
KUALA LUMPUR: Data centres and critical digital infrastructure should be Malaysia’s top cybersecurity investment priority over the next three to five years as the country accelerates its ambitions to become a major regional data centre hub, according to Russian cybersecurity company Positive Technologies.
Positive Technologies regional director for Asia Elena Grishaeva said the scale and pace of Malaysia’s data centre expansion meant cybersecurity needed to be embedded into infrastructure from the outset, rather than treated as an issue to be addressed after facilities had been built and brought online.
“Security has to be built in from the start, not retrofitted later once everything’s already up and running at scale,” she told SunBiz.
She said the rapid development of data centres, alongside the expansion of artificial intelligence and other digital infrastructure, was creating a growing cybersecurity exposure that required corresponding investment in skills, technology and operational capabilities.
Malaysia has emerged as an increasingly important destination for data centre investment in Southeast Asia, supported by demand for cloud computing, AI and digital services. The expansion is also bringing more interconnected infrastructure and systems into operation, increasing the potential impact of cyber incidents.
Grishaeva said Malaysia was making reasonable progress in developing cybersecurity talent, with investment from the government and universities supporting the growth of the digital workforce.
However, she said the country’s biggest challenge was no longer necessarily at the entry level, where Malaysia has a relatively strong pipeline of graduates and growing cybersecurity awareness.
Instead, the more significant gaps were in specialised and experienced roles.
“There’s a real shortage in OT and industrial control system security, the people who can protect the physical, industrial side of these data centre campuses,” she said.
She also identified a shortage of cybersecurity operations centre, or SOC, professionals capable of running effective detection and response operations around the clock, as well as experienced incident response leaders who can take ownership of a cyber breach from initial detection through containment and recovery.
The talent challenge is compounded by competition from adjacent areas of the digital economy, she said.
Cloud infrastructure, network architecture and data centre engineering are all drawing from the same relatively limited pool of skilled technology workers, creating additional competition for professionals who might otherwise move into cybersecurity.
Grishaeva said this created a structural mismatch between the speed at which digital infrastructure was being developed and the time required to develop experienced cybersecurity professionals.
“Training a qualified SOC analyst or an incident response lead takes years; building a new data centre or rolling out a new AI platform takes months. This mismatch is the core of the problem, everywhere.”
Beyond data centres, Grishaeva ranked manufacturing as Malaysia’s second cybersecurity investment priority, particularly the semiconductor and advanced electronics industries.
She said operational technology and industrial control system environments had historically been less secure relative to their strategic and economic importance, making them an increasingly attractive target.
Malaysia’s position in global semiconductor supply chains also means a successful cyberattack against manufacturers could have consequences extending beyond an individual company, she said.
Banking and financial services ranked third, despite the sector already having relatively mature cybersecurity investment.
Grishaeva said financial institutions were facing growing exposure to AI-driven fraud and increasingly sophisticated social engineering, with threat actors adopting new technologies and techniques faster than many organisations could adapt their controls.
Healthcare was ranked fourth in terms of urgency, although she stressed that this did not make it less important.
She said healthcare organisations held highly valuable patient information while increasingly relying on connected medical devices and digital systems, creating additional avenues for attack.
The sector also historically under-invests in cybersecurity globally, she said, meaning its risk profile could become more pronounced as digitalisation reaches deeper into hospitals and clinics.
Grishaeva said Malaysia was reasonably well positioned to develop the cybersecurity workforce needed to support its digital economy, pointing to government investment, national strategies and efforts by universities to adapt their programmes.
The challenge was not unique to Malaysia, with the global cybersecurity industry facing a shortage of several million professionals.
She said no country had fully solved the talent shortage as artificial intelligence, cloud infrastructure and other digital technologies continued to evolve rapidly.
Malaysia’s strengths were also evident among its participants at Positive Hack Camp, where Grishaeva said Malaysian participants stood out for being well prepared and comfortable working with international peers.
She said their English proficiency, structured approach and strong fundamentals reflected investment in education and skills development.
However, she said there was room for Malaysia to strengthen practical, hands-on offensive cybersecurity capabilities.
Compared with delegations from countries such as Vietnam and Indonesia, Malaysian participants could develop more experience in areas such as network attacks, system exploitation and other practical hacking techniques, she said.
“Malaysia’s strength is more on the structured, disciplined side, good fundamentals, good process, but that ‘hacker instinct’, the offensive ethical mindset, is still building up,” she said.
Grishaeva said the gap could be narrowed by introducing more practical cybersecurity training at an earlier stage of education.



