House Turns Up Pressure on Senate Over Cybersecurity Bill — What Happens If the Threat Hits First?

Philippines

House Turns Up Pressure on Senate Over Cybersecurity Bill — What Happens If the Threat Hits First?

MANILA — House lawmakers are pressing the Senate to move quickly on a sweeping cybersecurity measure that would create a dedicated National Cybersecurity Agency and establish tougher protections for the digital systems that keep the Philippines running.

Camarines Sur Reps. Miguel Luis “Migz” Villafuerte and Vincenzo Renato Luigi Villafuerte are urging senators to advance their chamber’s counterpart to House Bill No. 9605, or the proposed National Cybersecurity and Critical Information Infrastructure Protection Act of 2026.

The push comes after the House approved HB 9605 on third and final reading on August 12 by a vote of 198-3, with one abstention. The measure was transmitted to and received by the Senate on August 13, according to the House legislative database.

The proposed law is designed to create a more unified national system for preventing, detecting and responding to cyberattacks as government agencies, banks, telecommunications networks, hospitals, utilities and other essential services become increasingly dependent on digital infrastructure.

A proposed National Cybersecurity Agency

At the center of HB 9605 is the creation of a National Cybersecurity Agency (NCSA) under the Department of Information and Communications Technology, which would serve as the country’s primary body for cybersecurity policy, planning, coordination, implementation and administration under the House-approved measure.

The agency would be tasked with improving coordination among government institutions and strengthening the country’s response to cyber incidents.

The House measure also seeks to establish minimum cybersecurity standards for critical information infrastructure and strengthen threat-intelligence sharing.

The legislation covers threats ranging from online fraud, identity theft and data breaches to ransomware and attacks capable of disrupting essential services.

Critical infrastructure gets tighter protection

The bill places particular emphasis on critical information infrastructure, recognizing that a serious cyberattack could affect far more than individual computers or online accounts.

Energy, telecommunications, banking, transportation, healthcare and government systems increasingly rely on interconnected digital networks. A major attack against those systems could potentially interrupt services relied upon by millions of Filipinos.

The House said HB 9605 would require operators of critical information infrastructure to conduct regular risk assessments and continuous monitoring, while also submitting authenticated cybersecurity audit and risk-assessment reports at least every two years.

Critical and high-risk cyber incidents would also have to be reported under the proposed framework. National government agencies, government-owned corporations and local government units would likewise be required to adopt minimum cybersecurity measures and create or designate Chief Information Security Officers.

The measure also strengthens national incident-response capabilities through a proposed National Computer Emergency Response Team and National Security Operations Center, with closer coordination among government agencies, law enforcement, intelligence agencies and critical-infrastructure operators.

Why lawmakers say the measure is urgent

Villafuerte has argued that cybersecurity can no longer be treated simply as a technology issue.

As more government services, financial transactions and essential infrastructure move online, cyber resilience has become a matter of national security and economic stability, he said.

The House measure is also listed among the priority measures identified through the Legislative-Executive Development Advisory Council, giving it added significance in the 20th Congress.

The Philippine Information Agency likewise reported that the bill seeks mandatory cybersecurity standards and certification systems for organizations, technology providers and IT professionals, with the NCSA serving as the central body for the country’s cybersecurity framework.

EO 119 adds urgency to the debate

The House lawmakers’ latest appeal also follows President Ferdinand Marcos Jr.’s issuance of Executive Order No. 119, which updated the government’s data-classification framework as part of efforts to accelerate digital transformation while protecting government information.

Luigi Villafuerte said the new framework, including the government’s move toward cloud technologies, makes stronger and more standardized cybersecurity practices increasingly important.

The issue is particularly relevant as cyber scams continue to evolve. Manila Bulletin previously reported that GCash had blocked thousands of bogus merchant accounts associated with QR-code scams known as “quishing,” illustrating how criminals are adapting familiar digital-payment technologies for fraud.

The Senate now holds the next piece

For the proposed cybersecurity framework to become law, however, Senate action remains necessary.

The House-approved HB 9605 has already crossed the lower chamber and is now with the Senate. The latest appeal from the Villafuertes is aimed at getting senators to act on their counterpart measure so Congress can move toward a unified national cybersecurity framework.

For Filipinos increasingly dependent on online banking, digital government services, telecommunications and other connected systems, the debate is bigger than the creation of another government agency.

It is ultimately about whether the country’s cybersecurity defenses can keep pace with the rapidly expanding threats targeting the digital systems on which everyday life now depends.

WWC ONE MEDIA M.J.E

Leave a Reply

Your email address will not be published. Required fields are marked *