WHEN AI ACCELERATES ATTACKS, CAN YOUR DEFENCES KEEP UP?


Raja Azrina says TM’s cybersecurity capabilities have been built through years of experience in protecting our own operations as well as supporting the digital needs of enterprises and government, including networks, cloud, data centres and applications.

NEARLY 30 years after Malaysia began building its national cyber emergency response through the establishment of MyCert, the biggest change in the threat landscape is not the volume of cyberattacks, but how quickly they can now take place.

Artificial intelligence (AI) is accelerating that reality, making it easier for cyber attackers to detect vulnerabilities, create convincing phishing activities and launch attacks with greater speed.

Telekom Malaysia’s (TM) chief information security officer Raja Azrina Raja Othman, a co-founder of MyCert in 1997, says the nature of cyber threats has changed drastically since those early days.

Three decades ago, cyber threats were more likely to target specific systems and networks.

Today, almost every service operates digitally and is interconnected, ranging from banking and government services to corporate operations and critical infrastructure.

Cyber threats today

“When a cyberattack occurs, the impact is no longer simply a system being disrupted.

“It can affect operations, finances, customer data, reputation and even services used by the public,” she explains.

The speed at which attacks could take place has also increased at an alarming pace.

“With AI, cyber attackers can easily identify where an organisation is weakest, produce more convincing phishing activities and launch attacks much faster – sometimes remaining undetected for long periods of time.

“Cyber defence can no longer rely on manual processes alone,” she advises.

For enterprises and the government sector, the challenge is compounded by increasingly complex information infrastructure and the growing number of systems, platform and application integrations.

When IT planning and information security planning do not move in tandem, the risk of exposure to security threats increases. Yet some organisations still regard cybersecurity as an option rather than an essential element.

Raja Azrina argues that this needs to change – and quickly.

“The reality is that cybersecurity risk is a business risk. If a core system is affected, can an organisation continue to operate?

“Can they continue to provide services to customers? And how will it impact confidence in their business?

“These are the questions organisations need to consider. Cyber risk needs to be a top management and boardroom conversation. It involves embedding cybersecurity requirements into organisational governance and not simply remaining an IT checklist,” she says.

Cybersecurity investment, she added, should be guided by a risk-based approach, with spending prioritised to address the risks involved and their potential impact on the organisation’s business.

Incident readiness

Even then, investment does not guarantee an attack will be prevented.

“Even with investments in cybersecurity, we cannot assume that attacks will be stopped. Instead, we need to be prepared that incidents can still occur – sometimes where least expected.

“What differentiates organisations that are truly prepared is how early they can detect a threat, how quickly they can respond and how effectively they can recover to minimise prolonged disruption to operations.

“In cybersecurity, we cannot wait until a crisis occurs before deciding who needs to act,” she warns.

Cybersecurity is not a new area for TM, as Raja Azrina explained that it has long formed part of the company’s responsibility in operating and protecting the nation’s digital infrastructure.

“TM’s cybersecurity capabilities have been built through years of experience in protecting our own operations as well as supporting the digital needs of enterprises and government, including networks, cloud, data centres and applications,” she shares.

The company’s teams constantly monitor security across a broad and complex digital environment.

Its local cybersecurity specialists are also continuously trained in areas including threat detection and monitoring, threat hunting, incident response and digital forensics.

Raja Azrina adds that cybersecurity monitoring and controls need to be applied at every level of the network, infrastructure, systems and applications, creating layered controls while strengthening detection and response effectiveness.

For organisations, the question today is no longer whether they will use AI, but whether they can use it safely while maintaining the trust of customers and the public.

Integrated visibility

The TM Cyber Defence Centre (TM CYDEC) is designed around this need, providing an integrated view of cyber threats across networks, cloud platforms, applications and digital infrastructure.

It aims to help organisations detect threats early, respond

faster and reduce potential disruption to critical operations.

“As organisations adopt AI, they face emerging risks related to data exposure, governance, model integrity and regulatory compliance.

“This makes integrated threat visibility and cyber resilience across digital environments increasingly important,” Raja Azrina says.

Through its Cyber Fusion operating model, TM CYDEC brings together security monitoring and capabilities across connected digital environments, supported by 24/7 threat intelligence.

Correlating security information across diverse platforms and services provides a broader view of potential threat activities, enabling security response teams to assess threats from different contexts.

This empowers more informed decisions, focuses security attention and resources and helps organisations strengthen their ability to detect, respond to and recover from cyber incidents.

Raja Azrina explains the objective is not simply to defend against individual attacks, but to help organisations identify and respond to threats earlier and reduce their impact on business.

“We believe that with the right cybersecurity strategy, a risk-based approach, as well as effective services and technology, we can help organisations detect and respond to cyber threats early and reduce the impact on business.

“Ultimately, we want organisations to be able to continue innovating and harnessing AI with confidence, without compromising security and trust,” she concludes.

To learn more, visit www.tmone.com.my.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Business News

French woes fuel contagion
Private equity rides megatrends
Higher bond yields for longer?
AI borrowers face costly reality
Riding the choppy 4Q waters
Setting the right fitness tone
Time-tested appeal drives luxury watches
A lifeline for TXCD, a risk for Vestland
Private equity’s tougher path to riches
AI boom in question, again

Others Also Read