Cybersecurity & Data Privacy Communications

How Malaysia is regulating the rise in cybersecurity threats

For many businesses around the globe, ‘a matter of when, not if’ is ringing ever truer when it comes to cybersecurity threats. From phishing attacks to ransomware attacks – and even Asia Pacific’s first high profile deepfake financial scam costing HKD 200 million – cybercrime is part and parcel of the digital landscape, seemingly inevitable, and inseparable from today’s digital era. 

There is no doubt that cybercrime is increasing, but this unsavoury trend is having a tangible financial impact on organizations globally, costing a total of USD8 trillion in 2023, equivalent to the third largest GDP in the work behind only the US and China. By 2027, that number is expected to triple to around USD24 trillion according to projections by the FBI and IMF.

Cybercrimes have become a ‘daily nuisance’ for businesses and individuals 

In Malaysia, the situation has only gotten bleaker.

Recent reports show that the Southeast Asian nation was the world’s eighth most breached country in Q3 alone, with nearly half a million leaked accounts from data breaches – a 144% increase from the number leaked in Q2. Moreover, businesses across Malaysia faced 74,000 attacks per day in 2023 alone amounting to 26.85 million for the year. 

For ordinary Malaysians – 76% of whom have faced some form of online or phone scam in their lives – such attacks, high profile or not, have proven to become a ‘daily nuisance’ of sorts. It certainly has not helped that many businesses are currently not mandated by law to communicate data breaches to consumers, which has eroded public trust in existing cybersecurity infrastructure.

Malaysia’s approach

As businesses continue to struggle with cybercrime, the government has followed through on its promise to table the Cyber Security Bill this year – having passed it in late March through the Lower House of Parliament. Prime Minister Anwar Ibrahim has touted the bill as the way forward to strengthen the country’s cybersecurity capabilities. Current provisions aim to strengthen the National Cyber Security Agency and create the National Cyber Security Committee, which will oversee breach notifications for government and private organizations deemed a National Critical Information Infrastructure (NCII), which range from public utility companies to financial institutions. 

Organizations operating in the city-state are legally obliged to notify the Personal Data Protection Commission no later than 3 days from the moment a breach occurs – and communicate them with affected individuals if they are deemed to cause “significant harm”. 

As with matters of enforcement, the success of implementing the Cyber Security Bill – once it’s enacted into law – will heavily depend on the government’s clear communication of standards to NCII organizations. In turn, the latter will have to streamline disclosure mechanisms internally, and relay relevant processes to employees who are involved in the process to avoid confusion and miscommunication.

At the time of writing, Malaysia’s Cyber Security Bill has not specified time-based parameters for organizations to report to the National Cyber Security Committee in the event of a cyber incident. Creating a mechanism that encourages urgency in reporting will help strengthen businesses’ cybersecurity capabilities to protect their reputation and increase consumer trust, which can be achieved through a tailored cybersecurity communications plan.

Additionally, compelling organizations to carry out risk assessments on their cybersecurity capabilities would be a win-win for creating a more secure business environment and enhancing data privacy and protection efforts. The Malaysian government can look to the European Union’s landmark Cyber Resilience Act, which is expected to take effect in late 2025. 

While regulatory frameworks need to be combined with the right technology to address cyber threats, enacting the appropriate laws that prepare organizations for the inevitable serves as a robust starting point in creating a more prosperous and secure business landscape. 

The views expressed in this article are those of the author(s) and not necessarily the views of FTI Consulting, its management, its subsidiaries, its affiliates, or its other professionals.

©2024 FTI Consulting, Inc. All rights reserved. www.fticonsulting.com

Related Articles

Predictions for Cybersecurity in 2024: Communications and Reputational Perspectives

March 7, 2024—What will the cybersecurity space look like in 2024? And what do companies need to do to ensure they are prepared from a...

Cybersecurity in Latin America: Cyber Threats Evolve in a Landscape of Incipient Resilience

January 25, 2024—Organizations in Latin America should not wait for regulators to impose cybersecurity readiness requirements, as prepara...

A Year of Elections in Latin America: Navigating Political Cycles, Seizing Long-term Opportunity

January 23, 2024—Around 4.2 billion people will go to the polls in 2024, in what many are calling the biggest electoral year in history.[...

Global Public Affairs Newswire – 17 May 2024

May 17, 2024—Welcome to the latest edition of FTI Consulting’s fortnightly Global Public Affairs Newswire. In this installment, we ...

FTI Consulting News Bytes – 17 May 2024

May 17, 2024—FTI Consulting News Bytes Glass-half-full UK IPO news was prominent during the early part of this week’s news cycle wi...

ESG+ Newsletter – 16 May 2024

May 16, 2024—This week’s newsletter covers much of the latest regulation on ESG and sustainability across the globe, from efforts t...