MALAYSIA'S position at the heart of Asean's manufacturing, trade and digital economy brings significant opportunity. It also means that a cyber incident affecting a Malaysian manufacturer, logistics provider or digital platform can have consequences extending well beyond the organisation and even the country, in which it begins.
This interconnectedness is changing the nature of cyber risk. Organisations are no longer securing isolated networks. They are part of complex ecosystems spanning suppliers, cloud services, operational technology, digital platforms and partners across multiple markets. Attackers recognise these dependencies and increasingly look for the weakest point through which they can reach a larger network of organisations.
For Malaysia, cybersecurity is therefore not only a matter of protecting individual businesses. It is becoming fundamental to supply-chain resilience, investor confidence and the country's long-term competitiveness.
Malaysia is well positioned to lead regional cyber resilience
Malaysia has a particularly important role within Asean. The country accounts for approximately 13 per cent of global semiconductor assembly, testing and packaging, while electrical and electronics products contribute more than 40 per cent of national exports. Its manufacturing clusters, ports, logistics networks and extensive commercial links make it an important part of regional and global supply chains.
These strengths also increase its exposure. A cyberattack that interrupts production at a Malaysian factory, compromises a logistics operator or reaches operational technology through a supplier can create disruption across multiple businesses and markets.
However, Malaysia's position also gives it an opportunity to influence how cybersecurity is approached across Asean. Its mature industrial ecosystem, developing regulatory environment and experience coordinating regional initiatives provide a strong base from which to develop and scale practical approaches to cross-border cyber resilience.
Malaysia has already taken important steps. The Cyber Security Act 2024 has strengthened the governance and protection of National Critical Information Infrastructure (NCII), establishing clearer responsibilities for NCII sector leads and entities and providing a framework for managing cybersecurity threats and incidents affecting critical infrastructure. The Malaysia Cyber Security Strategy 2025–2030 provides a broader national direction for strengthening cybersecurity resilience across government, business and the wider community, including in response to emerging technologies and threats while the Cybercrimes Bill 2026, passed by Parliament in July 2026, seeks to address emerging offences and strengthen Malaysia's ability to respond to certain crimes with a cross-border dimension.
Malaysia also played an important role in developing the Asean Cybersecurity Cooperation Strategy 2026-2030. The next challenge is to translate this policy momentum into practical and measurable outcomes.
Moving from defence to disruption
Organisations must continue strengthening their own security. But cybercrime cannot be addressed by asking every business to defend itself independently. Criminal groups operate across borders, reuse infrastructure and monetise stolen information through connected networks of brokers, marketplaces, mule accounts and other intermediaries.
The next phase of Asean's cybersecurity effort must therefore focus not only on preventing attacks, but also on disrupting the systems that make cybercrime scalable and profitable.
Malaysia can help advance this effort in three areas.
First, Asean needs faster and more operational intelligence sharing. Governments, national computer emergency response teams, law-enforcement agencies and private-sector security providers often see different parts of the same criminal operation. Connecting these insights can help identify shared infrastructure, active campaigns and relationships between threat actors more quickly.
This requires trusted mechanisms for exchanging actionable intelligence, with clear rules governing how information is shared and used. The objective should be to shorten the time between identifying malicious activity and taking coordinated action against it.
Second, cross-border incident response must operate closer to the speed of cybercrime. An attack may be launched from one jurisdiction, use infrastructure in another and target organisations across several markets. Regional cooperation must support rapid coordination, evidence preservation and the disruption of malicious infrastructure before criminals can simply move to another provider or location.
The Asean Regional CERT and the Asean Cybersecurity Cooperation Strategy provide a foundation. The measure of success, however, will be how effectively these mechanisms support faster action when incidents occur.
Third, cybersecurity must become a practical competitive advantage for SMEs. Smaller businesses form the majority of Malaysia's enterprise base and are deeply integrated into regional supply chains. Many face limited budgets, skills shortages and increasingly complex security environments, making it difficult to manage a growing number of disconnected tools.
Malaysia can help by combining practical support with commercial incentives. Cyber maturity can increasingly be reflected in procurement requirements, access to financing, cyber insurance and participation in strategic supply chains. This would make stronger security both achievable and commercially valuable, rather than treating it only as a compliance obligation.
Turning regional strategy into measurable action
For Malaysian boards, cyber risk is now inseparable from operational resilience, reputation and growth. Businesses must understand their most critical assets, reduce unnecessary complexity and ensure they can detect, contain and recover from incidents quickly.
At the regional level, progress should be measured through tangible outcomes: faster intelligence exchange, shorter disruption times, stronger coordination during major incidents and improved resilience across shared supply chains.
Malaysia has the industrial depth, policy momentum and regional relationships to help drive this next phase. By aligning its domestic reforms with practical cross-border cooperation, it can protect its own digital economy while helping Asean make cybercrime more difficult, more costly and less profitable.
That would represent a meaningful shift, from managing cyber risk one organisation at a time to collectively disrupting the criminal ecosystem behind it.
Kevin Wong is the Country Manager at Fortinet Malaysia.
The views expressed in this article are the author's own and do not necessarily reflect those of Sinar Daily.
(0)Comments