Bylines

AI Shift: Why Cybersecurity Is Entering New Phase

Transforming Cybersecurity in Profound Ways—But With a Caveat

Artificial Intelligence (AI) is rapidly reshaping the balance between attackers and defenders in cyberspace. From the battlefield to the data centre, AI is emerging as a decisive factor in how conflicts unfold and in how cybersecurity is implemented. Its impact is comparable to earlier technological inflection points that reshaped global power dynamics.

Unlike previous technologies that were tightly controlled, AI tools are widely accessible. This accessibility means both defenders and adversaries are accelerating their capabilities, creating an environment where speed, scale, and automation define the cybersecurity landscape.

Across Asia Pacific, this shift is already visible. The rise of AI-enabled deepfakes and automated social engineering has driven a sharp increase in fraud and deception-based attacks, highlighting how quickly these tools are being weaponised.

The Growing Pressure from Generative AI

The rapid emergence of generative AI has significantly lowered the barrier to cybercrime. Attackers can now generate convincing phishing messages, synthetic voices, and even malicious code in seconds. What once required specialised technical skills can now be executed with minimal effort.

Like its neighbours across the region, Malaysia is also facing a rise in AI-driven cyber threats. A 2025 Fortinet survey revealed that nearly 50% of Malaysian organisations encountered AI-powered cyber threats. These attacks are escalating rapidly, with 54% of organisations reporting a two-fold increase, and 24% experiencing a three-fold surge.

Generative AI is also accelerating the pace of exploitation. In the past, organisations often had days or weeks to patch newly discovered vulnerabilities. Today, AI-driven tools can analyse those same patches and develop exploits in minutes, significantly shrinking the window for response.

Beyond technical exploitation, AI is transforming social engineering. Deepfake impersonations, automated reconnaissance, and AI-assisted phishing campaigns are enabling attackers to scale deception with unprecedented precision.

Organisations Struggle to Keep Up

While attackers are moving faster, many organisations in Malaysia are finding it difficult to keep pace. The rapid growth of digital services, cloud adoption, and connected technologies has significantly expanded the attack surface across industries, from financial services and manufacturing to healthcare and government systems.

Yet cybersecurity capabilities have not evolved at the same pace. Security responsibilities are often managed by small teams or embedded within broader IT functions, rather than supported by dedicated, mature security operations.

A 2025 Fortinet survey found that cybersecurity investment in Malaysia remains relatively low, with an average of 15% of IT budgets allocated to security—equivalent to just over 1% of total revenue. At the same time, only one out of five organisations are confident in their ability to defend against AI-powered attacks, and half feel that AI threats are outpacing their detection capabilities.

Malaysia is also experiencing the broader global shortage of cybersecurity professionals. Millions of roles remain unfilled worldwide, and the gap continues to widen as organisations accelerate digital transformation. Over 90% of organisations in Malaysia report breaches linked to a lack of skilled cybersecurity professionals, while 84% face challenges in hiring candidates with the necessary certifications.

National bodies such as the National Cyber Security Agency and CyberSecurity Malaysia have highlighted the growing need for stronger cyber capabilities across both public and private sectors. As threats evolve in speed and sophistication, organisations are recognising that traditional, manual approaches are no longer sufficient.

As Malaysia continues its push toward a digital economy, strengthening cybersecurity capabilities will be essential to ensuring that innovation and connectivity do not come at the cost of increased risk.

Why AI Alone Is Not Enough

However, deploying AI alone will not solve the cybersecurity challenge.

Many successful attacks still exploit well-known weaknesses such as unpatched vulnerabilities and misconfigured systems. Even when patches are available, delays in applying them leave systems exposed to relatively simple attacks.

AI can help identify and prioritise these gaps, but technology alone does not create an advantage—especially when both attackers and defenders are using similar tools.

Human expertise remains critical. Security teams must interpret AI-driven insights, understand context, and make informed decisions on response. Building the ability to work effectively alongside AI is becoming just as important as deploying the technology itself.

The Road Ahead for Cybersecurity

AI will continue to transform cybersecurity in profound ways. As both attackers and defenders increasingly rely on automation and machine learning, the pace of cyber conflict will only accelerate.

For Malaysia, maintaining trust in its digital economy will depend on how effectively organisations combine advanced technologies with skilled talent and strong governance. Building resilience will require collaboration across industry, government, and academia, along with a commitment to integrating security from the outset.

AI may be reshaping the cybersecurity landscape, but the outcome will ultimately depend on how strategically and responsibly it is used.

Kevin Wong

Fortinet Malaysia Country Manager

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *