CyberCode.ph · Philippines

Cyber Incident Response Checklist Philippines

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 3, 2026

Direct Answer

A cyber incident response should move quickly from verification and containment to evidence preservation, eradication, recovery, notification and lessons learned. The organization should document every major action and preserve the information needed for technical, legal and regulatory reporting.

First 60 Minutes

  • Confirm the incident and assign an incident owner.
  • Record the detection time and initial indicators.
  • Isolate affected devices or accounts when safe to do so.
  • Preserve logs, alerts and volatile evidence.
  • Disable or rotate compromised credentials.
  • Identify affected systems, services and data.
  • Escalate to management, IT, security, legal and privacy personnel as required.

Containment and Investigation

  • Block malicious domains, IPs, sessions or access paths.
  • Capture indicators of compromise.
  • Determine the attack vector and likely scope.
  • Check for persistence, lateral movement and exfiltration.
  • Protect clean backups from compromise.
  • Maintain an incident timeline and decision log.

Reporting

CERT-PH accepts cybersecurity incident reports and provides technical assistance. If personal data is involved, assess NPC breach-notification obligations separately. If criminal conduct is suspected, consider CICC, NBI or PNP reporting.

Recovery

  • eradicate malware and unauthorized access;
  • patch exploited vulnerabilities;
  • restore systems from trusted sources;
  • monitor closely for recurrence;
  • validate business operations before full return to service;
  • complete a lessons-learned review.

Official Sources