Three decades have passed since Malaysia established MyCERT in 1997, creating the nation's first coordinated cyber emergency response capability. Yet according to senior security officials, the most profound transformation has not been the sheer volume of threats alone, but rather their velocity—a pace now turbocharged by artificial intelligence technology that fundamentally changes how defenders must think about protection.

Raja Azrina Raja Othman, Chief Information Security Officer at Telekom Malaysia and a co-founder of MyCERT, draws a stark contrast between the cyber landscape of the 1990s and today's interconnected digital ecosystem. Early cyberattacks primarily targeted isolated systems and networks, affecting limited operational scope. The strategic threat model was, by modern standards, relatively straightforward. In the present day, virtually every critical function operates through digital infrastructure: banking platforms, government services, corporate networks and essential national infrastructure all depend on systems that are deeply interconnected and mutually dependent. When attackers compromise even a single node in this web, consequences cascade across multiple sectors simultaneously, creating compound risks that earlier security architects never had to contemplate.

The consequences of modern breaches extend far beyond temporary service interruptions. Contemporary attacks threaten operational integrity, financial stability, customer data security and institutional reputation—losses that ripple through ecosystems and erode public confidence. This represents a fundamental shift in what cybersecurity failures mean for organisational viability. A bank losing customer trust through a data breach faces existential questions about competitive survival. A government agency compromised in a similar manner faces legitimacy challenges that extend beyond technical recovery.

Artificial intelligence has become the force multiplier that distinguishes current threats from historical attack patterns. Contemporary attackers leverage AI systems to conduct rapid vulnerability discovery, generate highly convincing phishing communications at scale and orchestrate coordinated strikes at machine speed. Traditional cybersecurity approaches built on manual threat detection and response cycles cannot operate at this pace. The asymmetry has become acute: defenders working through human-managed processes face attackers augmented by algorithms capable of attempting thousands of attack variations simultaneously. Raja Azrina emphasises that contemporary cyber defence must abandon purely manual methodologies in favour of systems that match the speed and scale of AI-enabled threats.

Yet despite this evolving threat landscape, organisational responses remain inconsistent. Many enterprises continue treating cybersecurity as a peripheral compliance requirement rather than a core operational necessity. This gap between threat reality and institutional readiness creates dangerous vulnerability. The critical question each organisation must honestly answer involves business continuity: if attackers successfully compromise core systems, can operations continue? Can service delivery to customers be maintained? Will those customers retain confidence in the organisation after such a breach? These are not abstract security questions—they are fundamental business survival questions that should drive board-level strategic decisions.

Responsibility for addressing these questions cannot rest with technical teams alone. Cybersecurity must become embedded in organisational governance at the leadership level, with executives and board members understanding cyber risk as a business risk requiring active management. This represents a significant cultural shift for many Malaysian organisations accustomed to treating information technology as a cost centre rather than a strategic asset. When leadership genuinely prioritises cybersecurity, investment decisions naturally follow a risk-based framework: organisations identify their most critical systems, assess threats to those systems, quantify potential impact and direct resources accordingly.

Crucially, even well-resourced cybersecurity investments cannot guarantee absolute prevention of attacks. This counterintuitive reality forces organisations to adopt a preparedness rather than prevention mindset. The measure of security maturity becomes not the absence of incidents but rather organisational capability in three critical areas: early threat detection, rapid incident response and swift remediation that minimises operational disruption. Organisations that excel in these capabilities can experience breach incidents while sustaining business operations, customer confidence and stakeholder trust. Those lacking these capabilities face catastrophic consequences from relatively modest attacks.

Telekom Malaysia's experience managing and protecting the nation's digital infrastructure positions it uniquely to understand layered security requirements. The company's local expertise spans threat detection and monitoring, incident response capabilities and digital forensics investigation. This specialised workforce recognises that protection cannot succeed at a single level—comprehensive security requires parallel monitoring and controls across network infrastructure, physical systems and application layers. Each layer provides detection opportunities and response options, creating resilience through redundancy and diversity.

The company recently established TM Cyber Defence Centre (TM CYDEC) to address these integrated security requirements through a comprehensive monitoring approach spanning network, infrastructure and application security across industry and government clients. This institutional response reflects understanding that cybersecurity challenges have transcended technical boundaries to become strategic governance questions affecting national digital resilience.

Raja Azrina frames the contemporary challenge in terms that transcend Malaysian borders. The fundamental question organisations now face is not whether to adopt artificial intelligence—that adoption is inevitable—but whether they can implement AI securely while maintaining stakeholder trust. This question requires security capabilities that evolve as rapidly as technology itself, a demanding standard that forces continuous investment, continuous learning and continuous adaptation. For Malaysia, a nation increasingly dependent on digital infrastructure for economic competitiveness and social cohesion, this security imperative represents both extraordinary challenge and essential prerequisite for sustainable digital transformation.