Dedicated security office vs cyberattacks needed more than ever--solons
At A Glance
- Camarines Sur solons are pushing for the institutionalization of a quick-response agency that would craft and carry out a masterplan for building a robust defense infrastructure meant to shield individuals and organizations from cyberattacks.
(Unsplash)
Camarines Sur solons are pushing for the institutionalization of a quick-response agency that would craft and carry out a masterplan for building a robust defense infrastructure meant to shield individuals and organizations from cyberattacks.
Reps. Migz Villafuerte and Luigi Villafuerte, who represent Camarines Sur's 5th and 2nd districts, respectively, filed House Bill (HB) No. 2826 for this purpose.
Embodied in the measure is the proposed crearion of the National Cybersecurity Agency, (NCSA), which is tasked to standardize protocols for threat detection, information sharing and incident response, along with protection of the country’s critical information infrastructure (CII).
The Villafuertes highlighted their proposal even as the Department of Information and Communications Technology (DICT) warned of a possible cyberattack this week by way of a “traffic flood", wherein netizens might not be able to access websites, apps, and online services.
“We need to put front and center the protection of our online systems, networks and programs from attacks from threat actors who aim to access, alter or destroy sensitive information, extort money from cyber players through ransomware and/or disrupt normal government or business processes,” Migz said.
The DICT posted on its website that it has monitored a possible Distributed Denial of Service (DDoS) or “traffic flood” on Wednesday, Nov. 5, in which certain websites or apps might slow down or fail to load at once.
In HB No. 2826, the Villafuertes want the proposed NCSA, which shall be under the DICT, to put up a National Computer Emergency Response Team (NCERT). It will be composed of cybersecurity experts, who “shall respond quickly to cybersecurity incidents of threatened organizations, with the aim of minimizing the damage and ensuring recovery of affected systems".
This NCERT shall establish a liaison network of CERTs or computer emergency response teams among government agencies to support the implementation of the NCERT’s mandate.
New legislation on cybersecurity is among the 44 priority measures under the Common Legislative Agenda (CLA) that President Marcos drew up with Congress leaders during the first Legislative-Executive Development Advisory Council (LEDAC) meeting last Sept. 30 in Malacañang.
Migz says there is a need to "secure the Philippines’ digital future and make sure that our country is adequately prepared to confront and overcome the complex challenges of the modern cyber environment".
The Villafuertes said that the objectives of HB 2826 are the following:
1. Data Protection - Shielding sensitive data, personally identifiable information (PII), intellectual property, and other critical information from theft, loss, or misuse;
2. System and Network Security - Defending computer systems, networks, and connected devices (endpoints) from malicious attacks and unauthorized access; and
3. User Protection - Safeguarding individuals and organizations from identity theft, fraud, and other harms that can arise from cyberattacks.
Luigi explained that phishing involves duping people to download viruses or malware (malicious software) through fraudulent links in assorted channels like emails, mobile phone texts and websites, while ransomware involves encrypting through malware the data of persons or organizations to restrict access to their own files and systems and then demand ransom from these victims to get their data back.
Social Engineering, meanwhile, involves impersonating individuals so they can retrieve sensitive data from these targets through deception, such as pretending to be employees of banks or telecoms companies (telcos) to dupe their victims into giving them their personal passwords, Luigi said.
On top of liasoning with the network of CERTs among government agencies to support the bill’s mandate, the NCERT is tasked by HB No.2826 to perform vulnerability assessment and penetration testing initiatives to detect, identify and analyze cyber threats and to properly attribute cyber-attacks.
Camarines Sur 1st district Rep. Tsuyoshi Anthony Horibata and Bicol Saro Party-list Rep. Terry Ridon served as co-authors of the measure.