Back
About RSIS
Introduction
Building the Foundations
Welcome Message
Board of Governors
Staff Profiles
Executive Deputy Chairman’s Office
Dean’s Office
Management
Distinguished Fellows
Faculty and Research
Associate Research Fellows, Senior Analysts and Research Analysts
Visiting Fellows
Adjunct Fellows
Administrative Staff
Honours and Awards for RSIS Staff and Students
RSIS Endowment Fund
Endowed Professorships
Career Opportunities
Getting to RSIS
Research
Research Centres
Centre for Multilateralism Studies (CMS)
Centre for Non-Traditional Security Studies (NTS Centre)
Centre of Excellence for National Security
Institute of Defence and Strategic Studies (IDSS)
International Centre for Political Violence and Terrorism Research (ICPVTR)
Research Programmes
National Security Studies Programme (NSSP)
Social Cohesion Research Programme (SCRP)
Studies in Inter-Religious Relations in Plural Societies (SRP) Programme
Other Research
Future Issues and Technology Cluster
Research@RSIS
Science and Technology Studies Programme (STSP) (2017-2020)
Graduate Education
Graduate Programmes Office
Exchange Partners and Programmes
How to Apply
Financial Assistance
Meet the Admissions Team: Information Sessions and other events
RSIS Alumni
Outreach
Global Networks
About Global Networks
RSIS Alumni
Executive Education
About Executive Education
SRP Executive Programme
Terrorism Analyst Training Course (TATC)
International Programmes
About International Programmes
Asia-Pacific Programme for Senior Military Officers (APPSMO)
Asia-Pacific Programme for Senior National Security Officers (APPSNO)
International Conference on Cohesive Societies (ICCS)
International Strategy Forum-Asia (ISF-Asia)
Publications
RSIS Publications
Annual Reviews
Books
Bulletins and Newsletters
RSIS Commentary Series
Counter Terrorist Trends and Analyses
Commemorative / Event Reports
Future Issues
IDSS Papers
Interreligious Relations
Monographs
NTS Insight
Policy Reports
Working Papers
External Publications
Authored Books
Journal Articles
Edited Books
Chapters in Edited Books
Policy Reports
Working Papers
Op-Eds
Glossary of Abbreviations
Policy-relevant Articles Given RSIS Award
RSIS Publications for the Year
External Publications for the Year
Media
Cohesive Societies
Sustainable Security
Other Resource Pages
News Releases
Speeches
Video/Audio Channel
External Podcasts
Events
Contact Us
S. Rajaratnam School of International Studies Think Tank and Graduate School Ponder The Improbable Since 1966
Nanyang Technological University Nanyang Technological University
  • About RSIS
      IntroductionBuilding the FoundationsWelcome MessageBoard of GovernorsHonours and Awards for RSIS Staff and StudentsRSIS Endowment FundEndowed ProfessorshipsCareer OpportunitiesGetting to RSIS
      Staff ProfilesExecutive Deputy Chairman’s OfficeDean’s OfficeManagementDistinguished FellowsFaculty and ResearchAssociate Research Fellows, Senior Analysts and Research AnalystsVisiting FellowsAdjunct FellowsAdministrative Staff
  • Research
      Research CentresCentre for Multilateralism Studies (CMS)Centre for Non-Traditional Security Studies (NTS Centre)Centre of Excellence for National SecurityInstitute of Defence and Strategic Studies (IDSS)International Centre for Political Violence and Terrorism Research (ICPVTR)
      Research ProgrammesNational Security Studies Programme (NSSP)Social Cohesion Research Programme (SCRP)Studies in Inter-Religious Relations in Plural Societies (SRP) Programme
      Other ResearchFuture Issues and Technology ClusterResearch@RSISScience and Technology Studies Programme (STSP) (2017-2020)
  • Graduate Education
      Graduate Programmes OfficeExchange Partners and ProgrammesHow to ApplyFinancial AssistanceMeet the Admissions Team: Information Sessions and other eventsRSIS Alumni
  • Outreach
      Global NetworksAbout Global NetworksRSIS Alumni
      Executive EducationAbout Executive EducationSRP Executive ProgrammeTerrorism Analyst Training Course (TATC)
      International ProgrammesAbout International ProgrammesAsia-Pacific Programme for Senior Military Officers (APPSMO)Asia-Pacific Programme for Senior National Security Officers (APPSNO)International Conference on Cohesive Societies (ICCS)International Strategy Forum-Asia (ISF-Asia)
  • Publications
      RSIS PublicationsAnnual ReviewsBooksBulletins and NewslettersRSIS Commentary SeriesCounter Terrorist Trends and AnalysesCommemorative / Event ReportsFuture IssuesIDSS PapersInterreligious RelationsMonographsNTS InsightPolicy ReportsWorking Papers
      External PublicationsAuthored BooksJournal ArticlesEdited BooksChapters in Edited BooksPolicy ReportsWorking PapersOp-Eds
      Glossary of AbbreviationsPolicy-relevant Articles Given RSIS AwardRSIS Publications for the YearExternal Publications for the Year
  • Media
      Cohesive SocietiesSustainable SecurityOther Resource PagesNews ReleasesSpeechesVideo/Audio ChannelExternal Podcasts
  • Events
  • Contact Us
    • Connect with Us

      rsis.ntu
      rsis_ntu
      rsisntu
      rsisvideocast
      school/rsis-ntu
      rsis.sg
      rsissg
      RSIS
      RSS
      Subscribe to RSIS Publications
      Subscribe to RSIS Events

      Getting to RSIS

      Nanyang Technological University
      Block S4, Level B3,
      50 Nanyang Avenue,
      Singapore 639798

      Click here for direction to RSIS

      Get in Touch

    Connect
    Search
    • RSIS
    • Publication
    • RSIS Publications
    • Data Security in ASEAN’s Digital Economy: Lessons from the Philippines
    • Annual Reviews
    • Books
    • Bulletins and Newsletters
    • RSIS Commentary Series
    • Counter Terrorist Trends and Analyses
    • Commemorative / Event Reports
    • Future Issues
    • IDSS Papers
    • Interreligious Relations
    • Monographs
    • NTS Insight
    • Policy Reports
    • Working Papers

    CO23161 | Data Security in ASEAN’s Digital Economy: Lessons from the Philippines
    Jose Miguelito Enriquez

    06 November 2023

    download pdf

    SYNOPSIS

    Recent data breaches targeting Philippine government agencies have underscored the need to ensure a secure digital data environment. As ASEAN continues to lay the groundwork for its digital community and economy, the responsibility for data security must be shared by both domestic policymakers and relevant ASEAN mechanisms and frameworks.

    CO23161 Data Security in ASEANs Digital Economy Lessons from the Philippines
    Source: Freepik

    COMMENTARY

    When a spate of ransomware attacks and data breaches across several government agencies in the Philippines made headlines in September and October 2023, the extent of each breach sparked major concerns from both policymakers and the public.

    While cyberattacks appear to be unavoidable in this digital age, these events have unmasked several domestic and regional policy problems that will need to be resolved in order to prevent more damaging data breaches in the future.

    Recent Data Breaches in the Philippines

    News of data breaches in the Philippines began on 25 September 2023, when the Philippine Health Insurance Corporation (PhilHealth) reported to the National Privacy Commission (NPC) that its systems had been disabled by an attack from the Medusa ransomware group three days earlier on 22 September. An investigation by the state insurer revealed that the personal information of some 13 to 20 million members – approximately 18 per cent of the Filipino population – were disclosed by hackers in the dark web.

    The PhilHealth incident represented the most serious data breach of a Philippine public agency since seven years ago, when local hackers obtained the complete database of registered voters from the Commission on Elections in the middle of the 2016 presidential election. It was the beginning of a series of breaches to affect the public sector over several weeks.

    On 11 October, two weeks after the PhilHealth incident, the Philippine Statistics Authority (PSA) also informed the NPC that it had suffered a data breach. The country’s civil registry reported that the information illegally accessed were largely connected to recipients of the government’s social welfare programmes.

    Two days later, the Department of Science and Technology (DOST) also reported that the contact information of around 1,000 individuals registered in its OneExpert portal, an online registry of the country’s leading scientific experts, were leaked.

    These successive data breaches sparked questions over the integrity of the cybersecurity infrastructure of the respective agencies.

    The Need for Proactive Data Governance

    Even though inquiries by the Philippine Senate and the Department of Health (DOH) have yet to conclude, the incidents have already revealed some policy challenges that the government will need to confront. As some challenges remain unresolved, innovative policy solutions are needed.

    First, there is a need to swiftly inform affected data subjects of the breach and to institute methods of data recovery. On 13 October 2023, eight days after the hackers in the PhilHealth incident had uploaded the data into the dark web, the NPC launched a first-of-its-kind portal for the public to check whether their information had been compromised.

    Second, there should be improvements in how agencies tasked with cybersecurity and data protection coordinate and collaborate with each other. The NPC and the Department of Information and Communications Technology (DICT) recently launched the Digital Security and Privacy Quick Response Project (DSPQR), a system designed to swiftly respond to complaints from the public regarding potential privacy violations.

    While these services are welcome developments, there is a pressing need for more proactive data governance. The proposed e-Governance Act, a bill designed to speed up digitalisation and empower the DICT to institute information security standards in the government, was certified as urgent by President Ferdinand Marcos Jr in July 2022. However, the bill’s enactment has been delayed in the Philippine Senate.

    It is also apparent that necessary policy reforms should not only cover cybersecurity legislation. The PhilHealth had admitted that it had not been able to renew the license for its antivirus software due to revised government procurement rules, which contributed to weakened cyber defences once the ransomware had attempted to infiltrate its system.

    ASEAN’s Data Security Challenge

    The data breaches in the Philippines also demonstrate the continued threat of cybercrime within Southeast Asia. In its 2021 ASEAN cyberthreat assessment, Interpol noted that while ransomware risk in the region was relatively low, it could potentially increase in the future.

    Indeed, the Philippines is not the only country in the region to have suffered a major data breach. SingHealth, Singapore’s state health insurer, experienced a similar data breach in 2018. Malaysian authorities reported that more than 800 gigabytes of personal data were leaked through breaches in the telecommunications, banking, IT, and government sectors in the first half of 2023.

    As ASEAN’s digital economy continues to grow and its digital community continues to thrive, the region will surely have to grapple with the increasing risk of cyberattacks. This will require dynamic policy solutions both at the domestic and regional levels that could easily respond to cyber threats and close any capacity gaps between national cybersecurity agencies.

    There have already been moves at the ASEAN level to respond to this data security challenge. In 2018, ASEAN published its Digital Data Governance Framework which outlines the regional organisation’s goal to harmonise member states’ data protection laws.

    More recently, ASEAN launched its Regional Computer Emergency Response Team (CERT), an initiative to enhance regional readiness to respond to cyber threats in real time and facilitate information sharing and best practice exchange that will be operational by 2024. Data protection and cybersecurity are also topics that will be negotiated during the development of the ASEAN Digital Economy Framework Agreement (DEFA).

    It is important for the region to continue to take data protection concerns seriously, especially in the context of building its digital community and economy. Not doing so will come at a high economic cost. Interpol cited in its 2021 report an estimate of US$1 billion worth of global financial damage from ransomware attacks alone.

    Repeated data breaches at government agencies will not invite investor confidence in the region’s digital and tech industries, which will result in ASEAN missing its digital economic potential of US$2 trillion by 2030. It may also cause ASEAN to fail in delivering on its promise to provide trustworthy e-governance and other digital services as stated in the ASEAN Digital Masterplan 2025.

    Continued regional dialogue will also be necessary to prevent ASEAN member states from resorting to restrictive data localisation policies in the name of data protection, which will also negatively impact the economy and regional connectivity. Lowering localisation barriers will be required if ASEAN is serious about meeting its goals of building a regional e-payments and QR code system.

    Conclusion

    To become a global digital player, ASEAN’s initiatives in the digital economy and connectivity must be pursued with a steadfast commitment to ensure an effective data security architecture.

    Even if data security is primarily seen as a domestic policy challenge, regional frameworks will need to move from suggested outcomes to more binding commitments from each ASEAN member state. In a tight-knit digital economy, the region’s data security will only be as strong as its weakest link.

    About the Author

    Jose Miguelito Enriquez is Associate Research Fellow in the Centre for Multilateralism Studies at S. Rajaratnam School of International Studies (RSIS), Nanyang Technological University (NTU), Singapore. His research interests include digital economy governance in ASEAN, populist foreign policy, and Philippine politics and foreign policy.

    Categories: RSIS Commentary Series / Country and Region Studies / Singapore and Homeland Security / East Asia and Asia Pacific / South Asia / Southeast Asia and ASEAN / Global
    comments powered by Disqus

    SYNOPSIS

    Recent data breaches targeting Philippine government agencies have underscored the need to ensure a secure digital data environment. As ASEAN continues to lay the groundwork for its digital community and economy, the responsibility for data security must be shared by both domestic policymakers and relevant ASEAN mechanisms and frameworks.

    CO23161 Data Security in ASEANs Digital Economy Lessons from the Philippines
    Source: Freepik

    COMMENTARY

    When a spate of ransomware attacks and data breaches across several government agencies in the Philippines made headlines in September and October 2023, the extent of each breach sparked major concerns from both policymakers and the public.

    While cyberattacks appear to be unavoidable in this digital age, these events have unmasked several domestic and regional policy problems that will need to be resolved in order to prevent more damaging data breaches in the future.

    Recent Data Breaches in the Philippines

    News of data breaches in the Philippines began on 25 September 2023, when the Philippine Health Insurance Corporation (PhilHealth) reported to the National Privacy Commission (NPC) that its systems had been disabled by an attack from the Medusa ransomware group three days earlier on 22 September. An investigation by the state insurer revealed that the personal information of some 13 to 20 million members – approximately 18 per cent of the Filipino population – were disclosed by hackers in the dark web.

    The PhilHealth incident represented the most serious data breach of a Philippine public agency since seven years ago, when local hackers obtained the complete database of registered voters from the Commission on Elections in the middle of the 2016 presidential election. It was the beginning of a series of breaches to affect the public sector over several weeks.

    On 11 October, two weeks after the PhilHealth incident, the Philippine Statistics Authority (PSA) also informed the NPC that it had suffered a data breach. The country’s civil registry reported that the information illegally accessed were largely connected to recipients of the government’s social welfare programmes.

    Two days later, the Department of Science and Technology (DOST) also reported that the contact information of around 1,000 individuals registered in its OneExpert portal, an online registry of the country’s leading scientific experts, were leaked.

    These successive data breaches sparked questions over the integrity of the cybersecurity infrastructure of the respective agencies.

    The Need for Proactive Data Governance

    Even though inquiries by the Philippine Senate and the Department of Health (DOH) have yet to conclude, the incidents have already revealed some policy challenges that the government will need to confront. As some challenges remain unresolved, innovative policy solutions are needed.

    First, there is a need to swiftly inform affected data subjects of the breach and to institute methods of data recovery. On 13 October 2023, eight days after the hackers in the PhilHealth incident had uploaded the data into the dark web, the NPC launched a first-of-its-kind portal for the public to check whether their information had been compromised.

    Second, there should be improvements in how agencies tasked with cybersecurity and data protection coordinate and collaborate with each other. The NPC and the Department of Information and Communications Technology (DICT) recently launched the Digital Security and Privacy Quick Response Project (DSPQR), a system designed to swiftly respond to complaints from the public regarding potential privacy violations.

    While these services are welcome developments, there is a pressing need for more proactive data governance. The proposed e-Governance Act, a bill designed to speed up digitalisation and empower the DICT to institute information security standards in the government, was certified as urgent by President Ferdinand Marcos Jr in July 2022. However, the bill’s enactment has been delayed in the Philippine Senate.

    It is also apparent that necessary policy reforms should not only cover cybersecurity legislation. The PhilHealth had admitted that it had not been able to renew the license for its antivirus software due to revised government procurement rules, which contributed to weakened cyber defences once the ransomware had attempted to infiltrate its system.

    ASEAN’s Data Security Challenge

    The data breaches in the Philippines also demonstrate the continued threat of cybercrime within Southeast Asia. In its 2021 ASEAN cyberthreat assessment, Interpol noted that while ransomware risk in the region was relatively low, it could potentially increase in the future.

    Indeed, the Philippines is not the only country in the region to have suffered a major data breach. SingHealth, Singapore’s state health insurer, experienced a similar data breach in 2018. Malaysian authorities reported that more than 800 gigabytes of personal data were leaked through breaches in the telecommunications, banking, IT, and government sectors in the first half of 2023.

    As ASEAN’s digital economy continues to grow and its digital community continues to thrive, the region will surely have to grapple with the increasing risk of cyberattacks. This will require dynamic policy solutions both at the domestic and regional levels that could easily respond to cyber threats and close any capacity gaps between national cybersecurity agencies.

    There have already been moves at the ASEAN level to respond to this data security challenge. In 2018, ASEAN published its Digital Data Governance Framework which outlines the regional organisation’s goal to harmonise member states’ data protection laws.

    More recently, ASEAN launched its Regional Computer Emergency Response Team (CERT), an initiative to enhance regional readiness to respond to cyber threats in real time and facilitate information sharing and best practice exchange that will be operational by 2024. Data protection and cybersecurity are also topics that will be negotiated during the development of the ASEAN Digital Economy Framework Agreement (DEFA).

    It is important for the region to continue to take data protection concerns seriously, especially in the context of building its digital community and economy. Not doing so will come at a high economic cost. Interpol cited in its 2021 report an estimate of US$1 billion worth of global financial damage from ransomware attacks alone.

    Repeated data breaches at government agencies will not invite investor confidence in the region’s digital and tech industries, which will result in ASEAN missing its digital economic potential of US$2 trillion by 2030. It may also cause ASEAN to fail in delivering on its promise to provide trustworthy e-governance and other digital services as stated in the ASEAN Digital Masterplan 2025.

    Continued regional dialogue will also be necessary to prevent ASEAN member states from resorting to restrictive data localisation policies in the name of data protection, which will also negatively impact the economy and regional connectivity. Lowering localisation barriers will be required if ASEAN is serious about meeting its goals of building a regional e-payments and QR code system.

    Conclusion

    To become a global digital player, ASEAN’s initiatives in the digital economy and connectivity must be pursued with a steadfast commitment to ensure an effective data security architecture.

    Even if data security is primarily seen as a domestic policy challenge, regional frameworks will need to move from suggested outcomes to more binding commitments from each ASEAN member state. In a tight-knit digital economy, the region’s data security will only be as strong as its weakest link.

    About the Author

    Jose Miguelito Enriquez is Associate Research Fellow in the Centre for Multilateralism Studies at S. Rajaratnam School of International Studies (RSIS), Nanyang Technological University (NTU), Singapore. His research interests include digital economy governance in ASEAN, populist foreign policy, and Philippine politics and foreign policy.

    Categories: RSIS Commentary Series / Country and Region Studies / Singapore and Homeland Security

    Popular Links

    About RSISResearch ProgrammesGraduate EducationPublicationsEventsAdmissionsCareersVideo/Audio ChannelRSIS Intranet

    Connect with Us

    rsis.ntu
    rsis_ntu
    rsisntu
    rsisvideocast
    school/rsis-ntu
    rsis.sg
    rsissg
    RSIS
    RSS
    Subscribe to RSIS Publications
    Subscribe to RSIS Events

    Getting to RSIS

    Nanyang Technological University
    Block S4, Level B3,
    50 Nanyang Avenue,
    Singapore 639798

    Click here for direction to RSIS

    Get in Touch

      Copyright © S. Rajaratnam School of International Studies. All rights reserved.
      Privacy Statement / Terms of Use
      Help us improve

        Rate your experience with this website
        123456
        Not satisfiedVery satisfied
        What did you like?
        0/255 characters
        What can be improved?
        0/255 characters
        Your email
        Please enter a valid email.
        Thank you for your feedback.
        This site uses cookies to offer you a better browsing experience. By continuing, you are agreeing to the use of cookies on your device as described in our privacy policy. Learn more
        OK
        Latest Book
        more info