How Can Executives Defend Cybercrime Complaints?

How Can Executives Defend Cybercrime Complaints?

Introduction

Corporate executives may be named in cybercrime complaints because of their positions, authority over information-technology systems, or association with employees who allegedly committed unauthorized access, surveillance, data extraction, or hacking. However, corporate position alone does not establish criminal liability.

A sound defense must separate the alleged acts of individual hackers or employees from the executive’s own conduct. It must also test whether the complaint identifies a specific unlawful act, proves the executive’s participation or gross negligence, and complies with constitutional and procedural safeguards governing digital evidence.

The principal defenses discussed below apply conditionally. The proper strategy depends on the exact offense charged, the allegations in the complaint or information, the executive’s authority, the evidence relied upon, and whether a criminal case has already been filed in court.

What Cybercrime Allegations May Affect Corporate Executives?

Common accusations include unauthorized access, computer-related identity theft, illegal interception, cyber-related data offenses, and participation in the use of computer systems to commit another crime.

Under the Cybercrime Prevention Act, computer-related identity theft involves the intentional acquisition, use, misuse, transfer, possession, alteration, or deletion of identifying information belonging to another, without right. The Supreme Court upheld the validity of this offense, subject to constitutional safeguards protecting privacy and due process. See [Disini, Jr. v. Secretary of Justice, G.R. No. 203335, February 18, 2014](#J2.20).

An executive may therefore face exposure where evidence shows that the executive personally ordered, knowingly approved, participated in, or through gross negligence allowed the unlawful conduct. Mere ownership, directorship, supervision, or receipt of a business benefit is not automatically equivalent to criminal participation.

What Must the Complainant Prove?

The defense should require the complainant to identify the precise statutory offense and establish every element of that offense. A complaint that merely alleges a “hack,” “breach,” or “surveillance operation” without identifying the act, system, data, date, device, and responsible person is vulnerable to challenge.

The following questions are central:

  • What specific computer system or account was accessed?
  • What data was acquired, altered, transferred, intercepted, or deleted?
  • Was the access without right or beyond the scope of authorization?
  • Did the executive personally participate or direct the act?
  • Was there proof of knowledge, intent, conspiracy, or gross negligence?
  • Was the digital evidence lawfully obtained and properly authenticated?

These questions prevent criminal liability from being based solely on an executive’s title or general responsibility for company operations.

Can an Executive Be Liable for an Employee’s Cybercrime?

Not automatically. Individual criminal liability ordinarily requires proof connecting the executive to the prohibited act. The prosecution must show more than the existence of an employer-employee relationship or the executive’s general power to supervise the company.

Where the accused is a corporation or other juridical person, statutory provisions may impose penalties on responsible officers who participated in the offense or, through gross negligence, allowed it to occur. This does not dispense with the need to prove the officer’s participation, authority, knowledge, or gross negligence.

Administrative decisions under the Data Privacy Act illustrate this distinction. In [NPC SS 21-006, In re: Wefund Lending Corporation (JuanHand) and its Responsible Officers](#I2.74), the National Privacy Commission emphasized that corporate officers cannot be held criminally liable merely because of their positions without substantial evidence of direct participation or gross negligence.

Similarly, in [NPC SS 21-023, In the Matter of the Alleged Personal Data Breach of BDO Unibank, Inc.](#I5.25), allegations concerning the board’s knowledge of a security incident were not, by themselves, sufficient to establish individual liability. The evidence must connect the particular officer to the statutory violation.

How Should the Defense Distinguish Authorization from Illegal Access?

Many cybercrime complaints arise from legitimate security testing, internal investigations, incident response, system maintenance, or employee monitoring. The defense should establish whether the access was authorized, limited, and connected with a legitimate corporate purpose.

Relevant evidence may include:

  • Board or management resolutions;
  • information-security policies and acceptable-use policies;
  • employment agreements and confidentiality undertakings;
  • incident-response protocols;
  • penetration-testing or cybersecurity contracts;
  • access-control records and system logs;
  • tickets, work orders, and written instructions;
  • reports prepared by information-technology personnel; and
  • communications showing the scope and purpose of the activity.

The Supreme Court recognized that ethical hackers may use techniques associated with criminal hacking but remain protected when they act with prior permission and within the agreed scope of the engagement. The existence and limits of authorization should therefore be proved through contemporaneous documents rather than unsupported assertions.

The defense must also examine whether an employee exceeded the authority granted. Authorization to access one system, account, or category of data does not necessarily authorize access to another. Conversely, an employee’s unauthorized conduct outside the company’s instructions should not automatically be attributed to an executive.

What Constitutional Protections Apply?

Digital investigations implicate the rights to privacy, due process, and protection against unreasonable searches and seizures. The Supreme Court has recognized privacy as an independently protected constitutional right, including in relation to personal information and electronic communications. See [Disini, Jr. v. Secretary of Justice, G.R. No. 203335, February 18, 2014](#J2.20).

The defense should examine whether investigators obtained data through a lawful warrant, subpoena, consent, or other recognized authority. It should also determine whether the process used was appropriate for the type of information obtained.

Content data, traffic data, subscriber information, stored files, and data contained in a device may be subject to different legal requirements. A demand for information that does not particularly describe the material sought or its relevance may be challenged as constitutionally defective or procedurally irregular.

How Do Cybercrime Warrants Affect the Defense?

The Supreme Court’s [Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, 2018](#J1.15) provide specialized procedures for the preservation, disclosure, interception, search, seizure, and examination of computer data.

The Rules recognize warrants specifically adapted to electronic evidence, including a warrant to disclose computer data, a warrant to intercept computer data, a warrant to search, seize, and examine computer data, and a warrant to examine computer data.

A defense review should ask whether:

  • the proper type of warrant was obtained;
  • the issuing court had authority to issue it;
  • the warrant particularly described the data, device, account, or location involved;
  • the search remained within the warrant’s scope;
  • the data was preserved without alteration;
  • the officers documented the seizure and examination; and
  • the evidence can be authenticated in court.

For persons or service providers outside the Philippines, service of warrants and other court processes must be coursed through the Department of Justice Office of Cybercrime in accordance with relevant international instruments or agreements. See [Rules on Cybercrime Warrants, A.M. No. 17-11-03-SC, 2018](#J1.15).

Can a Motion to Quash Be Used?

Once an information has been filed, a motion to quash may be available when the information fails to charge an offense, does not allege essential elements, or is otherwise defective under the Rules of Criminal Procedure.

The motion should not merely deny the allegations. It should identify the missing element or legally incurable defect on the face of the information. For example, the defense may argue that the information does not allege the executive’s specific participation, does not identify the computer data involved, or fails to state facts showing that the access was without right.

Where a defect may be cured by amendment, the court may allow the prosecution to amend the information rather than immediately dismissing the case. The Supreme Court explained this principle in [Dio v. People of the Philippines, G.R. No. 208146, 2016](#J3.2).

A motion to quash should therefore be carefully distinguished from an evidentiary defense. If the information sufficiently alleges an offense but the prosecution’s evidence is weak, the issue may be better raised through trial, demurrer to evidence, or appeal rather than through a motion to quash.

What If the Complaint Is Based on Digital Communications?

Digital messages, emails, system logs, screenshots, and social-media communications must be examined for authenticity, completeness, context, and lawful acquisition. A screenshot alone may not establish who created the message, who controlled the account, whether the message was altered, or whether the account was compromised.

The defense should seek the original electronic data, available metadata, server records, device images, authentication records, and a clear chain of custody. It should also determine whether the complainant preserved the evidence before filing the complaint.

Where the complaint relies on allegedly intercepted communications, the defense should examine whether the recording was made by a private person, a law-enforcement officer, or an undercover investigator, and whether a statutory exception applies.

When Are Undercover Recordings Permitted?

Special statutes provide limited exceptions for undercover law-enforcement recordings in investigations involving online sexual exploitation of children and trafficking in persons. Under R.A. No. 11930, an undercover law-enforcement officer who records communications with a person reasonably believed to have committed, be committing, or be about to commit a covered offense is not treated as having committed illegal wiretapping under R.A. No. 4200.

Comparable protection applies in investigations under the Expanded Anti-Trafficking in Persons Act. See [R.A. No. 11862](#L2.19). These exceptions are offense-specific and should not be treated as a general license to record private communications in unrelated disputes.

The defense should therefore ask whether the recording falls within the precise statutory exception, whether the investigator acted within the investigation, and whether the recording was preserved and authenticated. A recording outside the statutory conditions may still be challenged under the Anti-Wiretapping Law, constitutional privacy protections, or evidentiary rules.

How Should Executives Respond Before Filing a Criminal Case?

Executives should avoid destroying, modifying, forwarding, or selectively deleting potentially relevant data. Automatic deletion policies should be suspended where appropriate, and a litigation or investigation hold should be issued.

The company should conduct a legally supervised internal review that preserves original data while maintaining confidentiality. The review should distinguish facts established by system records from assumptions based on employee statements or media reports.

The executive should also avoid informal explanations that may later be presented as admissions. Communications with counsel should be separated from ordinary business communications, and access to privileged material should be restricted.

What Defenses May Be Raised During Investigation?

The defense may submit a position paper, counter-affidavit, affidavits of witnesses, technical reports, and documentary evidence during preliminary investigation. The submission should focus on the absence of probable cause and should address the allegations individually.

A useful structure is:

  • the executive had no access, capability, or involvement in the alleged act;
  • the activity was authorized and performed for a legitimate business or security purpose;
  • the executive did not know of the alleged unauthorized conduct;
  • the executive exercised reasonable supervision and maintained appropriate controls;
  • the alleged data was not shown to have been accessed, altered, or transferred; and
  • the digital evidence was unlawfully obtained, incomplete, unreliable, or improperly attributed.

Technical conclusions should be supported by qualified cybersecurity professionals. The report should identify the source of each conclusion, the methodology used, the limitations of the examination, and whether the original data was preserved.

Can a Corporate Executive Seek Dismissal After Investigation?

If the prosecutor finds no probable cause, the complaint may be dismissed at the preliminary-investigation stage. If an information has already been filed, the accused may pursue available remedies under the Rules of Criminal Procedure, including a motion to quash where legally appropriate.

A denial of a motion to quash is generally interlocutory and ordinarily cannot be reviewed immediately through certiorari. The general rule is to proceed to trial and raise the alleged error on appeal, unless exceptional circumstances show grave abuse of discretion. See [Tulfo v. People of the Philippines, G.R. No. 237620, 2021](#J5.3).

The defense should therefore avoid using extraordinary remedies merely to correct an ordinary adverse ruling. Certiorari is not a substitute for appeal and requires a clear showing of jurisdictional abuse, not simply disagreement with the court’s conclusion.

What Corporate Governance Measures Reduce Executive Exposure?

Companies should maintain written controls that show which officers may authorize access to systems, conduct investigations, approve security testing, request data, and engage external cybersecurity providers.

At a minimum, companies should maintain:

  • documented access privileges and approval matrices;
  • periodic review of administrator accounts;
  • incident-response and evidence-preservation procedures;
  • vendor agreements defining permitted testing and data handling;
  • training on privacy, cybersecurity, and reporting duties; and
  • board-level oversight supported by written records.

These controls do not guarantee immunity. They may, however, help establish that the executive exercised reasonable care, that the company had a lawful purpose, and that an employee acted outside the authority granted to him or her.

Practical Defense Checklist

An executive confronted with a cybercrime complaint should immediately preserve relevant evidence, identify the precise offense alleged, retain counsel with criminal and cybersecurity experience, and prevent unauthorized internal access to potentially relevant systems.

The defense should then map the alleged conduct against access logs, authorization records, employee roles, device ownership, data classifications, communications, and the legal process used to obtain the evidence. It should also determine whether the complainant can establish the identity of the actor and the executive’s specific connection to the alleged act.

Where the complaint concerns surveillance or hacking, the most important distinction is often whether the conduct was authorized security work, an employee’s unauthorized act, or an executive’s knowing direction of unlawful activity. The available remedy will depend on that factual classification.

Conclusion

Corporate executives are not criminally liable merely because they hold office or supervise a company. A cybercrime complaint must connect the executive to a specific unlawful act and establish the required intent, participation, authorization, knowledge, or gross negligence.

The strongest defense combines an element-by-element legal analysis with careful examination of digital evidence, warrant compliance, attribution, and corporate authorization. Executives should preserve evidence, avoid informal admissions, obtain early legal and technical assistance, and raise procedural objections at the stage where they are legally available.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH