Phl firms urged to tighten endpoint security



Philippine National Police chief Gen. Jose Melencio Nartatez Jr. on Tuesday committed to implementing additional…

The average cost of a data breach in Southeast Asia climbed to a record $4.12 million in 2026 as artificial…

Nvidia has struck deals with some of Wall Street’s biggest financial firms to help its customers finance the massive…

The Department of Finance (DoF) and French development agency Agence Française de Développement (AFD) have partnered to…

Malaysia is eyeing Clark and New Clark City as launchpads for a bigger push into the Philippines, bringing a mission of…
Philippine businesses should strengthen endpoint security as the growing number of devices connected to corporate networks creates more opportunities for cyberattacks, according to a cybersecurity expert.
Subhalakshmi Ganapathy, chief IT security evangelist at ManageEngine, warned that laptops, desktops, mobile devices and servers have become potential attack vectors as businesses accelerate digitalization.
“Every laptop, desktop, mobile device, and server has become both a productivity tool and a potential attack vector,” Ganapathy said. “If organizations cannot see, manage, and secure every endpoint from a centralized platform, they are leaving critical gaps that attackers will inevitably exploit,” she added.
The Philippine digital economy was valued at P2.74 trillion last year, accounting for nearly 10 percent of gross domestic product. Meanwhile, nearly 25 million Filipinos fell victim to cybersecurity incidents, with SMS fraud accounting for more than 57 percent of attacks, according to figures cited by Ganapathy.
She said the threat continues to grow as phishing, malware, credential theft and ransomware become more sophisticated.
The government has also moved to strengthen data security requirements through President Ferdinand Marcos Jr.’s Executive Order No. 119, which covers data governance, residency, classification and cross-border data transfers.
“In effect, this compels organizations to know where their data resides, who can access it, and which endpoint devices interact with it every day,” Ganapathy said.
She said small and medium enterprises are particularly vulnerable as lean IT teams and limited budgets make maintaining dedicated cybersecurity operations difficult.
Many organizations have instead turned to managed service providers, or MSPs, for endpoint management, infrastructure monitoring, patching, compliance and security operations.
Ganapathy said MSPs may be responsible for hundreds or thousands of endpoints across several customers, making centralized management and automation increasingly important.
“MSPs need something more nimble. They need intelligent automation along with a unified platform that brings together endpoint management, patching, vulnerability remediation, policy enforcement, asset visibility and compliance,” she said.
The shift toward remote work and cloud-based applications has also changed where businesses need to focus their defenses.
“For years, organizations invested heavily in defending the corporate network. The problem is that today’s business no longer operates within one,” Ganapathy said.
“Employees work from anywhere, business applications live in the cloud, and endpoints connect from virtually every location imaginable. The perimeter hasn’t just expanded; it has dissolved and been replaced by the endpoint, which has become the new frontline,” she added.
Ganapathy said cybersecurity should therefore be integrated into routine IT operations instead of being added after new technologies are deployed.
“Businesses need to know what devices are connected to their environment, whether they’re properly configured, whether critical patches have been applied, and whether unusual activity is detected before it develops into a serious incident,” she said.
She also pushed for greater use of automation for routine work such as patch deployment, policy enforcement, software updates, asset discovery and incident response.
“Organizations must turn to intelligent automation, not to replace people, but to allow them to focus on higher-value work,” Ganapathy said.
She added that endpoint management should be integrated with governance and compliance as regulatory requirements evolve.
“Ultimately, endpoint security is about much more than preventing cyberattacks,” Ganapathy said.
“It is about giving organizations the confidence to innovate, grow, and embrace new technologies without losing control of their IT environment.”