When Malaysia established MyCERT nearly 30 years ago, cyber threats were largely isolated incidents affecting specific networks and systems. Today, that landscape has transformed so fundamentally that the volume of attacks pales in comparison to their velocity and sophistication. Artificial intelligence has become the accelerant, enabling attackers to identify vulnerabilities, craft convincing phishing campaigns and launch coordinated strikes at speeds that manual defence systems simply cannot match. This acceleration has become the defining challenge for Malaysian organisations as they navigate an increasingly interconnected digital economy where banking systems, government services, corporate networks and critical infrastructure all depend on digital channels.
Raja Azrina Raja Othman, Chief Information Security Officer of Telekom Malaysia and a co-founder of MyCERT in 1997, observes that the fundamental nature of cyber risk has evolved beyond technical considerations. When attackers strike today, the consequences extend far beyond temporary system unavailability. A successful breach can compromise financial systems, expose customer data, damage organisational reputation and cripple essential services that the public depends upon. The interconnected nature of modern digital infrastructure means that a vulnerability in one system can cascade across multiple domains, creating systemic risks that were inconceivable in earlier eras. This reality transforms cybersecurity from a technical department concern into an existential business question.
AI has fundamentally altered the attacker's advantage in several critical ways. Threat actors now use machine learning algorithms to rapidly scan networks for security gaps that humans would take weeks to discover manually. Phishing campaigns have become increasingly personalised and convincing, using AI to analyse communication patterns and craft messages that bypass human scrutiny. Attack frequencies have accelerated to the point where organisations can face multiple sophisticated threats simultaneously, rendering traditional reactive security models obsolete. The implication for Malaysian businesses is stark: cyber defence strategies rooted in manual monitoring and delayed response protocols are no longer viable in an AI-enabled threat landscape.
Raja Azrina identifies a critical disconnect in how many Malaysian organisations approach cybersecurity. While some recognise its importance, others still treat it as an optional expense rather than an integral operational requirement. This misunderstanding stems partly from viewing cybersecurity through a technical lens rather than a business continuity lens. When core systems are compromised, the question becomes not merely whether data has been stolen, but whether the organisation can continue serving customers, maintaining revenue streams and preserving public trust. These are fundamentally business questions, not IT questions, yet many organisations have not elevated cybersecurity to the strategic decision-making level where such implications are properly considered.
The root cause of many organisations' vulnerability lies in the complexity of modern information infrastructures. Systems are deeply integrated across multiple platforms, cloud providers and applications, creating countless potential attack surfaces. When information technology planning proceeds independently from cybersecurity considerations, organisations inadvertently embed vulnerabilities into their architecture. By the time security teams become involved, infrastructure decisions have already been made, making remediation expensive or impossible without complete system redesign. Malaysia's rapid digital transformation, while economically beneficial, has often proceeded without ensuring adequate security architecture, leaving many organisations playing catch-up.
Raja Azrina emphasises that cybersecurity responsibility must originate from organisational leadership and be embedded into governance structures. This represents a significant shift from treating cybersecurity as a technical function isolated in IT departments. When boards and executive management understand cybersecurity as a strategic risk requiring ongoing investment and oversight, organisations fundamentally change how they approach digital operations. Risk-based investment approaches become possible, where organisations prioritise resources toward threats most likely to disrupt critical operations. This governance-level integration also signals to employees, partners and customers that security is non-negotiable rather than aspirational.
A particularly important insight from Raja Azrina is the recognition that no organisation can prevent all cyberattacks entirely. This acceptance of inevitable threats represents mature security thinking that many Malaysian organisations have yet to embrace. Instead of pursuing the impossible goal of perfect prevention, effective organisations focus on three capabilities: early detection of threats before they cause major damage, swift response protocols that contain incidents quickly, and rapid remediation that restores normal operations without prolonged disruption. This resilience-based approach acknowledges that breaches may occur but minimises their impact through preparedness. For Malaysian critical infrastructure operators, government agencies and financial institutions, this shift in thinking could prove transformative.
Telekom Malaysia's own approach to cybersecurity is instructive for the broader Malaysian digital ecosystem. Having managed the nation's telecommunications infrastructure for decades, TM has accumulated extensive experience protecting vast and complex digital environments. The company's security capabilities span networks, cloud services, data centres and applications, with teams continuously monitoring and responding to threats across these domains. TM employs local cybersecurity specialists with deep expertise in threat detection, incident response and digital forensics, ensuring that security capabilities are neither outsourced nor dependent on foreign expertise. This combination of scale, experience and local capability positions TM as a reference point for how Malaysian organisations should approach security infrastructure.
The creation of TM's Cyber Defence Centre represents an institutional response to the challenge of coordinating security across multiple layers. Traditional security approaches often operate in silos, with network security teams, infrastructure teams and application security teams working independently. The centre's "Cyber Fusion" approach breaks down these silos, enabling comprehensive monitoring and response across network, infrastructure and application security domains simultaneously. This layered protection strategy recognises that attackers do not confine themselves to single domains but rather exploit weaknesses across multiple attack surfaces. For Malaysian government and enterprise sectors, access to such comprehensive monitoring capabilities could significantly improve threat detection and response times.
AI security governance itself has become critical as organisations accelerate their adoption of artificial intelligence across operations. The capability to deploy AI securely, while maintaining customer and public trust, requires frameworks and oversight mechanisms that many organisations have not yet developed. TM's development of an AI security framework illustrates how forward-thinking organisations are anticipating this challenge rather than reacting to AI-related breaches after they occur. As Malaysia's digital economy increasingly incorporates AI into banking, healthcare, government services and industrial operations, the security frameworks governing these technologies will become just as important as the technologies themselves.
For Malaysian policymakers, the implications are substantial. The government's digital transformation agenda, from MyDIGITAL initiatives to critical infrastructure digitisation, all depend on foundational cybersecurity capabilities that may not yet be in place across the ecosystem. Regulatory frameworks governing cybersecurity investment and accountability must evolve as rapidly as the threat landscape itself. Small and medium enterprises, which form the backbone of Malaysia's economy, often lack the resources to build sophisticated security infrastructure comparable to TM's capabilities, creating potential systemic vulnerabilities. Supporting SMEs in adopting security best practices and accessing shared security services becomes a matter of national economic resilience.
The broader challenge facing Malaysia is cultural and organisational rather than purely technical. Organisations must fundamentally rethink cybersecurity from an optional add-on to a strategic capability embedded into governance, planning and operations. The three decades since MyCERT's founding demonstrate that cyber threats are not problems technology alone can solve. Rather, they require alignment between leadership commitment, organisational structure, workforce capability and technological investment. Malaysia's trajectory as a regional digital economy depends not merely on how fast organisations adopt new technologies, but on how securely they do so. As AI continues reshaping both capabilities and threats, this balance becomes increasingly critical to sustaining public trust and economic stability.
