Nearly three decades after Malaysia established its cyber emergency response infrastructure through MyCERT in 1997, the threat landscape has undergone a transformation that extends far beyond simply higher attack volumes. The acceleration of threats themselves—now turbocharged by artificial intelligence—represents the most consequential shift for businesses and government agencies operating across the nation's digital ecosystem. Raja Azrina Raja Othman, who helped found MyCERT and now serves as Telekom Malaysia's Chief Information Security Officer, articulates a sobering reality: the nature and velocity of cyber warfare have fundamentally changed the calculus for national digital defence.

When MyCERT first began operations three decades ago, cyber threats typically targeted isolated systems or specific networks with relatively predictable attack patterns and response windows. Today's environment bears no resemblance to that earlier era. Banking infrastructure, government portals, healthcare systems, corporate networks and the interconnected web of national critical infrastructure have all migrated to digital-first operations that depend on seamless integration across multiple platforms and service providers. This convergence has created unprecedented complexity and, simultaneously, exponentially expanded the attack surface available to threat actors. The consequences of a successful breach now ripple across entire sectors, threatening not just operational continuity but customer confidence, regulatory standing, and ultimately organisational survival.

Artificial intelligence has fundamentally altered the attacker's calculus by compressing the timeline between vulnerability discovery and exploitation. AI systems enable threat actors to identify weaknesses in security architectures with minimal human intervention, generate sophisticated phishing campaigns that defeat traditional email filters through contextual sophistication, and launch coordinated attacks across multiple targets simultaneously. This acceleration poses an existential challenge to conventional cybersecurity approaches that have historically relied on manual detection, human analysis, and sequential response protocols. Organisations that continue to depend solely on manual processes for threat identification and response increasingly find themselves playing defence against an opponent that operates at machine speed, with human analysts perpetually trailing behind the curve.

The structural problem extends beyond technology to organisational culture and governance frameworks. Raja Azrina identifies a persistent disconnect between information technology planning and information security strategy within many Malaysian organisations. Chief information officers frequently develop infrastructure roadmaps without adequate input from security teams, resulting in systems deployed with inherent vulnerabilities that become exponentially more difficult and costly to remediate after implementation. More concerning is the prevalence of organisations that continue viewing cybersecurity as an optional risk mitigation measure rather than as a fundamental business operation, equivalent in importance to financial controls or supply chain management.

This categorisation error stems from a misunderstanding of what cybersecurity actually protects. It is not simply about preventing data breaches or maintaining system uptime, though those remain important. Cybersecurity fundamentally underpins business continuity, customer trust, and operational resilience. When critical systems sustain compromise, organisations confront cascading questions: can operations continue without interrupted service delivery? Will customers retain confidence in a business that failed to protect their data? Can the organisation maintain regulatory compliance and stakeholder trust after a significant incident? These existential questions demand that cybersecurity responsibility cascade from the board level downward through every layer of organisational hierarchy, embedded not as an afterthought but as a governing principle.

Raja Azrina advocates for a risk-based investment approach that prioritises cybersecurity spending according to potential business impact rather than treating all vulnerabilities as equivalent threats. This framework requires organisations to conduct sophisticated threat modelling that evaluates the intersection of attack likelihood, attack sophistication, and potential operational damage. However, even disciplined risk-based prioritisation cannot eliminate the possibility of successful cyber incidents. Sophisticated threat actors with adequate resources and persistence will eventually identify exploitable vulnerabilities, particularly within organisations that lack comprehensive security architectures. The distinction between organisations that suffer catastrophic breaches and those that weather incidents with minimal operational disruption lies not in perfect attack prevention but in detection speed, response readiness, and remediation capability.

Effective cyber defence in the age of AI requires layered protection operating simultaneously across network infrastructure, systems architecture, and application-level security controls. A single security perimeter or centralised monitoring capability proves inadequate because sophisticated attacks frequently bypass traditional network defences and establish persistence within internal systems. Telekom Malaysia has accumulated decades of experience protecting its own vast digital infrastructure and supporting enterprise and government customers across telecommunications networks, cloud computing environments, data centres and complex application ecosystems. This operational experience informs the development of comprehensive monitoring frameworks that maintain continuous vigilance across all defence layers rather than concentrating protective effort at predictable chokepoints.

The technical expertise required for modern cybersecurity extends across specialised domains that few organisations can develop internally. Threat detection and continuous monitoring require specialists who understand attacker methodologies and can recognise anomalous patterns within massive data flows. Incident response demands practitioners who can rapidly contain compromised systems, preserve forensic evidence, and execute remediation procedures under time pressure. Digital forensics capabilities enable organisations to reconstruct attack sequences after breaches occur, supporting both legal proceedings and improvements to future defences. Building and maintaining these specialised functions internally represents substantial financial and organisational investment that many Malaysian companies lack the scale or resources to justify.

Telekom Malaysia has responded to this landscape by establishing the TM Cyber Defence Centre (TM CYDEC), which consolidates comprehensive cybersecurity monitoring and threat response capabilities behind a unified security operations centre approach. The facility operates on a "Cyber Fusion" model that integrates monitoring across network infrastructure, systems security, and application-layer protections, serving both private sector enterprises and government agencies. This integrated approach enables security teams to correlate threat indicators across multiple visibility domains, identifying sophisticated attacks that might escape detection when security functions operate in isolation. Additionally, Telekom Malaysia has developed specific AI security governance frameworks that address the unique risks posed by artificial intelligence systems themselves, recognising that the same technology enabling more powerful cyberattacks also creates new security vulnerabilities within AI-dependent infrastructure.

The strategic question confronting Malaysian organisations today has shifted fundamentally from whether to adopt artificial intelligence to how to adopt AI securely while maintaining stakeholder trust and regulatory compliance. This shift demands that security strategies evolve with the same velocity as underlying technology, requiring continuous reassessment of threats, vigilant monitoring of emerging attack techniques, and sustained investment in security capabilities. For the telecommunications sector specifically, which operates as both essential infrastructure provider and critical national asset, cybersecurity excellence directly translates to national digital resilience. The 30-year evolution from isolated system threats to interconnected infrastructure facing AI-accelerated attacks underscores an inescapable truth: cybersecurity is no longer a technical function but a strategic imperative woven through every layer of national economic and governmental operations.