FOR Malaysians, the cycle has become exhaustingly predictable. From massive ransomware attacks crippling statutory bodies to recent headlines of employees casually leaking sensitive customer billing details online, the public is caught in a continuous loop of data compromises.
While the nature of these threats varies wildly – ranging from highly sophisticated, artificial intelligence-driven external cyberattacks to rudimentary internal snooping – the corporate response is almost always identical. The public is inevitably met with a standard public relations script: The company assures us it was an “isolated incident”, claims no broader systems were compromised and reiterates that they take data privacy “very seriously”.
However, as these incidents compound, a critical legal and governance question must be asked: How can the public independently verify these claims?
When a breach occurs, how do we know if the data controller truly implemented all necessary and reasonable security measures prior to the failure, or if their architecture was fundamentally inadequate from the start?
This is particularly relevant when examining insider threats.
If a company’s system architecture allows an employee to casually browse a customer’s sensitive billing or identification details without a verified, logged business justification, it points to a systemic failure in basic internal access controls. If an organisation fails to implement fundamental “Zero Trust” protocols internally, it is difficult to trust their capacity to defend against complex, external cyber threats.
Recognising the importance of these risks, the Personal Data Protection Department earlier this year issued guidelines on Data Protection by Design (DPbD) and Data Protection Impact Assessments (DPIA).
These guidelines should not be treated as mere administrative guidance. DPbD encourages organisations to build privacy safeguards into their systems from the outset, rather than addressing weaknesses only after deployment. Where proposed data processing is likely to pose a high risk, the DPIA requires data controllers to identify, assess and reduce those risks before processing begins.
Yet, the persistent pattern of data leaks suggests that much of corporate Malaysia is treating these critical guidelines as mere paperwork exercises to be filed away, rather than architectural mandates to be engineered into their daily operations.
We cannot continue to accept a culture where data security is only prioritised after a crisis has occurred.
Suing a rogue employee or issuing an apology after data has already surfaced online or on the dark web is purely reactive.
To break this loop, regulatory oversight must fundamentally shift. Regulators must move beyond issuing post-incident fines and begin conducting proactive, unannounced audits of corporate access controls.
Data controllers must be compelled to actively demonstrate exactly how data protection principles are hardcoded into their systems.
Until companies are held accountable for their internal architecture before a breach happens, the public will remain vulnerable to the next “isolated incident”.
THULASY SUPPIAH
Kuala Lumpur
The writer is a lawyer focusing on artificial intelligence, data centres and cybersecurity.
Already a subscriber? Log in
Get 20% OFF The Star Digital Access
Cancel anytime. Ad-free. Unlimited access with perks.
