

AS FILIPINOS increasingly rely on apps to move, save, borrow, and manage money, cybersecurity is becoming a more visible part of the financial experience — from the controls customers can use themselves to the systems and policies that keep services running when threats emerge.
At the recent BusinessWorld Cybersecurity Summit, Maya executives said this shift is changing how financial institutions approach security, what customers should expect and how regulators need to respond.
Maya has put more security controls directly in customers’ hands. Through its in-app features, users can immediately freeze or unfreeze their cards and manage how they are used. Biometric authentication, fraud monitoring, and other safeguards work in the background. Maya credit cards also use dynamic CVVs, adding another layer of protection for online transactions.
Maya also works with regulators and law enforcement agencies, including the Bangko Sentral ng Pilipinas (BSP), the Department of Information and Communications Technology (DICT)’s Cybercrime Investigation and Coordinating Center (CICC), the Department of Justice (DOJ), and the Philippine National Police (PNP).
For Kristoffer Rada, Maya’s head of corporate affairs, these measures reflect a broader shift in the relationship between cybersecurity and consumer trust.
“For us in Maya, cybersecurity is not some back-office product, it’s really part of the product,” Rada said. “As more people depend on digital financial services every day, maintaining trust becomes a responsibility shared by financial institutions, regulators, government and the broader ecosystem.
Rada said cybersecurity policy must balance strong safeguards and institutional accountability with the need to respond to rapidly changing technologies and risks.
The focus, he said, should go beyond compliance with individual rules. It should also protect customers, keep services running, strengthen accountability and ensure institutions can respond to and recover from cyber incidents.
“Technology evolves so fast. The rules that apply this year may no longer be applicable and could become archaic in five years,” Rada said. “Whatever technology evolves, you have to evaluate using the same standard because the risks are the same.”
Technology-neutral, risk-based standards can help regulations remain relevant, he said, but government and industry also need closer coordination.
Cyber risks increasingly cross the boundaries of banking supervision, data privacy, telecommunications, consumer protection and law enforcement. Rada said timely information-sharing, coordinated scam prevention and clear regulatory expectations are becoming increasingly important.
“Cyber threats do not stop at the boundaries of one company, one regulator or one country,” he said. “The stronger the coordination across the ecosystem, the better we can protect customers and maintain confidence in digital services.”
Building resilience across the enterprise
Jan Martin Encina, Maya’s director of information security, said organizations must treat cybersecurity as an enterprise-wide responsibility rather than leave it solely to IT teams.
“Cybersecurity is no longer just an IT issue; it is a business imperative, a national security priority and a fundamental component of public trust,” Encina said.
He said strong cyber resilience requires organizations to move beyond reactive defenses and adopt continuous monitoring, stronger identity and access management, resilient infrastructure, regular security testing and well-established incident response capabilities.
People also play a critical role in that defense. Ongoing employee awareness and customer education remain important as cybercriminals increasingly combine technology with social engineering and other tactics that exploit human behavior.
Encina also stressed the value of public-private partnerships, cross-border cooperation and threat-information sharing as cyberattacks become more sophisticated and interconnected.
“Ensuring that personal data is collected, stored and processed responsibly is not only a regulatory requirement, but also a moral obligation to the citizens and customers we serve,” he said.
For Maya, cybersecurity now operates on several fronts: giving customers greater control, strengthening defenses behind the scenes, building institutional resilience, and creating a regulatory environment that can keep pace with evolving technologies and threats. PR