Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      CodeSOD: A Unique Way to Primary Key

      July 22, 2025

      BrowserStack launches Figma plugin for detecting accessibility issues in design phase

      July 22, 2025

      Parasoft brings agentic AI to service virtualization in latest release

      July 22, 2025

      Node.js vs. Python for Backend: 7 Reasons C-Level Leaders Choose Node.js Talent

      July 21, 2025

      The best CRM software with email marketing in 2025: Expert tested and reviewed

      July 22, 2025

      This multi-port car charger can power 4 gadgets at once – and it’s surprisingly cheap

      July 22, 2025

      I’m a wearables editor and here are the 7 Pixel Watch 4 rumors I’m most curious about

      July 22, 2025

      8 ways I quickly leveled up my Linux skills – and you can too

      July 22, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025
      Recent

      The Intersection of Agile and Accessibility – A Series on Designing for Everyone

      July 22, 2025

      Zero Trust & Cybersecurity Mesh: Your Org’s Survival Guide

      July 22, 2025

      Execute Ping Commands and Get Back Structured Data in PHP

      July 22, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025
      Recent

      A Tomb Raider composer has been jailed — His legacy overshadowed by $75k+ in loan fraud

      July 22, 2025

      “I don’t think I changed his mind” — NVIDIA CEO comments on H20 AI GPU sales resuming in China following a meeting with President Trump

      July 22, 2025

      Galaxy Z Fold 7 review: Six years later — Samsung finally cracks the foldable code

      July 22, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Malaysia Dodged a Bullet in 2024. But Are We Ready for the Next One?

    Malaysia Dodged a Bullet in 2024. But Are We Ready for the Next One?

    April 29, 2025

    Malaysia Cybersecurity

    By Salleh Kodri, SE Regional Manager, Cyble

    2024 wasn’t just another year in Malaysia’s digital journey — it was a wake-up call.

    For those of us who’ve spent decades in the trenches of cybersecurity, watching logs, tracing threats, and hardening infrastructure, the wave of cyberattacks that hit our country this past year wasn’t surprising. But the scale, the coordination, and the economic fallout? That was something else entirely.

    Let me break down what happened — not just the headlines, but what it means for our economy, and why Malaysia needs to stop treating cybersecurity as a footnote and start treating it like national infrastructure.

    The Breach That Broke Our Complacency

    By the time we hit Q3 in 2024, over 1,500 cyberattacks had been recorded against government ministries and critical infrastructure systems. These weren’t amateur phishing attempts. They were sustained, sophisticated, and clearly state-backed or state-level in complexity. A few key ministries went dark for hours. One of our public healthcare systems experienced temporary data corruption. And a utilities provider had to isolate its control systems for 36 hours to avoid a complete system compromise.

    And here’s the thing: not all of it made the news.

    Behind closed doors, systems were patched, teams scrambled, and boards panicked. The cost wasn’t just digital — it was economic.

    Cybersecurity in Malaysia
    Source: Freepik

    Counting the Economic Damage

    You might think, “It’s just data.” But cyberattacks bleed real money. According to IBM’s 2024 data breach report, the average cost of a breach in ASEAN rose to $3.23 million, with the financial services sector averaging over $5.57 million per incident. Malaysia wasn’t spared. Several major Malaysian firms — including one logistics giant and a digital bank — quietly shelled out millions to contain the damage, restore systems, and placate regulators and customers.

    Here’s where it hits the broader economy:

    • Foreign investors began questioning the resilience of our digital infrastructure.
    • SMEs, which make up over 97% of our businesses, lacked cyber-readiness and saw disrupted operations and lost trust.
    • Public trust in digital government services took a hit, just when we were trying to push digital ID and e-payments deeper into daily life.

    A senior official in one ministry told me bluntly: “We thought we had five more years to prepare. We didn’t.”

    The RM60 Million Band-Aid

    To its credit, the government responded. Budget 2024 allocated RM60 million to strengthen cyberattack preparedness, develop local cybersecurity testing frameworks, and support 5G tech security.

    It’s a start — but let’s be clear. RM60 million doesn’t stretch far in cyber defense. That’s maybe a dozen enterprise-scale security upgrades or a few hundred well-trained specialists. For comparison, Singapore’s Cyber Security Agency has had an annual budget exceeding SGD 100 million since 2019. That’s the kind of investment we’re up against regionally.

    A Law Long Overdue

    What we really needed — and finally got — was the National Cyber Security Bill, passed in March 2024. It was years in the making and gives real legal backbone to our cyber defense efforts.

    Now, Critical National Information Infrastructure (CNII) operators are legally bound to report incidents, meet compliance standards, and undergo regular risk assessments. It’s no longer voluntary — and that’s a good thing.

    But enforcement will be key. We’ve seen laws on paper without bite before.

    The Talent Crisis Nobody’s Talking About Enough in Malaysia

    Let’s talk about the people behind the screens.

    Malaysia currently has 15,000 cybersecurity professionals, and we need at least 27,000 just to meet current demand. That’s a gap of 12,000 skilled individuals. And the attacks are only going to get more complex.

    This talent shortage is killing us.

    Many of our best minds are being poached by MNCs or lured abroad. We’ve got polytechnic grads doing L1 security ops when they could be trained into penetration testers, incident responders, and SOC analysts.

    If we don’t start investing in people as much as in tech, we’re going to lose this fight before it really starts.

    A Nation’s Resilience Is Now Digital

    Cybersecurity isn’t a niche IT problem anymore. It’s national security. It’s economic security. And it’s about trust.

    In 2024, Malaysians saw what happens when digital systems fail: queues at clinics, bank transfers on hold, GPS routes offline, and even brief water supply disruptions in a northern state. These aren’t “tech issues.” These are real-life disruptions to real people.

    And the knock-on effect? Delayed investments, rattled supply chains, and a hit to our digital economy ambitions.

    If we’re serious about being a Southeast Asian digital hub, we need to act like it, and that means building cybersecurity into every layer of our economy.

    Where Do We Go From Here?

    Here’s what needs to happen in 2025 if we want to bounce back stronger:

    1. Double our cyber workforce training pipeline – fast-track programs, sponsor certifications, retrain IT pros.
    2. Mandate cyber-readiness for all critical infrastructure operators, not just those in government.
    3. Establish a national bug bounty program – crowdsource protection with white-hat hackers.
    4. Support SMEs with affordable, shared cybersecurity services – they’re our most vulnerable segment.
    5. Treat cyber risk the same as financial risk – include it in board meetings, audits, and national economic planning.

    Final Word

    We dodged a bullet in 2024. But bullets keep coming.

    Malaysia has talent, drive, and potential. But in the cyber world, potential isn’t enough. Preparedness is everything.

    Let’s make 2025 the year we stop reacting and start leading.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleSecurity Isn’t a Tool—It’s a Mindset: Kapil Yewale’s Vision for Resilient Cyber Systems
    Next Article Malware Attack Targets World Uyghur Congress Leaders via Trojanized UyghurEdit++ Tool

    Related Posts

    Development

    GPT-5 is Coming: Revolutionizing Software Testing

    July 22, 2025
    Development

    Win the Accessibility Game: Combining AI with Human Judgment

    July 22, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    A beginner’s guide to Retrieval-Augmented Generation (RAG)

    Development

    FaFa Runner is a RPG game with a seamless gaming experience

    Linux

    CVE-2025-3524 – CVE-2022-36363: Apache Struts Command Injection

    Common Vulnerabilities and Exposures (CVEs)

    chess22k is a chess engine written in Java

    Linux

    Highlights

    CVE-2025-48139 – StyleAI Missing Authorization Vulnerability

    June 9, 2025

    CVE ID : CVE-2025-48139

    Published : June 9, 2025, 4:15 p.m. | 25 minutes ago

    Description : Missing Authorization vulnerability in relentlo StyleAI allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects StyleAI: from n/a through 1.0.4.

    Severity: 6.5 | MEDIUM

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Devman Claims Cyberattack on Thailand Ministry of Labour, Demands $15M Ransom

    July 18, 2025

    CVE-2023-53146 – “Linux Media DW2102 Null Pointer Dereference Vulnerability”

    May 14, 2025

    Microsoft subtly warns Windows 10 users to upgrade to Windows 11 in a new ad

    June 6, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.