When Telekom Malaysia's Chief Information Security Officer Raja Azrina Raja Othman helped co-found MyCERT nearly three decades ago, the cybersecurity universe looked fundamentally different. Threats were contained, attacks happened methodically, and response times measured in hours felt urgent. Today, that world has dissolved entirely. Speaking during TM's 80th-anniversary celebrations, Raja Azrina articulated a disquieting reality: artificial intelligence has compressed the timeline for cyber warfare to seconds, fundamentally reshaping how organisations across Malaysia and the region must think about protecting themselves.

The transformation extends far beyond mere speed. In 1997, when MyCERT emerged as Malaysia's digital immune system, cyber threats typically targeted isolated systems and individual networks. A bank's computers might be compromised; an organisation's email server infiltrated. The damage, while serious, remained largely localised. Fast forward to 2024, and the vulnerability surface has exploded exponentially. Every essential service—from banking and government administration to telecommunications, power generation and healthcare—now operates through interconnected digital ecosystems. These systems talk to each other, share data, and depend on one another for functionality. A vulnerability in one thread can unravel the entire tapestry. When a sophisticated cyberattack succeeds today, the consequences cascade across multiple domains simultaneously: operational paralysis, financial haemorrhaging, customer data exposure, reputational destruction, and the erosion of public confidence in critical services.

What truly distinguishes the current era is the role of artificial intelligence as a force multiplier for attackers. Traditional cybercriminals and state-sponsored actors operated within human cognitive and temporal constraints. They had to manually research systems, identify weaknesses, and orchestrate attacks. Now, AI tools compress these steps into fractions of a second. Machine learning algorithms can scan entire digital infrastructures searching for vulnerabilities more comprehensively than any human team. AI can generate thousands of phishing emails tailored to specific targets with convincing social engineering. Attackers can orchestrate coordinated strikes across multiple vectors simultaneously, overwhelming traditional defences built for sequential, human-paced threats. Raja Azrina's observation that "cyber attackers today operate rapidly with the aid of AI" captures an asymmetry that keeps security professionals awake at night: defenders must be right every moment of every day, while attackers need to succeed just once.

This acceleration has rendered manual, process-heavy cybersecurity strategies dangerously obsolete. Many Malaysian organisations, particularly smaller enterprises, still approach cyber defence through periodic security audits, occasional software patches, and hope. Such approaches assume time exists to detect, deliberate, and respond. They assume threats arrive at predictable intervals. Neither assumption holds in an AI-accelerated threat environment. Organisations that maintain purely human-dependent security operations centres will find themselves perpetually one step behind attackers using algorithmic speed. The realisation has forced a strategic reckoning: cybersecurity can no longer be compartmentalised as a technical IT function. It must become woven into boardroom strategy and executive decision-making.

Raja Azrina emphasises that this elevation reflects a fundamental misunderstanding about cybersecurity's business purpose. Many organisations still view it as an insurance policy—an expensive, regulatory requirement to satisfy compliance frameworks but essentially optional. This framing is dangerously backwards. Cybersecurity is, fundamentally, a business continuity question. If adversaries breach your organisation's core systems, can you continue operations? Can you serve customers? Can you retain their trust? Can you generate revenue? For critical infrastructure operators, the stakes climb higher still: a successful attack doesn't merely damage one organisation, it destabilises essential services that millions depend upon. Malaysia's rapidly digitising economy—with increasing reliance on e-commerce, digital banking, and online government services—amplifies these systemic risks. A sophisticated attack on TM's networks, for instance, could reverberate across telecommunications, financial services, and government operations.

Yet implementing robust cybersecurity requires more than purchasing expensive tools and hiring skilled technicians. Raja Azrina underscores that many organisations suffer from misalignment between IT infrastructure planning and information security architecture. A new cloud migration initiative might proceed without adequate security controls. A corporate merger might integrate networks harbouring incompatible security protocols. Legacy systems, chosen for stability and cost-effectiveness, lack modern security features but remain business-critical. These integration failures create security gaps that sophisticated attackers methodically exploit. Fixing them requires organisations to embed security considerations into technology decisions from inception, not retrofit them afterwards.

The governance dimension proves equally critical. Cybersecurity effectiveness depends less on technical sophistication than on whether an organisation treats it as a genuine priority worthy of executive attention and budgetary commitment. When board members view cybersecurity as someone else's responsibility—the IT department's problem—it withers. Conversely, when chief executives and boards understand the existential business risks, they fund adequate defences, enforce security-conscious culture, and make decisions that trade short-term convenience for long-term resilience. Raja Azrina's insistence that "responsibility for cybersecurity must start with leadership" reflects hardened experience: organisations that survived major breaches invariably had executive champions treating security as foundational to strategy.

Critically, even well-resourced organisations cannot achieve invulnerability. This uncomfortable truth requires a psychological shift from "prevent all attacks" to "detect quickly, respond swiftly, minimise damage." Sophisticated adversaries, particularly state-sponsored actors, possess resources and persistence that eventually penetrate most defences. The differentiator between organisations that recover with minimal impact and those that suffer catastrophic disruption lies in their detection and response capabilities. Can security teams recognise compromise within minutes rather than months? Can they contain the spread? Can they restore systems rapidly? Can they prevent the same attack vector from recurring? These capabilities demand investment in skilled personnel, detection tools, and pre-established incident response protocols that organisations practice regularly.

Telekom Malaysia's position as a national telecommunications operator positions it as a guardian of critical digital infrastructure. Through its cybersecurity operations and the recently established TM Cyber Defence Centre (TM CYDEC), the company operates continuously across network, infrastructure, and application layers—the full stack where threats propagate. This layered approach reflects matured understanding: a single-layer defence is inevitably bypassed. Threats detected at the network perimeter might slip through application security. Vulnerabilities in infrastructure oversight might enable lateral movement through supposedly secured systems. Only comprehensive, multi-layered monitoring and defence can substantially reduce breach probability.

As Malaysia accelerates its digital transformation—pushing everything from government services to financial operations to educational delivery into cloud and networked environments—the cybersecurity imperative intensifies. The question Raja Azrina poses to all organisations applies equally to society: not whether AI will transform business and government operations, but whether Malaysia can undertake this transformation securely, maintaining public confidence and trust. This requires sustained commitment to sophisticated cyber defence as a strategic national asset, not merely a cost centre. It demands that organisations, from private enterprises to government agencies, internalise cybersecurity into their operational DNA. And it recognises that in an accelerating threat landscape powered by artificial intelligence, Malaysia's prosperity and stability depend on its ability to defend the digital infrastructure undergirding modern life.