
MALAYSIA’s digital economy is undergoing impressive growth. Its digital economy surged 19% year-on-year, led by e-commerce and online travel, the rapid digitalisation of financial services, a population generally embracing new artificial intelligence (AI) tools and technologies, and massive infrastructure investments that have grown local data centre capacity 4.5-fold in a year.
Malaysia is outpacing all other countries in a region that is already the fastest growing in the world in this sector.
However, this dynamic growth is making the pace of transformation among Malaysian businesses look almost sluggish in contrast.
For example, research released by AWS late last year found that just over one in four Malaysian companies (27%) claim they have adopted AI, lagging Singapore (48%), Thailand (32%), or Indonesia (28%), and a large majority of those (73%) are focusing on basic AI applications and productivity gains, with only one in ten reaching more advanced stages of AI deployment and innovation.
Given the health of its overall digital economy, it is a safe prediction therefore that tech deployments and innovation are poised to accelerate and mature among Malaysian organisations in 2026.
While the expected benefits of AI and cloud computing have become more tangible, these technologies, along with the ever growing need to make applications available for hybrid, remote or mobile workforces, are creating complex networks, digital estates and supply chains
that legacy security simply cannot keep up with.
As innovation continues to move at pace, it can be hard for organisations to identify and prioritise the security gaps and blind spots they should address first. With this in mind, here are four key trends and risks that should be prioritised to safely enable the innovation we expect to see in the coming months.
Despite gradual progress in securing generative AI (gen AI) in the workplace, security issues related to its use will likely remain a challenge for organisations in 2026.
A recent report from the Netskope Threat Labs team revealed that attempts from employees to share sensitive data (including regulated data, intellectual property and source code) with genAI tools via prompts or documents doubled in 2025. Another research focusing on Asia found that, despite a sharp decrease in the 12 months prior, more than one in three employees (35%) are still using personal gen AI accounts at work.
This is commonly known as “shadow AI”, which refers to AI being used and deployed among organisations without the knowledge of IT or
security teams, and is a thorn in their side because of the lack of visibility it allows security teams.
The ongoing increase in gen AI adoption within organisations is only going to fuel those issues, and organisations that underestimate the human error factor will leave a large gap in their cybersecurity posture.
As often happens with emerging technologies, there has so far been more talk than walk regarding agentic AI, and we are yet to confirm the extent of the contribution AI agents can make to organisations’ operations and bottom lines.
But that is poised to change in 2026. In May last year, already 5.5% of organisations worldwide were experimenting with agentic AI deployments, and leaders in major Asian economies including India and Singapore are placing agentic AI in their strategic priorities for 2026.
As organisations accelerate the development and deployment of autonomous AIs, it would be a mistake to put security in the backseat.
Agentic systems will do what is necessary to achieve their objectives, potentially even through unsafe and destructive means. AI agents have the ethical compass we will design them with, and if that design is flawed, their behaviours will be too.
Managing AI agents has much in common with the manner of managing employees. Their role needs to be clearly defined, their performance monitored continuously, and their access to systems and resources should be strictly limited to what they need to achieve their goal to
prevent them from compromising core systems or mishandling sensitive data.
Another risk emerging with AI agents is the communication protocols they use to communicate with each other or with enterprise resources such as Model Context Protocol (MCP), which should not be ignored.
Because you can’t protect what you don’t know, a priority for security teams is to ensure they are aware of all agentic AI projects across their organisation, because without their oversight, 2026 could be the year we witness the first large-scale data breach caused by an AI agent.
In the past few years, we have seen the destructive success of cyber criminals in using the weaker entities within a digital supply chain or partnership — those with lower cyber defences — as a route into the larger organisations.
While the front door may be well secured, the integrations and service provision within digital supply chains create inconsistencies of security hygiene, and their points of linkage into each other’s organisation (via less secure access points and integrations) can be more easily abused.
With Malaysia and Southeast Asia’s digital economies thriving, businesses are likely to scale up technology and AI deployments, expanding their attack surface through a growing volume of integrations with third-party providers, partners and contractors. The probability that one of them becomes a weak link is high.
Not only do organisations need to vet their security standards and how they will handle their data, they should also ask about potential data sub-processors, especially as the removal of the whitelist regime for cross border data transfers from the PDPA is anticipated to facilitate data exchanges.
In-house technology projects also need to adhere to safe development practices. That means deploying strict access controls, vetting all stakeholders involved in the project, and ensuring that infected open-source components will not become part of the application’s fabric and spread malware among stakeholders and users.
While practical quantum computing may still be years away, the threat of "harvest now, decrypt later" (HNDL) is already a reality.
Adversaries are already stealing encrypted data with the intent to decrypt it once quantum processing becomes viable.
There are two ways organisations can counter this: Do whatever they can to avoid data breaches and upgrade the encryption of their sensitive data to standards that quantum computers will not be able to decrypt.
Those standards already exist. The US’ National Institute of Standards and Technology initiated a post-quantum cryptography (PQC)standardisation project as early as 2016, when they called on the world’s best cryptographers to submit encryption methods that could resist an attack from quantum computers. In 2024, NIST published three encryption standards (and two more since then) that organisations can use to upgrade the encryption of their data and systems.
While major technology players and government entities have spearheaded efforts to transition to PQC, organisations across the board must begin to work on it, starting with a thorough audit of their (and their service providers and technology providers’) current encryption standards. The task of shifting to these new algorithms must not be underestimated as it has new power and memory requirements, as well as thorough testing in sandbox environments. Waiting for the "quantum era" to kick-off the transition would be an oversight.
While it is clear that 2026 will see many new and growing challenges for every organisation, it’s important to remember that the challenges of 2026 are additive.
To stay ahead, it will be important to consider people (the workforce), processes and technology when upleveling security posture, because progress in one of these areas alone is never enough to mitigate risk. AI, quantum and digital supply chains all merit
strategic discussion among technology, security and broader business leadership in 2026.
Kunal Jha is the regional director for Asia at Netskope, a global cybersecurity firm.