Cyberuptive

Philippines · Data Privacy Act · BSP · ISO 27001

Security operations for Philippine organizations, staffed while you sleep.

Cyberuptive runs managed security operations for Philippine companies that carry real obligations: the Data Privacy Act, BSP supervision, ISO 27001 commitments to overseas clients. We deliver 24/7 SOC coverage, managed detection and response, and VAPT, with team members in Cebu and security operations run from our United States SOC.

  • 24/7 managed SOC with defined escalation
  • Incident response that supports your SIRT obligations
  • VAPT scoped for auditors and client reviews
  • Evidence for BSP CCSA and ISO 27001 control areas

Why outsourcing security operations is defensible here

The regulator already says you may outsource the response team.

Philippine organizations often assume that building an incident response capability means hiring one. The National Privacy Commission is clearer than most regulators on this point: the functions of the Security Incident Response Team may be outsourced, and there is no precise formula for the team’s composition. What the NPC cares about is capability. The members must collectively be ready to assess and evaluate a security incident, restore integrity to the information and communications system, mitigate and remedy resulting damage, and comply with reporting requirements.

That is a description of a functioning SOC. It is also a realistic answer for an organization that cannot justify three shifts of analysts to cover nights, weekends, and holidays, which is precisely when intrusions are allowed to develop.

What does not transfer.

We will not pretend that a contract moves your accountability. The NPC is explicit that the obligation to notify remains with the personal information controller even if processing is outsourced or subcontracted to a personal information processor. A provider who tells you otherwise is selling you a problem. The correct arrangement gives you a named escalation path, an agreed severity definition, and an investigation record you can hand to the Commission, while the decision to notify stays with you and your counsel.

Data Privacy Act obligations a SOC actually touches

Notification is the visible duty. Documentation is the one that fails audits.

Not every incident is notifiable. The NPC states that notification is mandatory only when all of the required elements are present. Many organizations stop reading there, which is a mistake, because the documentation duty is far wider than the notification duty.

Document everything

All security incidents and personal data breaches must be documented through written reports, including those not covered by the notification requirements. Any or all reports shall be made available when requested by the Commission.

Monitor and scan

The NPC expects controllers and processors to regularly monitor for security breaches and conduct vulnerability scanning of computer networks. That is a continuous obligation, not an annual project.

Report annually

Personal information controllers and processors are required to submit an Annual Report. A year of consistent incident records makes that submission an export rather than an exercise in reconstruction.

There is also a criminal dimension that tends to focus executive attention. The NPC notes that failure to notify the Commission or the public may create criminal liability for Concealment of Security Breaches Involving Sensitive Personal Information. This is one of the few privacy regimes where the consequence of staying quiet is described in terms of imprisonment rather than only administrative fines.

For BSP Supervised Financial Institutions

BSP Circular 1232 turned cybersecurity maturity into a submitted number.

Circular No. 1232, Series of 2026, established the Cybersecurity Maturity Framework and the Cybersecurity Control Self-Assessment. The circular requires all BSFIs to have periodic and rigorous self-assessment exercises using more robust data sets and variables as part of their information security risk management system. Submission of the CCSA is required of BSFIs notified by the Bangko Sentral as having a moderate and complex IT Profile, along with other BSFIs specifically identified by the Bangko Sentral.

The expected maturity is pinned to IT Profile classification, which makes the target concrete rather than aspirational:

IT Profile classification Required maturity alignment
Simple IT Profile Foundational to Established
Moderate IT Profile Established to Managed
Complex IT Profile Managed to Optimized

The Bangko Sentral evaluates maturity using the CCSA alongside other supervisory activities, so a self-assessment that overstates reality is a liability rather than a shortcut. In our experience the gap between Established and Managed is rarely about written policy. It is about whether a control runs continuously and leaves evidence behind. Continuous monitoring, documented triage, and retained logs are what make the higher tiers defensible, which is the part a managed SOC is built to supply.

Note: BSP Circular 1232 amends existing information security regulation and sits alongside earlier issuances, including Circular 982 on information security management. Confirm the requirements applicable to your institution and IT Profile with your supervising department.

ISO 27001 and the export contract problem

In the Philippines, ISO 27001 is usually a sales requirement before it is a security one.

ISO/IEC 27001 is not Philippine law. It became common here for a commercial reason: outsourcing and technology firms serving clients in the United States, European Union, Australia, and Japan are frequently required to certify before those clients will place regulated or sensitive data with them. It is also referenced in BSP issuances on technology risk management, which is why financial institutions encounter it from two directions at once.

We are not a certification body and cannot certify anyone. What we can do is operate the controls that several Annex A areas depend on and produce the records an auditor asks for: monitoring and logging that demonstrably ran, vulnerability management with remediation tracked to closure, and incident response with a written trail. Certification work goes faster when those things are already true.

Philippines cybersecurity FAQ

What Philippine security and compliance leaders ask first.

Can a Philippine organization outsource its Security Incident Response Team?

Yes. The National Privacy Commission states that "the functions of the Security Incident Response Team (SIRT) may be outsourced," and that there is no precise formula for the team’s composition. What the NPC requires is that the members collectively be ready to assess and evaluate a security incident, restore integrity to the information and communications system, mitigate and remedy resulting damage, and comply with reporting requirements. A managed SOC can perform the detection, investigation, and containment work. One thing does not transfer: the NPC is explicit that the obligation to notify remains with the personal information controller even when processing is outsourced or subcontracted. Accountability stays with you, so the engagement needs a documented escalation path to your decision-makers.

How quickly must a personal data breach be reported to the NPC?

The Implementing Rules and Regulations of the Data Privacy Act of 2012 require that the Commission and affected data subjects be notified within seventy-two (72) hours upon knowledge of, or when there is reasonable belief by the personal information controller or processor, that a notifiable personal data breach has occurred. Seventy-two hours is not long once you account for confirming what happened, determining which data and which data subjects are affected, and preparing a notice. That timeline is the practical argument for having monitoring, log retention, and an investigation process in place beforehand rather than assembling one during the incident.

Does every security incident have to be reported to the NPC?

No. The NPC states that notification is mandatory only when all of the required elements are present, so not every personal data breach is notifiable. However, documentation is broader than notification: the NPC requires that all security incidents and personal data breaches be documented through written reports, including those not covered by the notification requirements, and that any or all reports be made available when requested by the Commission. Personal information controllers and processors are also required to submit an Annual Report. In practice this means you need a defensible record of incidents you decided not to report, and the reasoning behind that decision.

What is BSP Circular 1232 and which institutions have to submit a CCSA?

BSP Circular No. 1232, Series of 2026, establishes a Cybersecurity Maturity Framework (CMF) and a Cybersecurity Control Self-Assessment (CCSA) for BSP Supervised Financial Institutions. The circular states that all BSFIs are required to have periodic and rigorous self-assessment exercises using more robust data sets and variables as part of their information security risk management system. Submission of the CCSA itself is narrower: it is required of BSFIs notified by the Bangko Sentral as having a moderate and complex IT Profile, plus other BSFIs specifically identified by the Bangko Sentral. Because the Bangko Sentral evaluates a BSFI’s cybersecurity maturity using the CCSA alongside other supervisory activities, the self-assessment should reflect controls you can actually evidence in operation.

What maturity level does our institution need to reach?

Under BSP Circular 1232 the expected maturity is tied to IT Profile classification rather than to institution size alone. A Simple IT Profile maps to Foundational to Established, a Moderate IT Profile to Established to Managed, and a Complex IT Profile to Managed to Optimized. The practical consequence is that moving from Established to Managed generally means demonstrating that controls run continuously and produce evidence, not that a policy exists. Continuous monitoring, documented triage, and retained logs are usually what separate those two tiers in an examination.

Does Cyberuptive operate a Security Operations Center in the Philippines?

No, and we would rather be precise about that than imply otherwise. Cyberuptive has team members based in Cebu who support regional coordination and client communication. Security operations themselves are delivered from our United States security operations center, which provides the 24/7 monitoring, triage, and escalation coverage. During discovery we document exactly which personnel perform which functions, where data is processed and retained, and how escalation reaches your team, so the arrangement can be assessed against your own contractual and regulatory commitments.

Is ISO 27001 certification required in the Philippines?

ISO/IEC 27001 is not a Philippine statutory requirement. It is a contractual one. Philippine service providers, particularly business process outsourcing firms and technology companies serving clients in the United States, European Union, Australia, and Japan, are frequently required to hold certification before those clients will place regulated or sensitive data with them. ISO 27001 is also referenced in BSP issuances on technology risk management. We are not a certification body and cannot certify you. What a managed SOC contributes is the operational evidence that several Annex A control areas depend on: monitoring, logging, vulnerability management, and incident response that demonstrably ran.

How does the time difference between Hawaii and the Philippines work in practice?

Manila is a constant eighteen hours ahead of Honolulu, and neither location observes daylight saving time, so the relationship never shifts. A Philippine business day of 08:00 to 17:00 corresponds to 14:00 to 23:00 in Honolulu. More usefully, 02:00 in Manila, a common hour for ransomware detonation precisely because nobody is watching, is 08:00 in Honolulu. Your unattended overnight window is our staffed business morning rather than the graveyard shift of a provider who is asleep at the same time you are.

What does a VAPT engagement include?

Scope should be written before pricing. A vulnerability assessment and penetration testing engagement normally defines the in-scope systems and applications, whether testing is external, internal, or both, whether it is authenticated, the testing window, rules of engagement covering what testers may and may not do, and the reporting format including how findings are ranked and retested. Ask any provider whether a retest after remediation is included, because a report of unfixed findings satisfies almost no auditor or client. Our penetration testing services page sets out how we scope this work.

Sources

Primary references used on this page.

This page is general information, not legal advice. Regulatory obligations depend on your organization, the data you process, and your contracts. Confirm applicable requirements with the relevant regulator and your own counsel.

Talk to the team that would run your SOC

Start with your obligations, your systems, and who has to sign the notice.

Tell us what you process, which regulators and clients you answer to, and what your current coverage looks like after hours. We will tell you whether a managed SOC, MDR, or a scoped VAPT engagement is the honest next step — including when it is none of them yet.