Private Sector Calls for Stronger Safeguards in Konektadong Pinoy Bill

Manila: Several groups of private information security professionals in the country called on lawmakers to address cybersecurity risks in the Konektadong Pinoy Bill.

According to Philippines News Agency, the Scam Watch Pilipinas, Women in Security Alliance Philippines (WiSAP), Philippines Chief Information Officer Association (PCIOA), PhilDev S and T Foundation, and BPO Cybersecurity Council have expressed their support for the bill while also urging for stronger safeguards to be embedded directly into the law. The groups highlighted concerns that certain provisions of the bill might expose the Philippines to increased cyber threats despite its aim to expand internet access and modernize the nation's digital infrastructure.

The statement from these organizations pointed out that the bill, which is currently awaiting the signature of President Ferdinand R. Marcos Jr., still requires attention to cybersecurity safeguards. One of the main concerns is the provision allowing new internet service providers to operate for up to three years without full compliance with cybersecurity and data privacy regulations. The critics of this provision argue that the grace period creates a "dangerous window" that could be exploited by hackers, scammers, or state-sponsored actors.

The groups also raised alarms about the potential security risks from easing the entry of foreign and local entities into building sensitive infrastructure such as international cable landing stations and satellite gateways. To mitigate these risks, they urged the President and lawmakers to eliminate the three-year grace period and mandate all Data Transmission Industry Participants and related entities to comply with stringent cybersecurity and data protection controls.

Furthermore, the statement called for a comprehensive risk assessment approach that addresses cybersecurity, privacy, technology architecture, geopolitical concerns, and economic viability, particularly for providers with foreign ownership or control. It also emphasized the necessity of a national security and cybersecurity vetting process for all prospective infrastructure providers involved in building or operating critical data infrastructure and recommended clear penalties for negligence leading to breaches of critical infrastructure.

The joint statement concluded that integrating these essential safeguards into the legislation would align the bill with existing Philippine cybersecurity and data privacy laws, thereby protecting the nation's digital infrastructure from evolving threats that could jeopardize its sovereignty and long-term digital future. The statement was signed by key figures including WiSAP chair and president Mel Migri±o, Scam Watch Pilipinas co-founder Jocel De Guzman, BPO Security Council president George Pineda, Philippines CIO Association trustee Apol Salud, and PhilDev S and T Foundation executive director Frederick Blancas.