Cybersecurity

Cybersecurity Awareness Month: 7 Work-From-Home Security Habits Every Filipino Employee Needs

Cybersecurity Awareness Month: 7 Work-From-Home Security Habits Every Filipino Employee Needs

Why This Cybersecurity Awareness Month Matters for Your Home Office

The world is marking the 18th annual Cybersecurity Awareness Month this October under the theme "Do Your Part. #BeCyberSmart," and Metro Manila has just eased to Alert Level 3 for October 16 to 31 — yet most Filipino office staff still work from the dining table, on the same home WiFi the kids use for online class. That is why work from home security tips belong on your team's agenda: the perimeter is no longer the office firewall, it is every employee's house, and one careless click can expose an entire client list.

One honest note first. October's observance is the international one, led by CISA and the National Cybersecurity Alliance, which set out the theme and its weekly topics on October 5. The Philippines' own Cybersecurity Awareness Month falls in September, under Proclamation No. 2054, s. 2010 — a detail plenty of local posts get wrong.

The alert-level shift, announced October 13 under the NCR pilot of the granular alert-level system, reopens offices in shifts, not in full. Last week's official theme was "Fight the Phish!", so here are seven work from home security tips any employee can start today, plus what employers owe their teams. For a proper look at your whole setup, that is what our cybersecurity services for Philippine SMEs are for.

Habits 1 and 2: Lock Down Your Logins

Your password is now the company's front door. There is no receptionist between the public internet and your open Gmail tab.

Habit 1: Use a Different Password for Every Work Account

Most "hacks" are not clever. Someone breaches an old shopping site or forum, the leaked email-and-password list gets traded around, and attackers try those pairs against Gmail, Facebook, and company portals. That is credential reuse, and it is the cheapest way in.

We see it with our clients constantly: one password on the POS terminal, the office router, and the owner's Facebook page. Fix it with a password manager — LastPass, Bitwarden, and 1Password all do the job — so you memorize one master password, not thirty. No appetite for new software? Use long passphrases: MalamigAngKapeTuwingLunes beats Bytes@123 on both counts.

If you have just finished moving from a Facebook page to a full website, that is one more admin login to protect from day one.

Habit 2: Turn On Two-Factor Authentication Everywhere

Two-factor authentication, or 2FA, means the account asks for a second proof after your password — usually a six-digit code. With your password alone, an attacker stalls there.

Turn it on in this order: work email (Gmail or Google Workspace, or Outlook), the Facebook page you manage for the business, then GCash and PayMaya.

Where you get a choice, pick an authenticator app such as Google Authenticator over SMS one-time passwords. Texted codes can be intercepted or talked out of you — and with scam texts flooding Filipino phones this month, the less your security leans on SMS, the better.

Habits 3 and 4: Treat Your Home WiFi Like Office Infrastructure

Your ISP router is company infrastructure that nobody has ever audited — installed in a hurry, untouched since.

Habit 3: Change Your Router's Default Passwords — Including the Admin One

There are two passwords on that box, and people confuse them. The first is the WiFi passphrase you hand to visitors — make it long, and set the network to WPA2 encryption, not the older WEP.

The second is the router's admin login, which controls port forwarding, DNS settings, and who can see your network. Default admin credentials on common PLDT and Globe home units are not secrets; they are published and passed around. Our PLDT Fibr UNO admin access walkthrough exists because of it: if we could write those logins down in 2018, anyone within WiFi range can use them today.

Three quick wins while you are in there: rename the SSID so it stops announcing your unit number, check for a firmware update, and disable WPS.

Habit 4: Use the Company VPN for Work Files

A VPN — virtual private network — is an encrypted tunnel between your laptop and the office network, so files and logins cannot be read by anyone in between. If your employer issued one, use it every time you open work files. If nobody did, ask — the next section explains why owners should say yes.

Put the kids' online-class tablets, the smart TV, and the CCTV app on a separate guest network. Most PLDT Fibr and Globe At Home routers support a guest SSID, which keeps a compromised gadget away from your work laptop.

Habits 5 and 6: Fight the Phish — in Email and in Text

Week 2 of this year's awareness month, which began October 11, carried the theme "Fight the Phish!" Of the work from home security tips here, these two get tested most often — the bait now arrives on two screens at once.

Habit 5: Spot Phishing Emails Before You Click

The red flags:

  • Manufactured urgency. "Your payroll account will be suspended today." Real HR does not work that way.
  • Mismatched sender domain. Display name says your manager; the actual address is a free mailbox.
  • Generic greeting. "Dear valued employee," where everyone knows your first name.
  • A login page that is almost right. One extra letter, or a .net where the real site uses .com.

Then apply the ten-second rule: hover the link on a laptop, or long-press it on your phone, and read the real domain before you tap. When something feels off, verify through a channel you initiate — call the office landline, message the person in your Viber group. Never reply to the email itself.

You know the ones: an unsolicited text offering easy work-from-home income or a prize, with a shortened link attached. That is smishing — SMS plus phishing. On October 7 the National Privacy Commission issued PHE Bulletin No. 21 on exactly this: unsolicited messages linking to fraudulent sites that harvest personal data or install malware on your phone.

Its advice is worth repeating to every member of staff — do not click links from services you never signed up for, and block and report the spam numbers.

What makes this a work habit and not just consumer advice: the phone receiving that fake job offer also holds your company email, your Viber chats, and your GCash. One tap can hand over a trusted route into everything your employer trusts you with.

Habit 7: Update, Back Up, and Keep Customer Data Off Personal Apps

Let the updates run. Windows Update and browser updates patch the exact holes attackers rely on, and on a typical Windows 10 machine, Windows Defender plus current patches beats a paid antivirus whose license expired months ago.

Back up where the company says to back up. Work files belong in approved storage — Google Drive, OneDrive for Business, or the office server — not solely on one aging laptop. Our older guide to backing up a Windows Server to a virtual hard disk shows what a disciplined routine looks like.

Then keep customer data where it belongs. A spreadsheet of customer names and mobile numbers on your dining table is still personal data under the Data Privacy Act of 2012 (RA 10173), the law that created the National Privacy Commission — home office or not. So no dumping the customer list into a personal Messenger thread, and no forwarding client files to a personal email account para mabilis.

What Employers Owe Their Work-From-Home Teams

Most work from home security tips stop at the employee. They shouldn't. If a staff member has no VPN, no written policy, and nobody to call when something looks wrong, that failure is organizational.

The law already frames it. The Telecommuting Act, Republic Act No. 11165, approved in December 2018, put work-from-home on a proper footing: voluntary, treatment equal to on-site staff, and explicit obligations to protect the data telecommuting employees handle. By now it is simply the WFH law — and data protection is the employer's half of the bargain.

A workable minimum for a Philippine SME:

  • Provide a VPN for anyone touching customer records or financial systems.
  • Put a password and 2FA policy in writing — one page is enough.
  • License real endpoint antivirus on company laptops.
  • Run a short security orientation. This article can be the handout.
  • Decide, explicitly, where customer data may and may not live.

Most SMEs do not need a full-time IT department. They need someone accountable when a laptop goes missing or a router misbehaves — which is where managed IT outsourcing for growing teams earns its keep.

Cybersecurity Awareness Month ends October 31 — these habits shouldn't. If your team went remote in a hurry and security was an afterthought, we will walk through your setup — accounts, routers, VPN, data handling — and hand back a prioritized fix list. Book a quick call and we start with the highest-risk gap.

Empowering Businesses with Customized Software Solutions

Tell us what you need — we typically reply within the day. Let’s build something that drives your business forward.