BUSINESS
Hacking incidents risk Phl viability as investment destination — IBPAP
The ramifications of cyberattacks extend beyond immediate financial losses. They can inflict lasting damage on businesses, leading to client attrition, reputational harm, and long-term financial implications
The IT and Business Process Association of the Philippines on Tuesday is airing deep alarm following the cyberattacks that targeted various government agencies, including the House of Representatives and the Philippine Statistics Authority which not only jeopardize the operations of the IT-BPM industry but also the reputation of the Philippines as an attractive investment destination.
In a statement, Jack Madrid, president of IBPAP, said the IT-BPM industry, which is projected to generate revenues of $35.4 billion by the end of 2023, has acknowledged that cyberattacks could potentially lead to substantial losses.
Heightened state of alertness
"IBPAP recognizes the need to maintain a heightened state of alertness, recognizing the inherent risks from its dependence on digital technologies and systems that host substantial volumes of sensitive data. More importantly, the ramifications of cyberattacks extend beyond immediate financial losses. They can inflict lasting damage on businesses, leading to client attrition, reputational harm, and long-term financial implications," he said.
Last month, state insurer Philippine Health Insurance Corporation (PhilHealth) was reportedly attacked by Medusa Ransomware, compromising some members' personal and sensitive information, such as addresses, and social security numbers, among others.
Also, a separate cyberattack hit the Philippine Statistics Authority, which announced on 12 October that personal and sensitive data from its Community-Based Monitoring System had been accessed by "bad actors."
Meanwhile, the website of the House of Representatives was also hacked last week.
What to do
In preventing cyberattacks from happening again, Madrid suggests that all entities, whether private or public, adopt a zero-trust approach and implement a zero-trust architecture to ensure that no user or device is automatically trusted, and that verification is required at every step.
"Invest in artificial intelligence or AI and machine learning, or ML-led threat hunting. Utilize AI and ML technologies to proactively identify and mitigate potential threats; enhance threat intelligence capabilities by developing robust threat intelligence capabilities to include monitoring and analyzing threat intelligence feeds, collaborating with peers in the sector, and leveraging threat intelligence platforms; and strengthen cybersecurity skills by addressing the cybersecurity skills gap by investing in training and upskilling programs for employees," he said.
Further, he said, companies and government agencies should implement strong data privacy and security measures by establishing policies and frameworks to protect sensitive data and ensure compliance with data privacy regulations.
"Regularly update and patch systems by keeping all software, applications, and systems up to date with the latest security patches and updates. Regularly scan for vulnerabilities and apply necessary patches to mitigate potential risks, and conduct regular security assessments by performing regular security assessments and penetration testing to identify vulnerabilities and weaknesses in the organization's infrastructure," he said.