The Philippines is moving ahead with a $25.6-million National Cybersecurity Center designed to give the government a round-the-clock view of cyber threats and a central point for coordinating responses when attacks affect multiple agencies or critical systems.
The Department of Information and Communications Technology and Korea International Cooperation Agency moved the project into implementation during an inception workshop held on August 25. Twenty-five Philippine agencies took part, including the Bangko Sentral ng Pilipinas, Department of Finance, Bureau of Internal Revenue, Philippine Statistics Authority, Commission on Elections and the Philippine National Police Anti-Cybercrime Group.

The project is expected to run through 2029 and includes the establishment of the cybersecurity center, a national cyber threat response system, information-security management and training for cybersecurity professionals. South Korea’s Korea Internet & Security Agency, or KISA, is leading the implementing consortium for the $25.6-million official development assistance project.
But what exactly happens inside a national cybersecurity center?
A control room for threats that cross government networks
At its simplest, the National Cybersecurity Center is intended to give the government a broader picture of threats that individual agencies may only see from inside their own networks.
A security team at one government agency, for example, might detect attempts to exploit a particular vulnerability. Another agency could be receiving suspicious traffic from the same infrastructure without immediately knowing that the incidents are related.
A national monitoring capability makes it possible to bring those signals together, identify common attack patterns and distribute relevant threat information to other organizations that may also be at risk.
This becomes particularly important when an attack is not confined to one website or database.
Cyber campaigns can simultaneously target government portals, financial institutions, telecommunications networks and other digital infrastructure. Detecting that wider pattern requires information to move between organizations rather than remain inside separate security teams.
The Philippines’ National Cybersecurity Plan 2023-2028 already calls for a national cybersecurity threat database, proactive monitoring of threats affecting government cyberspace assets and a National Cybersecurity Intelligence Fusion Center linked to a national network of Computer Emergency Response Teams.
It does not replace every agency’s cybersecurity team
A national center does not necessarily mean every cyber alert inside a government agency will be handled directly from one control room.
Agencies still have their own systems, security personnel and responsibilities for protecting their networks. Their teams remain closest to their applications, users and data and would normally be the first to investigate incidents affecting their operations.
The national layer becomes more useful when a cyber incident needs coordination beyond one organization.
If the same threat begins appearing across several agencies, for instance, national cybersecurity teams can help determine whether the incidents are connected, distribute technical information about the attack and coordinate assistance.
The country’s cybersecurity framework also provides for a network of CERTs with defined responsibilities rather than a single team replacing every organization’s security operation.
In that sense, the National Cybersecurity Center would function less like one enormous IT department for government and more like a cybersecurity command and coordination layer above existing security teams.
The system has to keep working during a crisis
The project is also intended to strengthen the country’s ability to continue cyber monitoring and response even during disasters.
That matters because cybersecurity operations can become even more critical when normal government operations are disrupted.
During a typhoon, earthquake, major power interruption or other emergency, agencies may become more dependent on digital communications and online systems. A cyberattack occurring at the same time could compound the disruption if government security teams lose visibility over what is happening across their networks.
The Korean-backed project therefore covers more than construction of a facility said its work will include establishing an information-security management system, building the national center, developing a national cyber threat response system and creating programs for cybersecurity professionals.
Where BSP and banks fit into the system
The participation of the BSP is particularly relevant for the financial sector, but the establishment of a national cybersecurity center should not be interpreted as DICT taking over cybersecurity monitoring inside Philippine banks.
Banks and other BSP-supervised financial institutions remain responsible for protecting their own systems and operate under separate cybersecurity and technology-risk requirements imposed by the central bank.

The BSP also maintains a dedicated Financial Services Cyber Resilience Plan 2024-2029 for the financial sector.
Under that framework, the central bank identifies itself as the lead Computer Emergency Response Team for the banking sector and calls for coordinated cyber resilience efforts among financial institutions, government agencies and private-sector participants.
That creates several layers of response.
A cyber incident affecting one bank would first involve the institution’s own cybersecurity operations and the BSP’s supervisory framework. But an attack campaign targeting banks together with government agencies or other critical infrastructure could require intelligence and coordination beyond the financial sector.
This is where participation in a broader national cyber framework becomes useful.
Attackers can reuse the same malicious infrastructure, vulnerabilities and techniques across different organizations. Information gathered from an attack against one institution could therefore help another organization detect or block similar activity earlier.
The bigger challenge is turning monitoring into response
Building the National Cybersecurity Center creates infrastructure for seeing more of what is happening across the country’s digital systems.
The harder part will be making sure information gathered by the center reaches the right organizations quickly enough to make a difference.
A threat detected in the middle of the night is only useful if the affected agency can be warned, investigate the activity, isolate compromised systems and begin recovery before the attack spreads.
That requires technology, but it also requires clearly defined responsibilities, skilled cybersecurity personnel and agencies that can exchange information quickly during an incident.
For the Philippines, the $25.6-million investment is therefore not simply about creating another government cybersecurity facility.
The larger objective is to build a national layer where cyber threats that initially appear to be isolated alerts can be connected, understood and acted on as part of a wider attack.
