`


THERE IS NO GOD EXCEPT ALLAH
read:
MALAYSIA Tanah Tumpah Darahku

LOVE MALAYSIA!!!

 



 

21 JUNE 2026

Thursday, July 31, 2025

Cyber resilience in Malaysia: Why compliance isn’t enough

 misinformation

IN today’s hyperconnected world, compliance is often seen as the gold standard for cybersecurity.

Across Malaysia, financial institutions, critical infrastructure providers, and businesses have made significant strides aligning with frameworks such as Bank Negara Malaysia’s Risk Management in Technology (RMiT) guidelines, the Personal Data Protection Act (PDPA), and various sector-specific regulations.

Yet breaches continue to make headlines, affecting even the most “compliant” organisations. Why?

The reality is compliance is only the starting line, not the finish line. In a rapidly evolving threat landscape, true cyber resilience demands much more.

Compliance alone can’t keep pace with threats

While regulatory frameworks are a crucial foundation, they represent only the minimum baseline.

Threat actors are not bound by minimum standards, they are innovating faster than regulations can evolve. Sophisticated ransomware gangs, state-sponsored groups, and cybercriminal syndicates are constantly refining their tactics.

According to CyberSecurity Malaysia, local organisations faced over 19 million cyber threats in the first half of 2024, resulting in financial losses exceeding RM1.2 bil.

Regional findings from Sophos indicate that 83% of APJ organisations report increased operational complexity due to cybersecurity regulations,  with 36% citing employee stress and burnout as a direct result.

Yet, 56% still recognise that these frameworks improve both cybersecurity and business resilience, highlighting the need to balance compliance with practical, scalable implementation.

Clearly, businesses must go beyond regulatory checklists and adopt proactive, intelligence-driven security measures.

At Sophos, our 2024 Threat Report highlights emerging tactics such as data extortion without encryption, AI-powered phishing campaigns, and the exploitation of zero-day vulnerabilities, all occurring faster than typical regulatory update cycles.

In Malaysia, sectors like education, healthcare, SMEs, and financial services are increasingly targeted by multi-extortion ransomware attacks.

For business leaders, compliance should be seen as a foundation, not a complete strategy. Cyber resilience demands real-time threat monitoring, AI-driven automation for faster incident response, and comprehensive recovery frameworks.

In today’s environment, “checking the box” is no longer enough; security must be responsive, intelligence-led, and fully embedded across operations.

The growing problem of framework fatigue

At the same time, organisations are grappling with an ever-expanding maze of cybersecurity frameworks; international, industry-specific, and national.

This burden is particularly acute for SMEs, which often lack the resources and expertise needed for robust cybersecurity implementation.

This complexity can lead to framework fatigue: confusion, burnout, and decision paralysis that prevent effective action.

While frameworks aim to provide clarity, without the right support, they risk overwhelming the very organisations they are meant to protect.

Malaysia’s evolving regulatory environment holds promise for streamlining this complexity.

However, businesses must be equipped with practical guidance, scalable technologies, and actionable strategies to bridge the gap between compliance and true resilience.

From compliance to resilience: A strategic imperative

It’s no longer enough to ask, “Are we compliant?” Organisations must ask:

  • Are our cybersecurity strategies aligned with real-world threats?
  • Do we have the visibility, control, and speed necessary to detect and respond to incidents?

Cyber resilience must be a board-level priority, recognised as a critical enabler of trust, operational continuity, and competitive advantage.

Organisations that treat cybersecurity as a strategic business imperative today will be the ones that thrive in Malaysia’s increasingly digital economy.

Aaron Bugal is the Field CTO of Sophos.

The views expressed are solely of the author and do not necessarily reflect those of  MMKtT.

- Focus Malaysia.

Of flying passports and counter-settings

 

THE integrity of a nation’s border is fundamental to its sovereignty, security, and reputation. In Malaysia, however, recent revelations have highlighted troubling systemic vulnerabilities within immigration and border enforcement practices particularly through covert and corrupt mechanisms known as “passport terbang” and “counter-setting”.

These practices not only compromise lawful migration processes but also facilitate serious transnational crimes, including human trafficking and the smuggling of migrants.

“Flying passport” (or ‘pasport terbang’ in Malay) refers to the unauthorised practice of submitting a passport to immigration authorities for renewal, visa endorsement, or extension without the physical presence of the passport holder.

This contravenes official procedures which mandate in-person attendance for identity verification, often through biometric means. In many of these cases, passports are collected and transported by intermediaries on behalf of the holder in exchange for illicit fees.

Counter-setting, on the other hand, involves immigration officers at entry or exit points such as Kuala Lumpur International Airport intentionally manning specific counters to facilitate the unlawful passage of foreign nationals without proper documentation or scrutiny.

These activities are typically arranged through clandestine networks and are executed in exchange for bribes.

Though seemingly procedural deviations, both practices signify entrenched corruption within parts of the immigration system, threatening not only Malaysia’s border control efficacy but also the country’s international standing in law enforcement, anti-trafficking efforts, and governance.

A critical enabler of these corrupt practices is the role played by a wide range of intermediaries including employment agents, taxi drivers, freelance “runners”, and even certain members of airport staff.

In trafficking-related cases, passports belonging to victims are often seized by traffickers and handed to these intermediaries, who in turn bribe immigration personnel to process renewals or extensions without the victim’s awareness or consent.

This shadow network enables the formal legalisation of an illegal or exploitative presence, allowing trafficked persons to remain in the country with official documentation while being subjected to labour or sexual exploitation.

Victims are thus rendered invisible to protective institutions, as their legal status on paper conceals the coercion and abuse they endure in practice.

These practices raise pressing legal and policy concerns because they violate several laws such as Section 55E of the Immigration Act 1959/63, which criminalises harbouring or employing undocumented migrants.

It also contravene the Anti-Trafficking in Persons and Anti-Smuggling of Migrants Act 2007, particularly where visa fraud is used to facilitate continued exploitation.

In addition, these practices undermine the standard operating procedures of the Immigration Department which mandate physical presence and biometric identity confirmation, and risk compromising Malaysia’s compliance with international legal instruments, including the UN Convention against Transnational Organised Crime (UNTOC) and the UN Trafficking Protocol.

Moreover, these practices significantly erode public confidence in enforcement agencies, perpetuate a culture of impunity, and hinder the nation’s efforts to combat organised crime and protect vulnerable populations.

To address these challenges, a multi-pronged strategy is required which targets both systemic weaknesses and individual accountability such as mandating biometric and in-person verification for all immigration procedures.

First, strict enforcement of in-person biometric verification for all passport, visa, and permit applications. Digital systems should automatically flag and suspend applications submitted without such verification.

Second, implement real-time surveillance and tamper-proof digital logs. In this instance, it would be useful to install CCTV with live monitoring at immigration counters and visa-processing units.

All entry and visa transactions should be recorded in tamper-proof systems accessible only to authorised personnel, with audit trails built in.

Third, identify, blacklist, and prosecute facilitators and middlemen involved in these activities. In this instance, it is recommended to maintain a registry of blacklisted intermediaries suspected or convicted of engaging in corrupt immigration practices.

Fourth, enforcement action should extend to all parties involved including agents, syndicates, and complicit civilians.

Fifth, enforcement of a system of regular staff rotations across immigration offices and entry points to disrupt entrenched corrupt networks and prevent collusion between officers and external actors.

Sixth, strengthen awareness among foreign nationals who are residing or working in Malaysia.

They should be educated on lawful immigration procedures, the risks of using unauthorised intermediaries, and the legal consequences of engaging in document fraud. Multilingual outreach materials should also be made readily available.

Flying passport and counter-setting are not mere administrative lapses but are manifestations of systemic corruption that threaten the rule of law, embolden transnational crime, and endanger human security.

Malaysia’s commitment to border integrity must be matched by the political will to root out these practices and strengthen the accountability of its immigration enforcement framework.

Just as immigration officers are duty-bound to uphold the law, foreign nationals must also respect and comply with Malaysia’s immigration regulations.

Any attempt to bypass due process whether through bribery, fraud, or intermediary collusion undermines the legitimacy of the nation’s legal system and puts both individuals and the broader public at risk.

Malaysia stands at a critical juncture: ensuring that its borders are not only efficient and accessible but also just, secure, and corruption-free.

Dr Haezreena Begum Abdul Hamid is a Criminologist and Senior Lecturer at the Faculty of Law, University of Malaya.

The views expressed are solely of the author and do not necessarily reflect those of  MMKtT.

- Focus Malaysia.

What’s in a title?

 

WHEN introducing themselves, various people have different ways of disclosing their names, and likewise when registering, or displaying their names such as in business cards.

While conducting training, I would urge participants to use a short name to introduce themselves in front of the class, just like family and friends would call them.

It is unnecessary to give their full name, which can be difficult to remember, along with 30 to 40 other names and new faces.

Unless they have adopted a familiar Western name, most Malaysian Chinese would use their common surname which is easier to remember.

Sometimes, one of them would translate from Chinese and add a mister in front of their surname and I would point out that it is not appropriate.

Occasionally, I may meet someone calling himself a “Datuk” or “Dato” first, but these titles are inconsequential to me. Anyone who is courteous and helpful has my respect, but not those who are arrogant or egoistic. Their title, position, wealth, or intellect has nothing to do with me.

If someone were to introduce himself as a doctor, I would ask if he is a dentist. Those who run their own dental clinics are likely to earn much more than general practitioners in private clinics.

Then there are also those who also call themselves doctors but are not medical practitioners, after being awarded a Doctor of Philosophy (PhD) or another type of doctorate degree.

While a PhD focuses on original research and contributing new knowledge to a field, professional doctorates focus on applying knowledge to professional practice rather than solely on research, such as Doctor of Business Administration (DBA).

In any case, there is a very wide difference in doctorate degrees, within the same country and internationally.

Degrees awarded by top ranked universities, be they bachelor’s, master’s or doctoral, are the most prestigious, recognised and door opener for the recipients.

At the other end of the scale are universities, mainly in developing countries, that are more like degree mills.

In 2016, the Higher Education Minister Datuk Seri Idris Jusoh said his ministry is committed to its aim of producing 60,000 PhD degree holders by 2023.

In January 2022, Bernama reported that Prof Datuk Dr Raduan Che Rose, president and chief executive officer of the National Council of Professors commented that it was normal for Universiti Putra Malaysia (UPM) to produce 400 PhD graduates each year.

He added that UPM produced 457 PhD graduates in 2021, Universiti Malaya (450), Universiti Kebangsaan Malaysia (516), Universiti Teknologi Malaysia (568) and Universiti Sains Malaysia (431). In 2024, Universiti Malaya churned out 599 individuals with doctoral degrees.

Way back in 2004, a year after he stepped down as prime minister, Tun Dr Mahathir Mohamad commented, “Before, if you threw a stone you would hit one Datuk. Now, you throw a stone, you hit two Datuks!”

Can this statement apply to those with PhDs today? Certainly, if you include those awarded or bought from dubious universities and bodies.

Not only that, some of them with questionable PhDs had the audacity to identify themselves as Prof Dr and then followed by their names.

Those who are good talkers may be able to get away initially but will be exposed by their inability to express their thoughts in writing.

The true worth of anyone with or without a doctoral degree is to write on what is currently happening or developing and have them published for public scrutiny.

If they cannot do that, whatever title, qualification and knowledge they may have or claim to have is of no benefit or interest to others.

On the other hand, it is always a delight to meet someone who is humble but keeps surprising those watching with hidden knowledge, skills and talents. 

YS Chan is master trainer for Mesra Malaysia and Travel and Tours Enhancement Course and an Asean Tourism Master Trainer. He is also a tourism and transport business consultant.

The views expressed are solely of the author and do not necessarily reflect those of MMKtT 

- Focus Malaysia.

Ramasamy’s Urimai in war of words with MIPP over who fights for Indian rights, “who seeks backroom deals”?

 

Editor’s Note:  A verbal exchnge has erupted between two Indian-based parties – the Malaysian Indian People’s Party (MIPP) and the United Rights of Malaysian Party’s (Urimai) – after the latter’s Selangor chief K. Gunasekaran accused Perikatan Nasional (PN) of failing to draw “real Indian leaders” with grassroots support.

Gunasekaran has further pointed out that Indian voters have yet to rally behind the opposition coalition despite growing disenchantment with the Madani administration.

Such statement has prompted MIPP deputy president S. Subramaniam hit back at Urimai leaders by describing the latter’s chairman Prof Ramasamy Palanisamy as an “opportunist” with no real credibility among the Indian community.

WE TAKE note of the remarks by Malaysian Indian People’s Party (MIPP) deputy president S. Subramaniam who questioned the United Rights of Malaysian Party’s (Urimai) registration status.

Let the record be clear. Urimai is fighting for its constitutional right in the courts – not sneaking through the backdoor –by hijacking another party’s name and structure.

On the contrary, MIPP was not born from public mandate or grassroots struggle. It emerged quietly without transparency through a technical backroom takeover.

If MIPP wants to talk about legitimacy, let them first reveal their actual membership. Beyond Subramaniam, its president S. P. Punithan and information chief Suthan Mookaiah, who else is with them?

By contrast, Urimai has already formed active state coordinating committees in eight states. We are building our base openly through the people – not through deals and shortcuts.

Let us also look at how these political actors left their former parties. Our interim council chairman Prof Ramasamy Palanisamy resigned from DAP when he was the party’s Penang deputy chairman.

Urimai interim council chairman Prof Ramasamy Palanisamy

He walked away from a strong position and from the prospect of GLC (government-linked company) appointments and honorary titles.

He did it to build a genuine struggle for the Malaysian Indian community. However, MIPP’s leaders left MIC not because of any principle but because they could not secure positions in the party.

MIC itself has been rejected by the community. If MIPP believes that MIC’s cast-offs can suddenly win back Indian support, they are fooling themselves. MIPP is not a new beginning. It is simply a Trojan horse within Perikatan Nasional (PN) with no organic support or moral compass.

Urimai deputy chairman David Marshel

MIPP can try to mislead PN leadership about its reach and support. But the Indian community knows who these people truly are. No amount of repackaging will hide the truth.

On the other hand, Urimai is here to build real political representation, social justice and reform. We are not here for favours. We are here to fight for the future of our people. 

David Marshel is the United Rights of Malaysian Party’s (Urimai) deputy chairman.

The views expressed are solely of the author and do not necessarily reflect those of  MMKtT.

- Focus Malaysia