CyberCode.ph · Philippines

Cybersecurity Incident Response Plan Philippines: What Businesses Should Prepare

Last updated September 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: September 3, 2026

Direct Answer

A cybersecurity incident response plan tells a business who must act, what must be protected, how an incident is escalated, how evidence is preserved and how systems are restored. In the Philippines, the plan should also include a privacy-breach assessment because a cyber incident involving personal data may trigger obligations under the Data Privacy Act and National Privacy Commission rules.

Key Takeaways

  • Define roles before an incident happens.
  • Separate detection, containment, eradication and recovery decisions.
  • Preserve logs, emails, screenshots and affected devices before evidence disappears.
  • Include legal, privacy, communications, IT and management escalation paths.
  • Test the plan regularly and update it after incidents or major system changes.

Jump to a Section

What Should an Incident Response Plan Contain?

At minimum, document the incidents covered, emergency contacts, reporting channels, severity levels, decision makers, evidence-handling rules, containment authority, recovery priorities, external providers and regulator/law-enforcement escalation paths.

The National Privacy Commission requires personal information controllers and processors to implement a security incident management policy. NPC guidance also calls for a security incident response team, preventive controls, response procedures, mitigation and compliance with breach-notification requirements.

A Practical Incident Response Process

1. Prepare

Maintain current asset lists, privileged-account records, emergency contacts, backups, logging, access to security tools and copies of the response plan that remain available if core systems go offline.

2. Detect and verify

Record what triggered the alert, when it began, which accounts or systems are affected and whether the incident is still active. Do not assume every alert is a confirmed breach, but do not delay preservation of evidence.

3. Contain

Containment may involve disabling compromised accounts, isolating devices, blocking malicious domains, suspending exposed credentials or restricting network access. Avoid destructive actions that unnecessarily erase evidence.

4. Eradicate

Remove the root cause: malicious software, unauthorized accounts, vulnerable plugins, exposed API keys, compromised passwords or unsafe configurations.

5. Recover

Restore services from trusted systems and backups, monitor for recurrence, rotate credentials and confirm that repaired systems are functioning normally before returning them to full production.

6. Review

Document the timeline, impact, decisions, costs, root cause, missed warning signs and improvements. Assign owners and deadlines to the corrective actions.

Who Should Be on the Response Team?

The exact team depends on organization size, but the function normally needs IT/security, management, privacy/data protection, legal, communications and business-process owners. External cloud providers, forensic specialists, insurers or counsel may also be part of the escalation tree.

NPC guidance does not prescribe a single formula for the response team, but it expects the team to be capable of assessing the incident, restoring system integrity, mitigating damage and complying with reporting duties.

When Does a Cyber Incident Become a Data Privacy Issue?

If an incident affects personal data, assess whether there has been unauthorized access, disclosure, alteration, loss or destruction. A security incident is broader than a personal data breach; not every cybersecurity event is automatically a notifiable breach.

Use the Data Breach Notification Philippines guide and the Data Breach Response Checklist for the privacy-specific decision path.

Incident Severity Levels

A simple severity model can help: low for contained events with no material impact; medium for limited compromise requiring coordinated remediation; high for active compromise, significant outage, sensitive-data exposure or fraud; and critical for organization-wide disruption, major financial loss or serious risk to affected individuals. Define the criteria before an emergency.

How Often Should the Plan Be Tested?

Run tabletop exercises at least periodically and after major changes to systems, vendors or organizational structure. A tabletop exercise walks the team through a realistic scenario such as ransomware, business email compromise or a cloud-account breach and tests decisions without disrupting production.

Minimum Incident Response Checklist

  1. Record detection time and reporter.
  2. Assign an incident lead.
  3. Preserve logs and evidence.
  4. Identify affected assets and accounts.
  5. Contain the active threat.
  6. Assess personal-data impact.
  7. Notify management and required specialists.
  8. Recover from trusted systems and backups.
  9. Monitor for recurrence.
  10. Complete a post-incident report and corrective-action list.

Frequently Asked Questions

Is an incident response plan legally required?

For organizations processing personal data, NPC rules require a security incident management policy and procedures for managing security incidents and personal data breaches. The broader cybersecurity plan should be aligned with those requirements.

Should the plan include ransomware?

Yes. Ransomware should be one of the scenarios tested because it can affect availability, integrity, confidentiality, backups and business continuity at the same time. See the Ransomware Attack Philippines guide.

Should employees report suspicious events even if they are unsure?

Yes. Internal reporting should be easy and fast. The incident team, not the employee, should determine whether an event is a confirmed security incident.

Related Cybercode Guides

Official Sources