Editorial: What Is DICT’s Cybersecurity Bureau Doing?
EDITORIAL
October is Cybersecurity Awareness Month, but government’s biggest cybersecurity problem may not be technology. It is accountability.
Every time a government website is defaced or a system is breached, the response sounds familiar: the incident has been contained, systems are safe and an investigation is ongoing.
Then public follow-through becomes difficult to find. What vulnerability was exploited? Was it fixed? Were other agencies checked for the same weakness?
Cybersecurity must also be separated from cybercrime. Cybersecurity is about protecting systems, managing vulnerabilities and preventing or limiting attacks. Cybercrime deals with offenses and the people behind them. CICC belongs primarily to the cybercrime side. Government cybersecurity sits with DICT.
DICT already has a Cybersecurity Bureau tasked with implementing the National Cybersecurity Plan 2023-2028 and overseeing NCERT. So the question is no longer whether government has a plan or an organization.
What exactly is the problem?
Is it a shortage of cybersecurity talent? Are government systems outdated? Is there insufficient funding? Are agencies failing to fix known vulnerabilities? Or does the Cybersecurity Bureau simply lack enough authority to make agencies comply?
Those are the questions government should answer.
PhilHealth, DOST, the Senate, House, DMW and DOLE have suffered cybersecurity incidents. More embarrassing, even a DICT staging website was defaced as Cybersecurity Awareness Month opened.
Government once heavily promoted CyberDome. Today, we barely hear about it. Cybersecurity cannot be another PR campaign that disappears with the headlines.
The talent, system and infrastructure gaps may all be real. But government first needs to identify which gap is actually causing repeated failures, who is responsible for fixing it and whether the Cybersecurity Bureau has the power and resources to do the job.
This Cybersecurity Awareness Month, DICT should tell us plainly: What is wrong with government cybersecurity, and what is the Cybersecurity Bureau doing about it?
