IJE Software logoIJEsoft
ServicesPortfolioPricingAboutCase StudyStackNewsBlogPartnerPH NewsMarketsContactGet in touch
← Back to Philippines Business News
BusinessWorld

Credential abuse becomes preferred cyberattack tactic, Kaspersky says

CREDENTIAL ABUSE is among the most effective techniques used by cyberattackers, with criminals now increasingly relying on these tactics over malware, according to a report by Kaspersky Security Services. Attackers found better success in getting access to users’ data while evading detection via password guessing and valid account misuse in 2025, triggering a shift from […]

Context & Analysis

The shift toward credential abuse reflects a broader reality in Philippine digital transformation: convenience has outpaced security discipline. As more micro, small, and medium enterprises migrate to cloud platforms, remote work arrangements stabilize, and government services move online, the attack surface expands beyond traditional network perimeters. Malware requires delivery mechanisms and technical execution, but stolen or guessed credentials simply walk through open doors. For Filipino business owners, this means cybersecurity is no longer an IT department concern. It is a boardroom governance issue tied directly to operational continuity, client trust, and regulatory compliance.

Philippine regulators have already signaled that authentication failures will not be tolerated as collateral damage of digital adoption. The National Privacy Commission continues to enforce breach notification requirements under the Data Privacy Act, while the Bangko Senteng Pilipinas and Securities and Exchange Commission tie cyber risk management to licensing and corporate disclosure standards. Companies that treat password hygiene and access controls as optional will face mounting penalties, higher insurance premiums, and strained relationships with larger partners who demand supply chain security audits. The business process outsourcing sector, which handles sensitive data for global clients, is particularly exposed. A single compromised vendor account can trigger cross-border liabilities and contract terminations.

What should investors and operators monitor next? Expect a measurable pivot in enterprise spending from perimeter defenses toward identity management, behavioral analytics, and automated access revocation. Watch for tighter NPC guidance on authentication standards, potential BSP circulars requiring financial institutions to enforce strict session controls, and SEC updates mandating clearer cyber risk disclosures in annual reports. Meanwhile, consumers will increasingly expect frictionless yet secure logins, pushing fintechs and e-commerce platforms to balance user experience with verification rigor.

The lesson is straightforward. In an economy racing toward digital maturity, credentials are the new vault keys. Protecting them requires policy, training, and continuous monitoring—not just software. Firms that treat identity security as a core operational metric will preserve margins and market confidence. Those that delay will pay for it in downtime, compliance fines, and eroded client loyalty.

Analysis by IJE Software — original commentary on the story above.

This is an excerpt. Read the full article at the original source:

Source: bworldonline.com

More from BusinessWorld

Philippine NG debt hits record-high P19.39 trillion

9h ago

Philippines’ fiscal deficit-to-GDP ratio to further narrow until 2027

9h ago

Hydrogen seen as long-term energy solution for Philippines but high costs remain a barrier

9h ago

MGEN starts MTerra Solar Phase 1 commercial operations

10h ago

Your Daily Briefing

AI business companion — delivered every morning

Markets, PH news, financial insights, and devotionals — curated by AI and sent at 7 AM PHT. Pick your topics below.

Devotionals
Blog Topics
HR & Workforce
Real Estate & Property
News & Markets

1 topic selected