Most important for cybersecurity is the human factor

by Patricia B. Mirasol, Producer
Experts highlighted the importance of the human factor in combatting cyberthreats in an October 9 forum by P&A Grant Thornton, a professional services firm.听
Social engineering (the use of deception to manipulate people into giving away private information) is as potent now as it was back in 2000, Leonard B. Duque, CIO of the company鈥檚 technology solutions group, said.听
鈥淚t鈥檚 still the number one entry of cyberattacks,鈥 he said. 听
Human error is cybersecurity鈥檚 bane, according to Mr. Duque.听
鈥淲hen employees ignore your guidance and click on links, those are human-based mistakes… When upper management doesn鈥檛 prioritize cybersecurity, that鈥檚 a human decision,鈥 he added.听
, a non-profit organization for cybersecurity professionals, the top three skills gaps at an organization are cloud computing security (35%), artificial intelligence/machine learning (32%), zero trust implementation (29%).听
Artificial intelligence (AI) is already the fastest growing technology in history, according to Alexis C. Bernardino,听field CISO and head of enterprise consulting practices at PLDT Enterprise.听
鈥淚t took the Internet 23 years to reach 1 billion users. It will only take AI 7 years to reach the same number,鈥 he said. 听
鈥淲ith that adoption,鈥 he added, 鈥渢he attack surface will increase.鈥听
Most of the cyberthreats identified in 2022 by the European Union Agency for Cybersecurity (ENISA) are related to AI, Jeffrey Ian C. Dy, undersecretary for the听Department of Information and Communications Technology (DICT), noted in the same event.听
That said, 鈥渘o firewall is stronger than a workforce trained to think critically, adapt rapidly, and respond decisively.” 听
Even end-users have to be concerned, Mr. Dy said.听
“The number one identified threat identified by ENISA is supply chain compromise, [yet] cybersecurity can鈥檛 just be the vendor鈥檚 responsibility,鈥 he said.听
鈥淲e鈥檙e trying to get legislation onboard such that it also becomes your concern,鈥 he told the event audience. 听
Mr. Dy added that the DICT is collaborating with social media platforms to implement automatic information labeling. The initiative aims to improve public understanding and surface 鈥渧erified sources of truth.鈥听
Human-centricity is the trend in security design practices in 2024, .听
By 2027, 50% of large enterprise CISOs will have adopted such an approach, the research showed.听
鈥淚n the early 2010s, the focus was on technical implementation,鈥 Mr. Duque said. 鈥淭he catalyst for the security awareness shift was COVID.”
Think of it as a shared responsibility, advised Mr. Bernardino.听
鈥Ang trabaho po natin is pahirapan ang buhay nung [Our role is to make it hard for the] hacker to be able to exfiltrate data,鈥 he said.听
鈥淚f employees are made aware, they could be the first line of defense and force multiplier in cybersecurity,鈥 he added.听
– up from 77 in 2020 – in the Global Cybersecurity Index of 2024. The area where the country most improved is in workforce capabilities.听


