Both agencies emphasized that the people deserve more than assurances and deseve “reliable, clear, and verified information.”
In a joint statement issued on Wednesday, September 9, the Department of Information and Communications Technology (DICT) and the Cybercrime Investigation and Coordinating Center (CICC) recognized the public’s concerns regarding the security of government digital systems, the protection of personal information, and the continuity of essential services.
They emphasized that cybersecurity is an “institutional responsibility” and reminded employees and the public to exercise caution. Although, it also does not diminish the government’s obligation to protect the systems and information entrusted to it.
“Public concerns must be met with concrete protective measures, timely response, and honest reporting,” the DICT and CICC said.
Thus, through a Joint Cybersecurity Advisory, all national government agencies, government-owned and controlled corporations, local government units, and operators of Critical Information Infrastructure have been placed under “heightened cyber vigilance” status.
According to both agencies, covered organizations are directed to undertake the prescribed cybersecurity measures and provide their agency head or chief executive with a one-page cyber readiness assessment identifying their most serious risks, immediate actions taken, and assistance required within 24 hours of receipt of this advisory.
“Priority actions include addressing critical vulnerabilities, enforcing multi-factor authentication for critical and privileged accounts, removing unnecessary internet exposure, strengthening security monitoring, verifying backup recoverability, reviewing third-party access, and validating incident-response and service-continuity procedures,” they said.
The DICT and CICC also emphasized that the readiness must be assessed using the green-amber-red status.
They explained that Red conditions require immediate reporting and response, while Amber conditions require remediation and monitoring. As regards to Green, it requires continued vigilance and does not mean zero risk.
“Suspected serious incidents must be escalated immediately and agencies must not waut for the completion of the 24-hour assessment before reporting a potential compromise,” they added.
Assessments are must accurately identify weaknesses, actions taken, and unresolved concerns requiring assistance, with both agencies stressing that this exercise must produce protective action. Agency heads and chief executives are also directed to lead implementation.
“DICT and CICC will coordinate with affected agencies to provide verified public updates on incidents affecting government services. These updates will distinguish confirmed findings from preliminary assessments and matters still under investigation, explain available service alternatives, and indicate when further information will be provided,” they added.
Meanwhile, statements concerning possible exposure of personal information must also reflect the scope and limitations of the technical assessment.
“Attribution to any individual, group, or foreign actor will be based on validated evidence—not speculation. Sensitive technical details will be protected without using the needs of an investigation as a blanket reason to withhold basic public-service information,” the agencies reminded.
DICT, through its Cybersecurity Bureau and National Computer Emergency Response Team, together with CICC and cybersecurity and law-enforcement partners, will also monitor threats and coordinating appropriate defensive measures across government and critical infrastructure.
Prior to this, last Monday, September 7, the DICT’s Cybersecurity Bureau, through the National Computer Emergency Response Team (NCERT), said that it was responding to multiple cyber threats detected across various government agencies.
It noted that these include unauthorized access to the website of the Department of Migrant Workers (DMW), a web defacement incident involving the Department of Labor and Employment (DOLE), and an alleged ransomware attack affecting the Philippine Ports Authority (PPA).
In response to the unauthorized access detected on the DMW website, the DICT said it had activated emergency incident protocols through direct coordination and on-site technical response with the DMW Management Information Technology Service (MITS).
The joint technical teams also immediately implemented access-control hardening and system isolation measures in aid of the ongoing forensic investigation and system recovery.
Meanwhile, upon detecting the unauthorized modification on the DOLE web host, the DICT promptly notified DOLE IT administrators and initiated coordinated response protocols.
“Designated agency focal persons confirmed that primary system and access-control measures were immediately enforced to isolate the affected node, support ongoing digital forensics, and facilitate safe system restoration,” the DICT stated.
It also added that initial technical assessments confirm that no sensitive databases or Personally Identifiable Information (PII) were compromised.
However, as a precautionary measure to ensure complete threat eradication and security hardening, the affected web services at DMW and DOLE were temporarily taken offline.
NCERT and agency technical teams are actively collaborating to finalize root-cause investigations and safely restore full web service availability.
Following reports alleging a ransomware attack targeting PPA systems, NCERT promptly alerted agency administrators via an official incident report.
“During a subsequent technical assessment, joint logs with the agency’s designated focal personnel verified that the report was a false positive, confirming that no ransomware activity or system compromise occurred within PPA infrastructure,” it added.
Investigation and mitigation procedures continue to be actively conducted by technical teams from the DICT and partner agencies.
