Villafuertes upbeat on National Cybersecurity Agency creation as bill moves forward in plenary
At A Glance
- House Bill 9605 advances, proposing a National Cybersecurity Agency under DICT.
- Rep. Migz Villafuerte frames cybersecurity as national security, requiring permanent institutional response.
- Rep. Luigi Villafuerte cites urgency after EO 119 and rising cyber fraud cases like GCash "quishing".
The House plenary (Contributed photo)
Camarines Sur Reps. Migz Villafuerte (2nd district) and Luigi Villafuerte (5th district) are upbeat over the imminent establishment of the proposed National Cybersecurity Agency (NCSA) under the Department of Information and Communications Technology (DICT).
This, after the recent approval by the House of Representatives on second reading of House Bill (HB) No. 9605 or the “National Cybersecurity and Critical Information Infrastructure Protection (CIIP) Act of 2026".
Rep. Migz chairs the House Committee on Information and Communications Technology (ICT), which endorsed the approval of the bill that served as the substitute measure of 26 CIIP or cybersecurity-related bills.
In his sponsorship speech on Aug. 3, Rep. Migz said on the plenary floor that cybersecurity was no longer an ICT concern alone, in light of mounting reliance on digital systems in all sectors. He says it has transformed into a national security concern.
Hence, he said, the NCSA, as proposed in HB No. 9605, aims to facilitate a whole-of-government approach to handling cybersecurity, beef up response to cyber attacks, establish minimum standards for CIIP, and provide for congressional oversight, judicial review and legal accountability.
“The question is no longer whether our country will experience another major cyber attack; the question is whether we are prepared for it when that happens,” said the 2nd district congressman.
"And because such a threat has become permanent, our institutional response must also be a permanent one.”
The proposed NCSA, he added, would strengthen national coordination, improve incident response, and establish minimum cybersecurity standards for critical information infrastructure.
Rep. Luigi noted that the approval of this cybersecurity bill became urgent on the heels of President Marcos’ recent issuance of Executive Order (EO) No. 119, which updated the Government Data Classification Framework of 1964 to accelerate the country’s digital transformation while safeguarding Filipinos against cybersecurity risks.
As regards cybersecurity risks, he said that mobile payments service provider GCash, for instance, reported last July having blocked some 6,700 bogus merchant accounts tied to QRPh scams known as "quishing", in which bad actors use phony QR codes to redirect users to fake GCash payment pages or illegitimate accounts to steal cash from the victims.
The proposed Cybersecurity Act was among the 48 priority measures that President Marcos identified for urgent action last year with the legislative-Executive Development Advisory Committee (LEDAC).
Rep. Migz said, “Ang panukalang batas na ito ang magbibigay ng permanenteng institutional framework upang maprotektahan ang ating mga kritikal na sistema, mapatatag ang ating pambansang katatagan, at mapangalagaan ang tiwala ng ating mga mamamayan sa digital na ekonomiya.”
(This proposed law will provide a permanent institutional framework to protect our critical systems, strengthen our national resilience, and safeguard the trust of our citizens in the digital economy.)
“Ang cybersecurity ay hindi na lamang usapin ng teknolohiya. Isa na itong usapin ng pambansang seguridad. At kung permanente ang banta, permanente rin dapat ang ating institutional response,” he added.
(Cybersecurity is no longer just a matter of technology. It has become a matter of national security. And if the threat is permanent, our institutional response must also be permanent.)