In today’s threat landscape, the question is no longer whether your organisation will face a cyberattack. It is whether you will be prepared when it happens.
Ransomware, phishing campaigns, supply chain compromises, and increasing regulatory oversight are affecting organisations across all sectors. Yet many continue to operate with critical blind spots such as outdated controls, unmonitored access points, and policies that no longer reflect how the business operates. A structured cybersecurity review provides clarity on your current security posture and highlights areas requiring attention.
Recent incidents, both in Malaysia and overseas, demonstrate how quickly cyber risks can escalate into operational challenges, financial losses, and reputational damage.
In March 2026, several brokerage firms reported cybersecurity incidents involving components within their internal systems. Bursa Malaysia responded by activating its cybersecurity response protocols, coordinating investigations, and directing brokers and selected vendors to conduct comprehensive security screenings. Although the incidents were contained, with no reported unauthorised trading activity or financial loss, they occurred less than a year after an April 2025 hacking incident that affected multiple trading accounts across several brokers.
Beyond Malaysia, global incidents further illustrate the scale and consequences of cybersecurity failures. The Change Healthcare ransomware attack disrupted healthcare services across the United States, affecting payment processing, prescriptions, and patient care, while exposing data belonging to more than 100 million individuals. Similarly, breaches involving organisations using Snowflake's cloud platform exposed large volumes of customer records, with missing or inadequate multi-factor authentication identified as a key contributing factor.
The MGM Resorts incident in September 2023 showed how a single social engineering call can cripple an entire enterprise. Attackers impersonated a senior employee in a vishing call to IT support, gained administrator-level access, and locked the casino operator out of critical systems, including gaming machines, cash registers, and guest room keys, for over ten days, with losses estimated at more than USD100 million.
AT&T, meanwhile, suffered two separate breaches affecting close to 110 million customers. The first involved a 2021 database that resurfaced on the dark web, while the second, tied to AT&T's Snowflake cloud environment, exposed call and text records for nearly all AT&T customers from 2022, making it one of the most consequential telecom breaches in US history. In Canada, Telus disclosed an incident in which the ShinyHunters group claimed to have exfiltrated at least 700 terabytes of data, including personally identifiable information, call records, background check details, and source code.
The SolarWinds supply-chain attack compromised software updates distributed to thousands of organisations worldwide, including government agencies and major enterprises, highlighting how a single compromised supplier can create widespread downstream impacts across an interconnected ecosystem. In Singapore, a cyber espionage campaign attributed to the UNC3886 threat group targeted major telecommunications providers, illustrating the persistence and complexity of state-linked cyber operations and the challenges organisations face in defending against advanced adversaries.
These cases illustrate that cyber incidents can arise from a wide range of threats, from weaknesses in fundamental controls such as access management and monitoring to highly sophisticated attacks conducted by well-resourced threat actors. While the nature of each incident differs, they all underscore the importance of maintaining strong cybersecurity governance, visibility across critical systems, and a proactive approach to identifying and addressing potential risks.
A comprehensive review goes beyond checking boxes. It examines how well your technical controls, processes, and people work together to protect critical assets. Key areas typically include:
Understanding your current cybersecurity posture can provide valuable insight into how well your organisation is prepared for an evolving threat landscape. A tailored review can help highlight areas for consideration, support informed decision-making, and identify opportunities to strengthen your overall security approach.
Whether you are assessing existing controls, planning future improvements, or simply seeking greater visibility into your environment, a cybersecurity review can offer a useful starting point. If you would like to explore the topic further, our team would be pleased to discuss how such a review may support your organisation's objectives.
Other articles