Why Review Now?
Cyber Risk Is Now a Business Risk
Malaysian SMEs increasingly depend on cloud applications, email, accounting systems, shared files, remote access and connected devices. A weakness in any one of these areas can expose customer information, interrupt operations or allow an attacker to move deeper into the business network.
Installing antivirus or a firewall is not the end of cybersecurity. Protection also depends on configuration, software updates, user access, backup recovery, staff awareness and the ability to respond when suspicious activity is detected.
Recent Corporate Incident: Duopharma Biotech Berhad
Duopharma disclosed an incident involving unauthorised access to its IT infrastructure and the alleged extraction of files that may include personal data. Its internal cyber-defence systems detected the incident and activated containment measures. The company reported that its core corporate network and operational systems remained functional while a digital forensic investigation was initiated.
This case highlights an important lesson: security controls can help detect and contain an incident, but businesses must still be prepared to investigate affected data, notify the relevant authorities and strengthen safeguards.
Source: The Star, 11 September 2026.
CyberSecurity Malaysia has also reported that fraud, intrusion and data breaches continue to be significant threats. The right response is not panic—it is a structured review of the controls that protect your daily operations.
Reference: CyberSecurity Malaysia / MyCERT Cyber Incident Quarterly Summary Report, Q4 2025.
