‑averse postures and demonstrate trust to clients and stakeholders.
Jay‑R Ipac, managing partner of a law firm, highlighted the EU’s GDPR and NIS2 Directive as key regulations influencing local companies, noting that even draft frameworks signal a shift toward organizational resilience.
He cited the central bank as an active regulator, stressing that financial institutions confront rapid tech change and sophisticated digital threats.
Kristoffer Rada, head of corporate affairs at a major fintech firm, observed that worldwide cyber laws now hold boards and senior executives accountable, expanding responsibility beyond technical teams.
He said the focus has moved from prevention to operational resilience—detecting, responding, recovering and maintaining essential services.
Rada added that technology must be paired with public education, urging risk‑based, outcome‑oriented regulation and timely, accurate transparency for consumers.
The panelists agreed that cybersecurity leadership is evolving from a purely technical function to a governance issue, with many firms still relying on chief information security officers while neglecting broader accountability.
Ipac warned that policies and documentation often prove insufficient during an actual breach and called for a culture where every stakeholder prioritizes security.
Navarro stressed that business leaders need enough technical insight to make informed decisions and to safeguard national security.
The rapid adoption of artificial intelligence raises new stakes, as the same tools that enhance defenses also enable sophisticated attacks, scams and disinformation.
Trinchera noted that AI legislation lags behind deployment, leaving organizations without clear accountability and creating a “playground” for misuse.
He urged regulatory convergence aimed at preserving trust, describing trust as the universal currency across industries and jurisdictions.
Navarro acknowledged legislative efforts to keep pace with AI but encouraged firms to establish internal AI governance policies tailored to their risk profiles.
Maya’s Rada described how AI assists in detecting suspicious financial transactions, illustrating how technology can bolster security when combined with collaborative policy making.
The experts concluded that effective cybersecurity requires coordinated action between public and private sectors, with ongoing dialogue to shape rational policies that address emerging threats.