The voice of the ASEAN people

INSIDE·ASEAN

Connecting ASEAN with the World

Philippines

Cybersecurity Landscape in the Philippines: Challenges and Opportunities

A recent report highlights significant gaps in cybersecurity management among organizations, emphasizing the need for automation and improved threat exposure management.

By Paolo Mercado19 July 20263 min read
Cybersecurity Landscape in the Philippines: Challenges and Opportunities

The cybersecurity landscape in the Philippines is facing critical challenges as organizations grapple with the complexities of threat management. According to the State of Threat Management Report by Filigran, a European open-source threat management company, many organizations are hindered by fragmented tools and manual processes, which exacerbate the gap between threat awareness and effective Continuous Threat Exposure Management (CTEM).

Only 41 percent of organizations surveyed reported having a fully consolidated view of their cyber risk exposure. Alarmingly, security teams are spending an average of 42 percent of their time investigating risks that ultimately turn out to be low priority or non-exploitable. This inefficiency highlights a significant disconnect between the growing recognition of CTEM as an essential framework and the operational maturity required to implement it effectively.

The report indicates that despite deploying an average of 14 different threat intelligence feeds, 61 percent of organizations are unable to identify which vulnerabilities are most likely to be exploited in real-world attacks. Furthermore, only 38 percent utilize threat intelligence within a continuous, fully automated validation process. The findings suggest that heavy investment in security tools has not resulted in a unified view of exposure, with less than half of organizations reporting full consolidation of cyber risk visibility.

In the Asia-Pacific (APAC) region, which includes the Philippines, the report reveals the widest gap in operational maturity regarding cybersecurity. Just 31 percent of organizations in APAC have a fully consolidated view of their cyber risk, and only 27 percent employ continuous, automated validation—approximately half the rate of organizations in North America. This disparity raises concerns about the potential for breaches, particularly in regions where operational gaps are most pronounced.

As organizations acknowledge that periodic assessments cannot keep pace with the rapid changes in their environments, nearly half continue to rely primarily on manual processes for vulnerability identification and threat analysis. The bottleneck created by this reliance has tangible consequences, as most surveyed organizations agree that cyberattacks typically exploit known risks that are not prioritized. Barriers to validating whether threats are exploitable include fears of disrupting systems, excessive manual effort, and inadequate integration with existing security processes.

Moreover, 89 percent of respondents indicated that reducing alert noise would assist in identifying which alerts represent real business risks. A pressing concern is the need for greater automation; 88 percent of security teams agreed that without it, they could not manage the volume of risks they face. Currently, 37 percent of exposure management processes are driven by artificial intelligence (AI), and this figure is expected to rise to 59 percent within the next two years.

As organizations plan to invest in cyber risk quantification tools and exposure assessment capabilities over the next 12 to 24 months, the urgency for improvement in cyber risk management becomes increasingly clear. Delaying such enhancements raises the likelihood of serious incidents. A proactive cybersecurity posture in 2026 will depend on the integration of threat intelligence with exposure management, a sentiment echoed by analysts who emphasize the importance of continuous validation against actual exposure.

The Filigran report is based on a survey of 550 senior IT security decision-makers and practitioners from organizations with over 1,000 employees across various sectors, including financial services, healthcare, energy, public sector, IT and technology, and retail. As the Philippines continues to navigate the complexities of cybersecurity, the findings underscore the need for organizations to adopt more automated and integrated approaches to threat management.