Natiional Cybersecurity Enhancement Act
Seitate Office of the Corarriarp TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES First Regular Session 25 NOV 11 P2:52 SENATE RECEIVED BY: 1492 S. No. Introduced by Senator Raffy T. Tulfo AN ACT ESTABLISHING THE PHILIPPINE CYBERSECURITY COUNCIL AND ENHANCING THE NATIONAL CYBERSECURITY FRAMEWORK EXPLANATORY NOTE In an era where daily life, governance, and the economy increasingly depend on the digital sphere, the Philippines faces growing exposure to cyber threats that undermine national security and the welfare of ordinary Filipinos. From phishing scams and identity theft to cyberbullying, fake news, and ransomware attacks on government systems, these dangers affect not only institutions but the lives and livelihoods of millions of citizens. The International Telecommunications Union's 2024 Global Cybersecurity Index (GCI) ranked the Philippines 53rd out of 194 countries, placing it in the "advancing" category. This reflects the country's ongoing efforts to strengthen its digital defenses. However, despite this progress, cyberattacks on local businesses, hospitals, and government agencies have increased in recent years, compromising sensitive information and undermining public trust in online systems?. While the Cybercrime Prevention Act of 2012 penalizes offenses committed in cyberspace, the country still lacks a unified and proactive cybersecurity framework that ensures coordination among government agencies and protection for citizens ' International Telecommunication Union. Global Cybersecurity Index 2024 (GCIv5). Geneva: International Telecommunication Union, 2024. 2 Donald Patrick Lim, "Launching a United Defense: The Cybersecurity Council of the Philippines," BusinessWorld Online, June 17, 2025, https://www.bworldonline.com/opinion/2025/06/18/679708/launching-a-united-defense-the-cybersecurity-council-of- the-philippines/ # google_vignette.
before, not only after, an attack occurs. The absence of clear lines of accountability and rapid public response mechanisms has left many Filipinos, especially the poor and digitally vulnerable, without accessible channels for redress. This proposed measure seeks to strengthen the Philippines' national cybersecurity framework by establishing a National Cybersecurity Council, institutionalizing inter-agency coordination, and enhancing the capacities of the Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC). It also introduces provisions unique to this measure, such as the creation of a Public Cyber Complaint and Rapid Response Unit to assist citizens affected by cybercrimes, scams, or data breaches, and the establishment of a Cyber-Justice Assistance Desk to provide free legal support to victims of online abuse and exploitation. Furthermore, the bill underscores transparency and accountability in government cyber operations by mandating regular public reports on the state of national cybersecurity, public education campaigns in partnership with media and civil society, and strict penalties for negligence leading to breaches of public data. This measure recognizes that cybersecurity is not only a matter of national defense, but also of public service, consumer protection, and social justice. Protecting Filipinos in the digital world is as vital as protecting them on the streets and its of utmost importance that the government ensures that technology empowers, rather than endangers, its people. In view of the foregoing, the immediate passage of this bill is earnestly sought. RAFFY T. TULFO
senate Office of the Secretary TWENTIETH CONGRESS OF THE REPUBLIC OF THE PHILIPPINES First Regular Session NOV 11 P2:52 SENATE RECEIVED BY: S. No. 1492 Introduced by Senator Raffy T. Tulfo AN ACT ESTABLISHING THE PHILIPPINE CYBERSECURITY COUNCIL AND ENHANCING THE NATIONAL CYBERSECURITY FRAMEWORK Be it enacted by the Senate and the House of Representatives of the Philippines, in Congress assembled:
Section 1. Short title. - National Cybersecurity Enhancement Act
Sec 2. Declaration of Policy. - It is the policy of the State to protect the Filipino
people and the nation's institutions from all forms of cyber threats and attacks that endanger public safety, privacy, and national security. The State recognizes that access to safe and reliable cyberspace is a basic public right and a foundation of national progress. The State shall strengthen the country's capability to prevent, detect, and respond to cyber incidents by building a secure digital environment that upholds 9 transparency, accountability, and the protection of personal data. It shall ensure that every Filipino whether an individual user, worker, or business is defended from online abuse, fraud, exploitation, and misinformation. To this end, the government shall institutionalize a unified national cybersecurity framework that promotes cooperation among public and private sectors, enhances digital resilience, and guarantees that technology serves the welfare of the people and the integrity of the Republic.
Sec 3. Creation of the National Cybersecurity Council. - There is hereby created
2 a National Cybersecurity Council, hereinafter referred to as the Council, which shall 3 serve as the primary policy-making, coordinating, and monitoring body on all matters relating to cybersecurity, cyber-terrorism, and the protection of critical information 5 infrastructure in the Philippines. The Council shall be attached to the Office of the President for policy direction 7 and oversight and shall be chaired by the Secretary of the Department of Information 8 and Communications Technology (DICT). The Executive Secretary and the Director- 9 General of the National Intelligence Coordinating Agency (NICA) shall serve as Co- 10 Chairpersons. The Council shall be composed of the following members: a. Secretary of the Department of Foreign Affairs (DFA); b. Secretary of the Department of Science and Technology (DOST); C. Secretary of the Department of the Interior and Local Government (DILG); d. Secretary of the Department of Justice (DOJ; e. Secretary of the Department of National Defense (DND); f. Chairperson of the National Privacy Commission (NPC); g. Commissioner of the National Telecommunications Commission (NTC); h. Director of the National Bureau of Investigation (NBI); i. Chief of the Philippine National Police (PNP); and j. Executive Director of the Cybercrime Investigation and Coordinating Center (CICC). The Council shall coordinate closely with the Anti-Terrorism Council on matters involving cyber-terrorism and digital threats to national security, ensuring that preventive and investigative actions respect human rights and due process while maintaining the safety of the public and the integrity of the State. The Council may invite representatives from other public and private institutions, including the business sector, academe, and civil society organizations, to participate in meetings or consultations relevant to cybersecurity. 30 The DICT Cybersecurity Bureau shall serve as the Secretariat of the Council and shall provide technical and administrative support necessary for the effective performance of its functions.
SEC. 4. Powers and Functions. - The Council shall formulate and implement a
2 unified national cybersecurity policy and ensure the protection of the country's 3 information and communications technology systems, networks, and critical information infrastructure. It shall serve as the central authority for coordinating 5 cybersecurity efforts across all government agencies and private institutions. In pursuit of this mandate, the Council shall have the following powers and functions: a. Policy Direction - Formulate, update, and oversee the implementation of the National Cybersecurity Plan and related strategies to strengthen digital resilience and public protection. b. Coordination and Monitoring - Coordinate all cybersecurity activities of national government agencies, local government units, government-owned or - controlled corporations, and private sector partners, and monitor compliance with national cybersecurity standards. c. Cyber-Terrorism Prevention and Response - Coordinate with the Anti-Terrorism Council (ATC) and relevant law enforcement and defense agencies to prevent, detect, and respond to cyber-terrorism and digital threats that endanger public safety or national security. d. Incident Response - Oversee the establishment of a National Computer Emergency Response Team (NCERT) and ensure the continuous operation of the National Security Operations Center (NSOC) to respond to cybersecurity incidents. e. Capacity Building - Develop training, certification, and public education programs to raise cybersecurity awareness and skills among government employees, businesses, and the general public. f. Public Protection and Assistance - Establish a Public Cyber Complaint and Rapid Response Unit and a Cyber-Justice Assistance Desk to provide immediate help and free legal aid to citizens affected by cybercrimes, scams, and online exploitation. g. Partnerships and International Cooperation - Strengthen coordination with foreign governments, international organizations, and global cybersecurity networks for information exchange and joint capacity-building initiatives.
h. Standards and Accreditation - Recommend minimum cybersecurity standards, accreditation requirements, and risk-management protocols for both public and private ICT systems handling sensitive or personal data. i. Other Functions - Perform such other powers and duties as may be necessary to fulfill its mandate under this Act and other existing laws.
Sec 5. Meetings of the Council. - The Council shall meet at least once every
7 quarter to review the state of national cybersecurity, assess emerging threats, and 8 evaluate the implementation of ongoing programs and policies. Special meetings may be convened by the Chairperson, or upon the written request 10 of any two (2) Co-Chairpersons, in cases of urgent cyber incidents, large-scale data breaches, or threats to critical information infrastructure or national security. A majority of all the members of the Council shall constitute a quorum. Decisions shall be made by a majority vote of the members present. The Council may create technical working groups or subcommittees to focus on specific areas such as cyber-terrorism prevention, data protection, financial security, or public complaint response. These groups shall submit their reports and recommendations to the Council for approval. The Secretariat shall prepare the agenda, minutes, and documentation of all meetings and shall ensure that summaries of non-classified actions and resolutions are made available for public access, consistent with national security and data privacy laws.
SEC. 7. Reporting of Cybersecurity Breaches. - All government agencies,
government owned or controlled corporations, and private entities operating critical information infrastructure shall immediately report any cybersecurity breach, incident, or data compromise to the National Cybersecurity Council, through the Cybercrime Investigation and Coordinating Center and the National Computer Emergency Response Team. The initial report shall be made within twenty-four (24) hours from discovery of the breach and shall include basic details necessary to assess the nature, scope, and possible impact of the incident. A full report shall be submitted within seventy- two (72) hours thereafter, unless otherwise extended by the Council for justifiable reasons.
Entities handling personal or sensitive information shall also notify affected individuals and the National Privacy Commission (NPC) in accordance with the Data 3 Privacy Act of 2012. Failure to report a breach or the deliberate concealment of material information 5 shall constitute gross neglect and may result in administrative, civil, or criminal liability under this Act and other applicable laws. The Council shall maintain a confidential National Cyber Incident Registry for classified data and a public advisory system that promptly informs citizens, without disclosing sensitive details, of major cyber threats or ongoing attacks that could 10 endanger public welfare or essential services.
SEC. 8. Implementing Rules and Regulations. - The DICT, the DO], the DILG
and the NSC shall jointly formulate the necessary rules and regulations within ninety (90) days from approval of this Act, for its effective implementation.
SEC. 9. Separability Clause. - If any provision of this Act is here invalid, the
other provisions not affected shall remain in full force and effect.
SEC. 10. Repealing Clause. - All laws, decrees, orders, rules and regulations or
other issuances or part thereof inconsistent with the provisions of this Act are hereby repealed accordingly.
SEC. 11. Effectivity. - This Act shall take effect fifteen (15) days after its
publications in the Official Gazette or in any two (2) newspapers of general circulation in the Philippines. Approved,
Text extracted from the scanned Senate document via OCR — it may contain recognition errors. The official PDF is the authoritative version.