Search
Close this search box.

Cyber Threats Evolve As Fast As AI, Making Cybersecurity A Strategic Priority

Kuala lumpur: In the nearly 30 years since Malaysia began developing its national cyber emergency response capabilities with the establishment of MyCERT, the most significant change has been not merely the growing volume of cyber threats, but the speed at which attacks can occur, now further accelerated by artificial intelligence (AI).

According to BERNAMA News Agency, Telekom Malaysia (TM) Chief Information Security Officer Raja Azrina Raja Othman, who was among the co-founders of MyCERT in 1997, said cyber threats three decades ago were largely confined to specific systems and networks. Today, however, almost all services operate digitally and are interconnected, ranging from banking and government services to corporate operations and national critical infrastructure.

Raja Azrina emphasized that when a cyberattack occurs, the impact extends beyond mere system downtime. It can compromise operations, finances, customer data, and reputation, as well as disrupt services relied upon by the public. She highlighted these concerns during a special interview held in conjunction with the recent launch of TM's 80th-anniversary celebrations, officiated by Prime Minister Datuk Seri Anwar Ibrahim.

She added that another major shift was the sheer speed at which cyberattacks could now be launched, with AI further accelerating the process. With AI, cyber attackers can more easily identify vulnerabilities, craft more convincing phishing campaigns, and launch attacks at a much faster pace. Cyber attackers today operate rapidly with the aid of AI, leading to the necessity for cyber defense strategies to evolve beyond manual processes.

The real challenge, according to Raja Azrina, lies in increasingly complex information infrastructures driven by extensive application integration. A lack of alignment between IT planning and information security could increase an organization's exposure to cyber threats. Despite this, she noted that some organizations still view cybersecurity as an optional measure rather than an essential component of their operations.

In reality, cybersecurity is a matter of risk management and business continuity. If core systems are compromised, can the organization continue to operate? Can service delivery to customers be maintained? Will customers retain confidence in the business? These are the critical questions organizations must address, she stated.

Responsibility for cybersecurity must start with leadership and be embedded within organizational governance. Cybersecurity investments should be guided by a risk-based approach, with organizations prioritizing risks according to their potential impact on business operations. Even with cybersecurity investments, the assumption that attacks can be entirely prevented is a misconception. Instead, preparedness for potential incidents is crucial.

Raja Azrina emphasized that truly prepared organizations are distinguished by their ability to detect threats early, respond swiftly, and remediate issues without causing prolonged disruption to operations. In cybersecurity, proactive measures are necessary, and waiting for a crisis to strike before taking action is not an option.

Cybersecurity is not a new field for TM, Raja Azrina noted, as it has been part of the company's responsibility to manage and protect the nation's digital infrastructure. TM's cybersecurity capabilities are built on years of experience in protecting operations and supporting the digital needs of enterprises and the government, covering networks, cloud services, data centers, and applications.

TM also has local cybersecurity experts specializing in various areas, including threat detection and monitoring, incident response, and digital forensics. Cybersecurity monitoring and controls are required at every level-network, infrastructure, and application-to establish layered protection and enhance detection and response effectiveness.

The question today, according to Raja Azrina, is no longer whether organizations will adopt AI, but whether they can do so securely while maintaining the trust of customers and the public. Security measures must evolve as rapidly as technology, prompting TM to develop the TM Cyber Defence Centre (TM CYDEC).

Through a 'Cyber Fusion' approach, TM CYDEC enables comprehensive monitoring of cybersecurity issues across network, infrastructure, and application security for the industry and government sectors. TM also has an AI security framework to govern AI security. The goal is to enable organizations to continue innovating and leveraging AI with confidence, without compromising security and trust.

Recent News

ADVERTISMENT