A series of cyber incidents in the Philippines’ IT-BPM industry highlights the urgent need for enhanced data governance and security measures to maintain global trust and competitiveness amid rising risks and automation pressures.
Philippine information technology-business process management firms are being urged to tighten data governance and privacy controls as a series of cyber incidents raises the risk of reputational damage in an industry already under strain from automation and slower growth. Analysts say the sector’s standing as a global outsourcing hub depends increasingly on whether it can prove it can protect client data as effectively as it processes it.
Dominic Vincent D. Ligot, director for AI Ethics & Data Governance at the Philippine AI Business Association, said even a single alleged insider incident can affect how international clients assess risk, particularly when delivery work is based offshore. He said the latest breach should not be treated as a broader indictment of the workforce, but as a warning that weak controls at any point in the chain can damage confidence across the sector. He added that the issue is not confined to offshore operations, but reflects failures in end-to-end governance.
The warning comes after Australian authorities detected a breach linked to a former employee at a Manila-based call centre, which exposed the personal and financial details of about 900,000 Origin Energy customers in Sydney. The episode followed a similar vishing attack on Qantas’s Manila-based contact centre last year, reinforcing concerns that social engineering and insider misuse remain persistent risks for large service operations in the Philippines. Industry observers say such cases can magnify perceptions that outsourcing locations carry weaker controls, even when the underlying failures are isolated.
The Information Technology and Business Process Association of the Philippines said its member companies continue to invest in stronger safeguards, responsible access to information and compliance with applicable laws. The group has also been working with stakeholders to raise privacy standards and cybersecurity awareness. It said data protection is central to the trust that sustains the country’s IT-BPM industry.
Analysts and industry advocates say firms now need more than generic security policies. Mr Ligot called for tougher personnel screening, role-based and time-limited access, segregation of duties, continuous monitoring, rapid revocation of access and clearer whistleblowing channels. He also said contracts should spell out data ownership, permitted artificial intelligence tools, subcontracting limits and incident notification timelines. Ronald B. Gustilo of Digital Pinoys said the industry must build competitiveness on security and governance, not only on low labour costs.
His comments align with broader policy discussions in Manila, where the Senate committee on science and technology is developing measures to support the sector as automation changes employment patterns. That concern is sharpened by fresh cyber-risk data: a Viettel Cyber Security report said the Philippines logged 255 breach incidents in the first half of 2026, exposing about 335 million records and 19.2 million account credentials. IBPAP’s latest roadmap also points to a more cautious outlook, with the sector now seen reaching at least $43.3 billion in revenue and 1.85 million AI-enabled workers by 2028, below earlier projections.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





