Pass NCA law soon, Congress urged

THE growing threat of cyberattacks against financial platforms, government databases, power systems, transportation networks, and healthcare services has intensified the push in Congress to establish a permanent National Cybersecurity Agency.

House Committee on Information and Communications Technology Chairman Migz Villafuerte said the proposed agency would strengthen the country’s ability to prevent and respond to cyberattacks, which now pose risks not only to computers but also to the economy, public services, and the safety of Filipinos.

The proposal gained urgency after GCash reported blocking approximately 6,700 fraudulent merchant accounts connected to ‘quishing’ scams in July. During the same month, the Philippine National Police Anti-Cybercrime Group conducted 6,845 cyber patrol operations and at least 220 digital forensic examinations.

Villafuerte expressed optimism about the proposed establishment of the NCSA under the Department of Information and Communications Technology (DICT), following the House of Representatives’ recent approval on second reading of House Bill 423, or the ‘National Cybersecurity and Critical Information Infrastructure Protection Act of 2026.’

The substitute measure was consolidated by a technical working group from 26 cybersecurity- and

critical information infrastructure protection-related bills discussed by the committee during the First Regular Session.

In his sponsorship speech on August 3, Villafuerte told the House that cybersecurity is no longer solely an information and communications technology concern. The country’s growing dependence on digital systems across government, the economy, finance, transportation, healthcare, and energy has transformed cybersecurity into a national security issue.

The proposed NCSA aims to establish a whole-of-government approach to cybersecurity, strengthen the country’s response to cyberattacks, set minimum standards for protecting critical information infrastructure, and provide mechanisms for congressional oversight, judicial review, and legal accountability.

‘The question is no longer whether our country will experience another major cyber attack; the question is whether we are prepared for it when that happens,’ Villafuerte said. ‘And because such a threat has become permanent, our institutional response must also be a permanent one.’

He added that the proposed agency would strengthen national coordination, improve incident response, and establish minimum cybersecurity standards for critical information infrastructure.

‘The question now is no longer whether we will experience another major cyberattack. The question is whether our country will be ready when it happens,’ Villafuerte said.

‘This proposed law will provide a permanent institutional framework to protect our critical systems, strengthen national resilience, and preserve the public’s trust in the digital economy,’ he said.

According to Villafuerte, cybersecurity is no longer merely a technological issue. It has become a matter of national security, saying, ‘If the threat is permanent, then our institutional response must also be permanent.’

Villafuerte noted that the country’s economy, financial system, power supply, transportation network, healthcare services, and government service delivery now rely heavily on digital systems.

‘When these systems are compromised by a cyberattack, it is not only computers that are affected. The economy, public services, and the safety of every Filipino are also placed at risk,’ he said.

Camarines Sur Rep. Luigi Villafuerte, another author of the bill, said the passage of the cybersecurity measure had become more urgent following President Ferdinand Marcos Jr.’s issuance of Executive Order No. 119. The order updated the government’s data classification framework, which had been in place since 1964, to accelerate the country’s digital transformation while protecting Filipinos from cybersecurity risks.

Executive Order No. 119 allows government agencies to adopt cloud technologies and introduces a modern data security framework. It also establishes standardized cybersecurity practices for protecting government information and strengthens the country’s resilience against cyberthreats.

The proposal is among the 48 priority measures identified by Marcos for urgent legislative action in coordination with the Legislative-Executive Development Advisory Council.

Leave a Reply

Your email address will not be published. Required fields are marked *