Nearly three decades have passed since Malaysia established MyCERT in 1997 to build its national cyber emergency response capabilities, yet the threat landscape has transformed beyond the volume of attacks. The defining change is velocity—the sheer speed at which malicious actors can now strike, turbocharged by artificial intelligence capabilities that fundamentally reshape how cybersecurity threats operate. This evolution demands a corresponding shift in how Malaysian organisations conceive of and resource their defensive posture, moving away from optional supplementary measures toward foundational business strategy.
Raja Azrina Raja Othman, Chief Information Security Officer at Telekom Malaysia and a founding member of MyCERT, underscores the profound structural difference between cyber risks three decades ago and today's environment. In the 1990s, threats remained largely isolated to specific systems and contained networks with limited interconnection. Contemporary reality presents an entirely different challenge: nearly all business operations now depend on digital platforms that form deeply integrated ecosystems spanning banking, government administration, corporate functions and national critical infrastructure. When a cyberattack succeeds in this interconnected environment, the consequences cascade far beyond technical downtime, potentially compromising financial systems, customer personal information, operational continuity and—critically for public trust—service delivery that citizens and businesses depend upon daily.
The acceleration of threat speed represents perhaps the most disruptive change in the cybersecurity landscape. Artificial intelligence enables attackers to identify system vulnerabilities with unprecedented efficiency, generate convincing phishing communications that bypass traditional awareness training, and execute sophisticated multi-stage attacks in timeframes that human-centred defence teams cannot match. This asymmetry between attacker speed and defender capacity means organisations relying on manual security processes face mounting disadvantage. The traditional model of human-supervised, reactive incident response proves increasingly inadequate when adversaries weaponise machine learning to compress attack cycles from weeks into hours or minutes.
Organisational leadership frequently underestimates this transformation, continuing to treat cybersecurity as peripheral risk management rather than essential operational infrastructure. This misconception stems partly from historical precedent—when systems were less integrated and attacks more limited in scope, cybersecurity functioned as a specialised department's concern. Contemporary threats demand fundamentally different executive orientation. Raja Azrina articulates this reframing as a business continuity question: if attackers compromise core systems, can the organisation maintain operations? Will customers retain confidence? Can essential services continue reaching the public? These questions redefine cybersecurity from technical problem to existential business risk requiring board-level governance and resource allocation.
A critical vulnerability in many organisations lies at the intersection of technology planning and security strategy. When information technology departments design infrastructure and application architectures without systematic security integration, they inadvertently create expanded attack surfaces and compounding vulnerabilities. This misalignment stems partly from siloed organisational structures where security teams operate independently from infrastructure teams, resulting in systems deployed with security retrofitted rather than architected from inception. Remedying this structural problem requires deliberate governance changes positioning security decision-makers within technology planning processes, not relegated to post-implementation review.
Raja Azrina emphasises that sophisticated cybersecurity investment requires systematic risk prioritisation rather than uniform spending across all potential threats. Organisations should apply structured risk frameworks identifying which threats pose the greatest business impact, then concentrate resources accordingly. This approach acknowledges a difficult truth: no finite investment completely eliminates breach probability. Even well-resourced, mature organisations must operate under assumption that breaches will eventually occur. The distinction between organisations that merely survive compromises and those that contain damage lies in detection speed, response capability and remediation execution. Organisations requiring crisis mobilisation to respond to breaches have already failed—effective security postures operate with pre-positioned expertise and predetermined escalation procedures enabling rapid activation.
Telekom Malaysia's position as both a cybersecurity service provider and critical infrastructure operator creates particular responsibility. The company's operational teams continuously monitor vast, complex digital environments supporting millions of Malaysian users across networks, cloud services, data centres and applications. This experience translates into sophisticated threat intelligence about emerging attack patterns, vulnerability exploitation techniques and attacker tactics evolving across Malaysian telecommunications and government sectors. TM's in-house specialisation spans threat detection and monitoring, incident response orchestration and digital forensics capabilities—deep expertise developed through sustained operational necessity rather than theoretical study.
Effective cybersecurity defence requires layered protection operating simultaneously across network, infrastructure and application layers. Single-layer approaches invariably fail because attackers routinely bypass perimeter defences, necessitating internal detection capability. Network monitoring alone misses application-layer attacks; application security without infrastructure visibility fails to prevent lateral movement following initial compromise. This multi-layered architecture demands coordinated expertise and tooling—security monitoring disconnected from threat response creates false confidence because detection without remediation merely documents attacks while systems remain compromised.
Recognising these operational requirements, TM developed the TM Cyber Defence Centre (TM CYDEC), implementing what the company describes as a "Cyber Fusion" approach enabling comprehensive monitoring across network, infrastructure and application security domains for both industry and government clients. This consolidation addresses the fragmentation that characterises many organisations' security operations, where different monitoring tools generate alerts disconnected from coordinated response capability. The centre also maintains an AI security framework specifically designed to govern secure artificial intelligence deployment—acknowledging that AI tools themselves introduce security risks requiring deliberate oversight.
The fundamental question organisations now confront is no longer whether to adopt artificial intelligence, but how to integrate AI capabilities while maintaining customer trust and public confidence in security posture. This reframing reflects recognition that technology adoption decisions inevitably involve security trade-offs; organisations cannot simply deploy powerful tools without comprehending attendant risks. Malaysia's evolution from establishing MyCERT in 1997 to confronting AI-accelerated threats in 2024 demonstrates how cybersecurity priorities must evolve continuously. The nation's critical infrastructure—telecommunications networks that enable digital commerce, government systems delivering citizen services, financial networks processing transactions—depends entirely on security strategies advancing as rapidly as the threats they defend against. This requirement elevates cybersecurity from technical specialisation to strategic national priority requiring sustained leadership attention and resource commitment.
