GMAsia
    🇵🇭Philippines·Policy·18 Sept 2026·via Newsbytes

    DICT orders annual security testing for gov’t IT systems

    The Department of Information and Communications Technology (DICT) has mandated annual cybersecurity assessments for all Philippine government agencies. Department Circular No. HRA-008, series of 2026, requires Vulnerability Assessment and Penetration Testing (VAPT) yearly and after major system changes. This applies to national agencies, government-owned corporations, state universities, and local governments. Critical flaws must be fixed within five business days, with other vulnerabilities resolved in 30 business days.

    Nexa's Summary

    The DICT order for annual VAPT across Philippine government systems moves beyond basic compliance. It establishes concrete deadlines: critical flaws require fixes within five business days. This structure aims for continuous security improvement, not just periodic checks. The focus is on faster remediation, which is a practical step for public sector cyber defense.

    This policy creates a clear opportunity for cybersecurity providers in the Philippines. Agencies can use internal teams, but the DICT also accredits external providers through its D-TAP portal. This formal accreditation process could drive demand for specialized local firms. It also sets a standard that other Southeast Asian governments might watch for their own digital transformation efforts.

    The test for this directive is its actual enforcement and the DICT's capacity to monitor compliance and remediation. The government must ensure agencies have the budget and personnel to meet the five-day critical flaw deadline. This will determine if the circular genuinely strengthens national cybersecurity or becomes another unfunded mandate.

    #vulnerability assessment and penetration testing#dict#e-security
    Original reporting by NewsbytesWe don't republish, read the full story →

    Related reading

    6 stories