Last materially reviewed: September 3, 2026
Direct Answer
The Philippines does not have one single agency for every cyber issue. Responsibilities are split among cybercrime investigators, cybersecurity responders, prosecutors, privacy regulators and policy bodies. Knowing which office handles which problem can save time during an incident.
Core Government Cybersecurity Agencies
| Agency | Primary role |
|---|---|
| CICC | Cybercrime coordination, public reporting and anti-scam initiatives |
| DICT Cybersecurity Bureau / CERT-PH | National cybersecurity coordination and computer security incident response |
| NBI CyberCrime Division | Investigation of computer crimes and digital evidence |
| PNP Anti-Cybercrime Group | Law-enforcement investigation of cybercrime |
| DOJ Office of Cybercrime | Cybercrime prosecution strategy, international cooperation and legal coordination |
| National Privacy Commission | Data Privacy Act enforcement, complaints and personal data breach regulation |
When to Use CERT-PH
CERT-PH, under the DICT Cybersecurity Bureau, receives and responds to computer security incident reports. It is the appropriate technical channel for incidents involving compromised systems, malware, vulnerabilities, denial-of-service activity and other cybersecurity events affecting organizations.
When to Use Law Enforcement
Use the NBI CyberCrime Division, PNP Anti-Cybercrime Group or CICC when the issue may involve a criminal offense such as hacking, online fraud, account takeover, identity theft, cyber libel or unauthorized access.
When to Use the NPC
If the incident concerns misuse, unauthorized disclosure or a breach of personal data, the National Privacy Commission may have jurisdiction under the Data Privacy Act. See the Data Privacy Complaint Checklist.
