BillBuddy
Back to SBN-2085

Cybersecurity Act

SBN-2085 · 20th Congress · verbatim text↗ Official Senate PDF

Senate Office of the Secretarp TWENTIETH CONGRESS OF THE 26 MAY -4 P3:27 REPUBLIC OF THE PHILIPPINES First Regular Session ) RECEIVED BY: SENATE 2085 Senate Bill No. _ Introduced by Senator Erwin T. Tulfo AN ACT STRENGTHENING THE NATIONAL CYBERSECURITY SYSTEM BY INSTITUTIONALIZING EXECUTIVE ORDER NO. 95, AND ENHANCING PROTECTION AGAINST CYBER THREATS, AND FOR OTHER PURPOSES EXPLANATORY NOTE The Philippines is undergoing a rapid digital transformation, driven by the expansion of e-governance, digital banking, e-commerce, and the increasing use of online platforms by Filipinos in their daily lives. Government initiatives such as digital public services, online financial transactions, and interconnected critical systems have significantly improved efficiency and accessibility. However, this growing dependence on information and communications technology has likewise heightened our country's exposure to cybersecurity threats. In recent years, the Philippines has experienced a surge in cyber incidents, including data breaches affecting government databases, ransomware attacks, online fraud, disinformation campaigns, and intrusions targeting critical information infrastructure such as energy, telecommunications, transportation, and financial systems. These incidents not only disrupt essential services but also erode public trust, compromise sensitive personal data, and threaten national security.

The bill aims to institutionalize and enhance the National Cybersecurity Council by ensuring a unified leadership in cybersecurity governance, improving inter-agency coordination, and establishing clear standards for the protection of government systems and critical digital assets. A key feature of the measure is the formulation of a National Cybersecurity Plan, which will serve as the country's strategic blueprint for safeguarding cyberspace. Ultimately, this proposed legislation aims to strengthen the country's cybersecurity posture by establishing a resilient, coordinated, and forward-looking framework that is responsive to evolving digital threats. In view of the foregoing, the immediate passage of this bill is earnestly sought. ERW IN T. TULFO

Senate Difice of the Sorcretarp TWENTIETH CONGRESS OF THE MAY -4 P3:27 REPUBLIC OF THE PHILIPPINES First Regular Session RECEIVED BY: SENATE Senate Bill No. 2085 Introduced by Senator Erwin T. Tulfo AN ACT STRENGTHENING THE NATIONAL CYBERSECURITY SYSTEM BY INSTITUTIONALIZING EXECUTIVE ORDER NO. 95, AND ENHANCING PROTECTION AGAINST CYBER THREATS, AND FOR OTHER PURPOSES Be it enacted by the Senate and the House of Representatives of the Philippines in Congress assembled:

SECTION 1. Short Title. - This Act shall be known as the

2 "Cybersecurity Act."

SEC. 2. Declaration of Policy. - It is hereby declared the policy

5 of the State to ensure the security, resilience, and reliability of the 6 country's information and communications technology (ICT) 7 infrastructure. The State recognizes cybersecurity as a critical component of national security, public safety, economic stability, and the protection of individual rights. Towards this end, the State shall develop and maintain a secure and resilient cyberspace by protecting critical information infrastructure, ensuring rapid and coordinated responses to cyber threats, and strengthening the capabilities of law enforcement and defense institutions.

SEC. 3. National Cybersecurity Council. - The National

2 Cybersecurity Inter-Agency Committee created under Executive Order 3 No. 95 (s. 2019) is hereby institutionalized, reorganized, and renamed 4 as the National Cybersecurity Council (NCC) under the administrative supervision of the Office the President.

SEC. 4. Reorganization of the National Cybersecurity Council. -

8 The NCC shall be chaired by the Secretary of the Department of 9 Information and Communications Technology (DICT) and co-chaired 10 by the Executive Secretary and the National Security Adviser and 11 Director General of the National Security Council (NSC), and shall further be composed of the following officials as members: a) Secretary of the Department of Foreign Affairs (DFA); b) Secretary of the Department of Finance (DOF); c) Secretary of the Department of Science and Technology (DOST); d) Secretary of the Department of Interior and Local Government (DILG); e) Secretary of the Department of Justice (DOJ); f) Secretary of the Department of Energy (DOE); g) Secretary of the Department of National Defense (DND); h) Secretary of the Department of Transportation (DOTr); i) Secretary of the Presidential Communication Operations Office (PCOO); j) Commissioner of the National Telecommunications Commission (NTC);

k) Director-General of the National Intelligence Coordinating Agency (NICA); 1) Director of the National Bureau of Investigation (NBI); m) Chief of the Philippine National Police (PNP); n) Chief of Staff of the Armed Forces of the Philippines; o) Chairman of the National Privacy Commission (NPC); P) Executive Director of the Anti-Terrorism Council- Program Management Center (ATM-PMC); q) Executive Director of the Cybercrime Investigation and Coordinating Center (CICC); and r) Governor of the Bangko Sentral ng Pilipinas (BSP) as members. The NCC shall have a secretariat to be headed by an Executive Director. The organizational structure and staffing pattern of the secretariat shall be formulated by the Secretary of the DICT, subject to the approval of the Department of Budget and Management (DBM) in accordance with Executive Order No. 292, otherwise known as the "Administrative Code of 1987." The NCC may invite concerned public and private agencies or entities to participate, complement, and assist in the performance of its functions. The NCC shall collaborate with the Anti-Terrorism Council (ATC) on matters relating to cyber-terrorism.

SEC. 5. Power and Functions. - The NCC shall be the main

authority to exercise powers and functions that would address all cybersecurity-related matters. It shall perform the following functions:

a) Formulate and implement a National Cybersecurity Plan pursuant to Section 7 of this Act; b) Assess the vulnerabilities of the country's cybersecurity; c) Implement capacity building measures for the purpose of responding to Cybersecurity threats and emergencies; d) Issue updated security protocols to all government employees involved in the storage, handling and distribution of all forms (digital, electronic, snail mail, etc.) of documents and communications, following best practices. These protocols shall be updated periodically and, as necessary, in light of the rapid developments in information and communications technology. e) Enhance the public-private partnership in the field of information sharing involving cyberattacks, threats and vulnerabilities to cyber threats; f) Conduct periodic strategic planning and workshop activities that will reduce the country's vulnerabilities to cyber threats; g) Direct its member agencies and appropriate agencies to implement cybersecurity measures as may be required by the situation; h) Serve as the country's coordinating arm on domestic, international, and transnational efforts pertaining to cybersecurity; i) Make such recommendations and/or such other reports as the president may from time to time direct; and j) Perform such other functions as may be necessary.

SEC. 6. Meetings of the Council. - The NCC shall hold regular

meeting every quarter and such special meetings as may be necessary upon the request of the chairman or at least two (2) of its members.

SEC.7. National Cyber Security Plan. - The NCC shall

6 formulate, adopt, and periodically update a National Cybersecurity 7 Plan (NCP), which shall serve as the comprehensive framework for safeguarding the country's cyberspace. The NCP shall include, but not 9 be limited to, the following components: a) Identification and protection of critical information infrastructure; b) National risk assessment and threat monitoring mechanisms; c) Cyber incident prevention, detection, response, and recovery protocols; d) Roles and responsibilities of government agencies and stakeholders; e) Capacity-building, workforce development, an d public awareness programs; f) Mechanisms for public-private sector collaboration; g) International cooperation and information sharing strategies; h) Standards, compliance, and regulatory frameworks for cybersecurity; and i) Periodic evaluation and performance metrics.

SEC. 8. Report of Data Breach. - Government institutions,

2 agencies, instrumentalities, including government-owned and 3 controlled corporations, all private corporations, companies, and business establishments, operating wholly or partly in the Philippines, 5 are required to report to the NCC, within 24 to 72 hours, all kinds of 6 data breaches occurring in their jurisdiction. Provided, That the NCC 7 shall conduct training on cybersecurity to all stakeholders for the 8 effective implementation of this Act. Failure to make the required report shall be penalized with 11 imprisonment of not less than six (6) months but not more than two (2) years or a fine of not more than P 1,000,000.00, or both at the discretion of the court. In case of penalty of imprisonment, the same shall be imposed on the officials or persons who are responsible for making the report, as determined in the implementing rules and regulations.

SEC. 9. Protection Against Insider Threats. - All government

agencies and Critical Information Infrastructure (CII) covered by this 19 Act shall implement measures to prevent, detect, and respond to insider 20 threats involving their employees, contractors, or other authorized users.

SEC. 10. Reportorial Requirement. - The NCC shall submit a

quarterly report, or as often as may be necessary, to the President of the Philippines and to Congress on the state of cybersecurity threats and other related information. The NCC may request an executive session from Congress if it may deem necessary.

SEC. 11. Implementing Rules and Regulations. - The DICT, the

DOJ, the DILG, and the NSC shall jointly formulate the necessary rules and regulations within ninety (90) days from approval of this Act, for its effective implementation.

SEC. 12. Appropriations. - The amount needed for the initial

implementation of this Act shall be charged against the current year's appropriations of the departments/agencies concerned. Thereafter, such

1 sums as may be necessary for the continued implementation of this Act 2 shall be included in the annual General Appropriations Act.

SEC. 13. Separability Clause. - Should any provision or part of

5 this Act be declared unconstitutional or invalid, the other provisions 6 and parts hereof, insofar as they are separable from the invalid ones, 7 shall remain in full force and effect.

SEC. 14. Repealing Clause. - All laws, decrees, executive orders,

10 issuances, rules, and regulations or parts thereof which are inconsistent 11 with this Act are hereby repealed or modified accordingly.

SEC. 15. Effectivity. - This Act shall take effect fifteen (15) days

after its publication in the Official Gazette or in at least two (2) newspapers of general circulation. Approved,

Text extracted from the scanned Senate document via OCR — it may contain recognition errors. The official PDF is the authoritative version.