Nearly three decades have passed since Malaysia established MyCERT, marking the nation's formal entry into coordinated cyber emergency response. Yet the landscape has transformed so dramatically that the core challenge today bears little resemblance to threats of the 1990s. Raja Azrina Raja Othman, Chief Information Security Officer at Telekom Malaysia and among MyCERT's original architects, contends that the defining shift is not simply the rising volume of attacks, but their accelerating velocity—now turbocharged by artificial intelligence. Speaking during celebrations marking TM's 80th anniversary, officiated by Prime Minister Datuk Seri Anwar Ibrahim, she outlined how the interconnected nature of modern digital infrastructure has created unprecedented exposure for organisations across the region.
When MyCERT was founded in 1997, cyber threats typically targeted isolated systems or contained networks. The attacker's toolkit and targets were correspondingly limited. Today, virtually every service—from banking and government functions to retail operations and essential infrastructure—depends on digitally integrated systems that share data and resources across boundaries. This shift has profound implications for any breach. A successful cyberattack no longer merely causes temporary downtime; it can simultaneously compromise operations, drain finances, expose customer data, damage institutional reputation and cripple public-facing services. For a nation like Malaysia with growing digital payment adoption, e-government initiatives and cloud-based service delivery, the consequences ripple across society within moments.
What distinguishes the current era is the velocity at which attackers operate. Artificial intelligence has fundamentally altered the attack timeline. Rather than months of reconnaissance followed by carefully orchestrated infiltration, AI-powered systems now identify vulnerabilities, generate targeted phishing campaigns and deploy exploits at machine speed. Cyber defenders operating on traditional timelines—requiring human review, approval and manual response—find themselves perpetually behind adversaries who scale attacks instantaneously. This disparity means that organisations relying on legacy defence approaches, however well-resourced, face structural disadvantage.
Raja Azrina emphasises that this technological transformation demands equally fundamental shifts in organisational strategy. Manual cybersecurity processes, however rigorous, cannot match the pace of AI-driven attacks. Yet many Malaysian firms and government agencies continue treating cybersecurity as a peripheral compliance function rather than embedded operational necessity. This attitude persists despite mounting evidence that cyber incidents directly threaten business survival. The critical questions that leadership must confront are unambiguous: if core systems fall to attackers, can operations continue? Can the organisation fulfil obligations to customers and citizens? Will stakeholders retain confidence? These are not hypothetical scenarios but questions Malaysian businesses increasingly face.
The root cause of inadequate cybersecurity readiness often traces to misalignment between information technology planning and security strategy at the governance level. Organisations pursue digital transformation—cloud migration, enterprise application integration, remote working infrastructure—without embedding security architects in these decisions from inception. The resulting complexity creates cascading vulnerabilities. Integration points between systems multiply; data flows through channels no single security team fully understands; legacy protections become obsolete while new vulnerabilities emerge faster than teams can assess them. Without intentional alignment between IT and security leadership reporting to the same strategic objectives, exposure accumulates systematically.
Raja Azrina contends that remedying this requires cybersecurity to become a board-level governance issue, not a technology department concern. Risk management frameworks should guide investment, with organisations prioritising threats according to potential business impact. This shift recognises cybersecurity as fundamentally a continuity problem: an organisation that cannot detect and remediate threats rapidly faces operational paralysis. Yet even well-prepared enterprises must abandon the illusion of perfect prevention. Sophisticated attackers will eventually penetrate even robust defences. The differentiator lies in capability to detect intrusions early, mobilise response teams rapidly and contain damage without prolonged service disruption. This resilience orientation—assuming breach will occur and preparing accordingly—contrasts sharply with older prevent-only strategies.
Telekom Malaysia's position as custodian of Malaysia's telecommunications backbone gives its security expertise particular relevance. For decades, TM has protected its own vast infrastructure while supporting government and enterprise digital requirements across networks, data centres, cloud services and applications. This experience managing complex, mission-critical environments across diverse sectors has informed TM's security architecture. The company maintains specialised teams spanning threat detection, incident response and digital forensics—capabilities typically distributed across several vendors in smaller organisations. Critically, TM's approach enforces layered protection at network, infrastructure and application levels simultaneously, recognising that threats can exploit vulnerabilities at any tier.
This depth of capability informed development of TM Cyber Defence Centre (TM CYDEC), which applies what the company terms a "Cyber Fusion" approach. Rather than fragmented monitoring separated by infrastructure layer, CYDEC provides unified visibility across network, infrastructure and application security domains for both private sector and government clients. The integration allows security analysts to correlate events across layers that attackers routinely exploit—lateral movement through networks toward applications storing sensitive data, for instance. TM has additionally established an AI security framework specifically designed to govern deployment of artificial intelligence tools while preventing AI systems themselves from becoming attack vectors.
For Malaysian organisations contemplating AI adoption, the strategic imperative has reversed. The question is no longer whether to deploy artificial intelligence—competitive and operational pressures make that decision increasingly irreversible—but how to adopt AI securely while maintaining customer and public trust. This demands that security measures evolve at technological pace rather than lagging behind innovation. Traditional procurement cycles, where security is retrofitted after deployment, no longer suffice. Instead, security must be embedded throughout AI systems from development through operation, with continuous monitoring for new attack patterns that emerge as AI capabilities mature. This represents a fundamental restructuring of how Malaysian enterprises approach digital innovation.
Regional implications extend beyond individual organisations to national competitiveness. Countries that successfully embed cybersecurity within digital transformation strategies attract international investment and retain domestic talent in high-value technology roles. Conversely, nations experiencing repeated breaches and unable to assure service continuity see investors migrate to more secure jurisdictions. Malaysia's ambitions as a digital economy hub and regional technology centre therefore depend on visibly strengthening collective cybersecurity posture. Government leadership in mandating security-first digital governance, combined with private sector expertise like TM's demonstrated capabilities, can establish Malaysia as a trusted digital economy—essential for attracting regional headquarters, fintech investment and cross-border digital services.
