Posted on Leave a comment

US$7B opportunity, zero competition: Why SEA integrators are sleeping on Manila’s cyber modernisation

On July 25, Defense Secretary Gilberto Teodoro Jr. ordered the Armed Forces of the Philippines to widen its Direct Commission Program (DICOM), fast-tracking cyber, AI, and engineering talent into commissioned officer roles. Defence spokesman Arsenio Andolong was blunt about the logic: some of the country’s best hackers are unemployed, and the state would rather channel that talent than lose it to cybercrime.

Most coverage stopped there — a recruitment story. That’s exactly why the real opportunity is still sitting open. Recruiting a few hundred officers doesn’t build or run a modern military’s cyber backbone. It’s a talent signal sitting atop an integration, training, and sustainment gap that no single Philippine agency can close alone — and one that almost no SEA integrator has priced into their pipeline yet.

The size of what’s actually up for grabs

DICOM sits within a much larger machine: the AFP’s Comprehensive Archipelagic Defence Concept and its Horizon 3 modernisation phase, which, for 2026, carries a defence budget of roughly ₱430 billion (US$7.08 billion), with tens of billions earmarked specifically for cyber and command-and-control systems.

Set against that budget is a workforce gap DICT itself has been flagging for years: roughly one cybersecurity professional for every 2,000–3,000 citizens, against a mature-economy benchmark near 1-in-200. Other estimates put unmet demand at around 180,000 professionals just to cover 10 per cent of critical institutions.

Put those two numbers side by side, and the gap is the opportunity: a ₱430-billion (US$7.08 billion) modernisation program with nowhere near the domestic technical bench to execute it, and almost no regional integrators actively positioned to fill that bench. This isn’t a crowded RFP market yet — it’s closer to whitespace.

Where DICT and CICC actually fit — and why most pitches miss half the buyer

Here’s the mistake most outside vendors make: they treat the AFP as the only buyer. It isn’t. The Philippines built a division of labor after the Cybercrime Prevention Act (RA 10175) and the law creating DICT (RA 10844): law enforcement (NBI, PNP-ACG), intelligence (NICA), national defence (DND/AFP, NSC), and — sitting in the middle — network protection, split across DICT and its attached agency, the Cybercrime Investigation and Coordinating Center (CICC).

Also Read: Human-centric skills in the age of AI: How to never lose touch with humanity in the workplace

Vendors who only build a relationship with DND miss half the approval chain. That’s precisely why “zero competition” isn’t hyperbole — most firms aren’t even mapping the right buyers.

Eight concrete plays for SEA integrators — before this stops being whitespace

  • Systems integration and interoperability layers — stitching legacy AFP comms, newly acquired foreign platforms, and DICT’s NCERT/NSOC feeds into one auditable architecture, instead of another siloed point solution.
  • Managed detection and response for under-resourced agencies — CICC’s thin technical bench is a direct opening for outsourced SOC-as-a-service and incident-response retainers tied to existing reporting requirements.
  • Workforce-scale training and certification pipelines — bootcamps and university partnerships, in the spirit of the UP–DICT microcredentials model, producing hundreds of vetted operators a year — not the handful DICOM can commission.
  • Sovereign, auditable software builds — co-developed or locally-built detection, logging, and command-support tools that satisfy data-sovereignty and JV-ownership rules foreign closed-source vendors can’t.
  • Multi-year sustainment contracts — maintenance and local technical support built in from day one, addressing the exact failure mode analysts cite in past hardware procurement.
  • Compliance and reporting tooling — dashboards that help agencies meet the pending DICT/CICC critical-infrastructure incident-reporting mandate, a near-guaranteed procurement line once the legislation passes.
  • AI-readiness and data-governance consulting — auditing data pipelines and setting decision-vs-flag guardrails before any model goes live, positioning integrators as foundation-builders, not platform-sellers.
  • Regional threat-intelligence sharing infrastructure — tools that let the AFP participate in allied information-sharing (e.g., under the US–Philippines defence guidelines) without breaching data-localisation rules — a genuinely unmet niche.

Firms that check off two or three of these — not just pitch a single flagship platform — are the ones positioned to actually survive procurement cycles that move slower than the news.

Why the whitespace exists — and won’t stay open forever

The AFP’s own modernisation is still assembling itself in phases — Horizon 1 gave frigates and jets, Horizon 2 gave rocket systems and submarines — and analysts call the process piecemeal, project-by-project rather than unified. Few local firms have end-to-end integration experience at this scale. Commentators still point to the Jose Rizal-class frigate program as a cautionary tale of systems bought without maintenance planning — a risk cyber platforms carry just as heavily. That gap is real, but temporary: the government’s own legislative pipeline is working to close it.

The barriers that are keeping the field this empty

Ownership ceilings

Under RA 12024, foreign firms need a Filipino JV partner holding at least 60 per cent. RA 11647 lets the President block foreign investment in “strategic” cyber industries outright — exactly why most foreign players haven’t bothered.

Hardware-first procurement law

RA 10349 and RA 10055 were built around buying hardware, not software expertise. Pending bills would add a dedicated innovation office and capacity fund, but expect processes calibrated for frigates, not SaaS — for now.

Budget volatility

Of ₱90 billion (US$1.48 billion) proposed for 2026, only ₱40 billion (US$659 million) was firmly programmed; the rest depends on new revenue. In 2024, the Senate had to restore a ₱10-billion (US$165 million) cut to cyber-related projects. Structure contracts to survive a legislature that treats this funding as negotiable.

“Ghost project” scrutiny

The AFP has uncovered ghost projects within its own modernisation spending — treat that scrutiny as a filter favouring credible operators over opportunists.

Data localisation tension

Industry groups warn broad localisation mandates can isolate defenders from threat-sharing. Systems must satisfy sovereignty rules without severing allied intelligence-sharing under US-Philippines defence guidelines.

These barriers explain why the market stays thin. They’re not permission slips for foreign platform vendors — they’re a moat that favours integrators with a real local partnership and patience.

Also Read: The anti-hustle manifesto: Why being strategic beats being the best

Is anyone actually opposing this?

No official has publicly opposed the DICOM expansion itself. The friction is structural, not ideological:

None of this is opposition — it’s a signal that execution, not intent, is the real battleground, and where a patient, credible integrator wins.

Where AI fits — and why sequencing matters

AI is an obvious accelerant for a talent-constrained cyber effort: threat detection, log analysis, anomaly detection, decision support. That’s a legitimate line item.

But this is a matter of national security, not just good practice: Filipino institutions need their own foundations — trained analysts, governed data pipelines, clear rules on what AI may decide versus flag, and homegrown audit capacity — before layering AI on top.

A system deployed without that foundation doesn’t just underperform; it can distort judgment and create dependency on foreign black boxes the country can’t independently verify in a crisis. Integrators leading with “buy our AI platform first” are pitching the wrong stage. Those who build talent, data discipline, and audit capacity first — in coordination with DICT’s NCERT/NSOC infrastructure and CICC’s coordination role, not around them — win the long-term contract.

The bottom line

This is a ₱430-billion (US$7.08 billion) modernisation program with a documented skills gap, two agencies quietly competing for the same talent pool, and a legal framework still built for buying hardware rather than software. That combination is precisely why competition is thin: most integrators saw a recruitment headline and moved on, without mapping DICT, CICC, the ownership rules, or the actual services gap underneath. The integrators who understand the full buyer chain, respect the procurement realities, and build local capacity before selling AI shortcuts have a genuine multi-year opportunity — and right now, remarkably little company.

This article synthesises public statements from the Department of National Defense, the AFP, DICT, CICC, the Philippine News Agency, and independent defence-policy analysis. It is a market and policy overview for technology integrators, not legal or investment advice.

Editor’s note: e27 aims to foster thought leadership by publishing views from the community. You can also share your perspective by submitting an article, video, podcast, or infographic.

The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of e27.

Join us on WhatsAppInstagramFacebookX, and LinkedIn to stay connected.

The post US$7B opportunity, zero competition: Why SEA integrators are sleeping on Manila’s cyber modernisation appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *