Skip to content
  • Case Studies
  • Cybersecurity Readiness Assessment
simply data logo
  • About
    • About Us
    • Innovation
      • SD Platform Overview
    • Certifications & Awards
  • Our Services
    • CyberSecurity Services
      • DFIR (Digital Forensics and Incident Response)
      • Compromise Assessment
      • Security Operations Center (SOC) Managed Service
        • SD-Cyber Deception
        • Threat Intelligence
        • Managed Detection and Response (MDR)
        • Cloud Security Posture Management (CSPM)
        • Web Defacement Monitoring
        • In-house Automation Script Development
        • Advanced Malware Analysis & Threat Intelligence
        • Office 365 Monitoring
        • SaaS Monitoring
      • Extended Threat Intelligence
        • Dark Web Monitoring
        • Attack Surface Management
        • Cyber Risk Management
        • Supply Chain Intelligence
      • Security Posture Assessment (SPA)
      • VAPT & Penetration Testing
      • Network & Security Configuration Audit & Hardening
      • Phishing Email Simulation
    • Managed Network & Security Services
    • Application Performance Monitoring (APM)
      • APM as a Service (APMaaS)
      • Cloud Monitoring
      • Database Performance Monitoring
      • Web Application Monitoring
      • Synthetic Testing Monitoring
      • Real User Monitoring (RUM)
      • Application Stress Test / Load Test Services
    • Consultancy Services
      • NCSB Risk Assessment
      • Security BluePrint™ Consultancy Services
    • Agentic AI & Automation
      • SD Unified Platform (SDP)
      • Agentic AI SOC
      • AI Automation
      • SD Monitoring — 100% Data Ingestion Visibility | SD Unified Platform
      • SDP-Portal — Customer-Facing SOC Visibility | SD Unified Platform
      • AI Threat Hunting — Chat-Driven Investigation by SD Unified Platform
    CyberSecurity Services
    • VAPT & Penetration Testing
    • Cyber - 911 - DFIR Services
    • Compromise Assessment
    • Security Operations Center (SOC)
    • Extended Threat Intelligence
    • Security Posture Assessment (SPA) Services
    • Network & Security Configuration Audit & Hardening
    • Phishing Email Simulation
    • AI Automation
    Managed Network & Security Services
    • Managed Network & Security Services
    Consultancy Services
    • NCSB Risk Assessment
    • Security BluePrint™ Consultancy Services
    Agentic AI & Automation
    • SD Unified Platform
    • Agentic AI SOC
    • AI Automation
    • SD Monitoring
    • SDP-Portal
    • AI Threat Hunting
    Application Performance Monitoring
    • APM as a Service (APMaaS)
    • Cloud Monitoring
    • Database Performance Monitoring
    • Web Application Monitoring
    • Synthetic Testing Monitoring
    • Real User Monitoring (RUM)
    • Stress Test / Load Test – Performance Assessment

    Not Sure What Security Threats Your Organization is Facing?

    We can help. Contact us now for a free consultation and protect your business from potential risks.

    Contact Us
  • Technology Vendor Partners
  • Blog & News
  • Contact
    • Contact Us
    • Become a Simply Data Partner

Under Attack?

Submit your message through our contact form or call us at +603 5886 2714.

    Industry Insights & Trends

    Malaysia Cybersecurity Threat Report 2025: Key Findings & Strategic Insights

    February 27, 2026
    Malaysia Cybersecurity Threat Report 2025

    Home – Malaysia Cybersecurity Threat Report 2025: Key Findings & Strategic Insights

    The Malaysia cybersecurity threat report 2025 reveals a significant escalation in sophisticated cyberattacks targeting businesses across all sectors. From ransomware groups to state-sponsored APT activity, Malaysian organisations face an increasingly complex threat landscape.

    /* ── Sidebar: hide for this post ── */ body.postid-28446 #secondary, body.postid-28446 .widget-area, body.postid-28446 .keydesign-sidebar { display: none !important; } body.postid-28446 .keydesign-container { display: block !important; } body.postid-28446 #primary, body.postid-28446 .content-area { width: 100% !important; max-width: 100% !important; flex: none !important; float: none !important; padding: 0 !important; margin: 0 !important; } body.postid-28446 .entry-content, body.postid-28446 .post-content { max-width: 100% !important; padding: 0 !important; margin: 0 !important; } body.postid-28446 .wp-block-html { margin: 0 !important; padding: 0 !important; }/* ── Report wrapper ── */ .sd-report-wrap { display: block !important; font-family: ‘Barlow’, sans-serif !important; } .sd-report-wrap *, .sd-report-wrap *::before, .sd-report-wrap *::after { box-sizing: border-box !important; } .sd-report-wrap p { margin: 0 !important; } .sd-report-wrap h1,.sd-report-wrap h2,.sd-report-wrap h3, .sd-report-wrap h4,.sd-report-wrap h5 { margin: 0 !important; line-height: 1.2 !important; }/* ── Inline Download Form Section ── */ .sd25-dl-section { background: linear-gradient(135deg, #0D1B2A 0%, #1B2E45 100%); padding: 70px 20px; margin: 0; border-top: 4px solid #E84A0C; } .sd25-dl-inner { max-width: 860px; margin: 0 auto; } .sd25-dl-eyebrow { display: inline-block; font-family: ‘Barlow Condensed’, sans-serif; font-size: 12px; font-weight: 700; letter-spacing: 3px; color: #E84A0C; text-transform: uppercase; background: rgba(232,74,12,0.12); border: 1px solid rgba(232,74,12,0.35); padding: 5px 14px; border-radius: 20px; margin-bottom: 18px; display: inline-block; } .sd25-dl-heading { font-family: ‘Bebas Neue’, sans-serif !important; font-size: clamp(34px, 5vw, 56px) !important; color: #fff !important; margin: 0 0 12px 0 !important; letter-spacing: 1px; line-height: 1.1 !important; } .sd25-dl-sub { font-family: ‘Barlow’, sans-serif; font-size: 16px; color: rgba(255,255,255,0.7); margin: 0 0 40px 0 !important; line-height: 1.7; max-width: 680px; }/* ── Form Box ── */ .sd25-form-box { background: #fff; border-radius: 12px; padding: 40px 36px 36px; box-shadow: 0 20px 60px rgba(0,0,0,0.4); } .sd25-form-box h3 { font-family: ‘Barlow’, sans-serif !important; font-size: 19px !important; font-weight: 700 !important; color: #0D1B2A !important; margin: 0 0 6px 0 !important; } .sd25-form-box .sd25-form-subtitle { font-size: 14px; color: #6B7E90; margin: 0 0 28px 0 !important; font-family: ‘Barlow’, sans-serif; line-height: 1.5; } .sd25-form-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; margin-bottom: 14px; } @media (max-width: 600px) { .sd25-form-grid { grid-template-columns: 1fr; } } .sd25-form-field { display: flex; flex-direction: column; } .sd25-form-field.full { grid-column: 1 / -1; } .sd25-form-field label { font-size: 12px; font-weight: 700; color: #1C2B3A; margin-bottom: 5px; letter-spacing: 0.05em; text-transform: uppercase; font-family: ‘Barlow’, sans-serif; } .sd25-form-field label .req { color: #E84A0C; } .sd25-form-field input, .sd25-form-field select { padding: 11px 13px; border: 1.5px solid #D4DDE6; border-radius: 6px; font-size: 14px; font-family: ‘Barlow’, sans-serif; color: #1C2B3A; background: #fff; transition: border-color 0.2s, box-shadow 0.2s; outline: none; width: 100%; box-sizing: border-box; } .sd25-form-field input:focus, .sd25-form-field select:focus { border-color: #E84A0C; box-shadow: 0 0 0 3px rgba(232,74,12,0.1); } .sd25-accept-row { margin: 18px 0 20px; font-size: 13px; color: #5A6E80; font-family: ‘Barlow’, sans-serif; display: flex; align-items: flex-start; gap: 10px; line-height: 1.6; } .sd25-accept-row input[type=”checkbox”] { margin-top: 3px; flex-shrink: 0; width: 16px; height: 16px; accent-color: #E84A0C; cursor: pointer; } .sd25-accept-row a { color: #E84A0C; text-decoration: underline; } .sd25-submit-btn { width: 100%; background: #E84A0C; color: #fff; border: none; padding: 16px 24px; font-size: 16px; font-weight: 700; border-radius: 7px; cursor: pointer; font-family: ‘Barlow’, sans-serif; letter-spacing: 0.05em; transition: background 0.2s, transform 0.1s, box-shadow 0.2s; box-shadow: 0 4px 16px rgba(232,74,12,0.35); display: block; } .sd25-submit-btn:hover { background: #c43d09; transform: translateY(-1px); } .sd25-submit-btn:active { transform: scale(0.99); } .sd25-submit-btn:disabled { background: #aaa; cursor: not-allowed; box-shadow: none; transform: none; } .sd25-form-msg { margin-top: 14px; padding: 12px 16px; border-radius: 6px; font-size: 13px; font-family: ‘Barlow’, sans-serif; display: none; line-height: 1.5; } .sd25-form-msg.error { background: #fff2f0; color: #c00; border: 1px solid #ffccc7; display: block; } .sd25-form-msg.success { background: #f0fff4; color: #1a6b2a; border: 1px solid #b7eb8f; display: block; } .sd25-success-box { text-align: center; padding: 30px 20px; display: none; } .sd25-success-box.show { display: block; } .sd25-success-icon { font-size: 48px; margin-bottom: 14px; } .sd25-success-box h4 { font-family: ‘Bebas Neue’, sans-serif !important; font-size: 28px !important; color: #0D1B2A !important; margin: 0 0 10px !important; } .sd25-success-box p { font-size: 15px; color: #5A6E80; margin: 0 0 22px !important; font-family: ‘Barlow’, sans-serif; } .sd25-dl-direct { display: inline-block; background: #E84A0C; color: #fff !important; text-decoration: none !important; padding: 13px 28px; border-radius: 7px; font-weight: 700; font-family: ‘Barlow’, sans-serif; font-size: 15px; box-shadow: 0 4px 14px rgba(232,74,12,0.35); transition: background 0.2s; } .sd25-dl-direct:hover { background: #c43d09; }:root { –orange: #E84A0C; –orange-light: #FF6B35; –navy: #0D1B2A; –navy-mid: #1A2E42; –slate: #2A3F55; –light: #F4F6F8; –white: #FFFFFF; –text: #1C2B3A; –muted: #5A6E80; –border: #D8E2EC; }*, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; }html { scroll-behavior: smooth; }body { font-family: ‘Barlow’, sans-serif; font-weight: 300; background: var(–white); color: var(–text); line-height: 1.75; font-size: 17px; }/* ── HERO ── */ .hero { background: var(–navy); position: relative; overflow: hidden; min-height: 92vh; display: flex; align-items: center; padding: 80px 5%; }.hero::before { content: ”; position: absolute; inset: 0; background: radial-gradient(ellipse 80% 60% at 70% 40%, rgba(232,74,12,0.18) 0%, transparent 60%), radial-gradient(ellipse 50% 80% at 10% 80%, rgba(232,74,12,0.09) 0%, transparent 55%); }.hero-grid { position: absolute; inset: 0; background-image: linear-gradient(rgba(255,255,255,0.03) 1px, transparent 1px), linear-gradient(90deg, rgba(255,255,255,0.03) 1px, transparent 1px); background-size: 60px 60px; animation: gridPulse 8s ease-in-out infinite; }@keyframes gridPulse { 0%, 100% { opacity: 0.4; } 50% { opacity: 0.8; } }.hero-content { position: relative; z-index: 2; max-width: 820px; }.hero-eyebrow { font-family: ‘Barlow Condensed’, sans-serif; font-size: 13px; font-weight: 700; letter-spacing: 0.25em; text-transform: uppercase; color: var(–orange); margin-bottom: 24px; display: flex; align-items: center; gap: 12px; }.hero-eyebrow::before { content: ”; display: block; width: 40px; height: 2px; background: var(–orange); }.hero h1 { font-family: ‘Bebas Neue’, sans-serif; font-size: clamp(52px, 8vw, 110px); line-height: 0.92; color: var(–white); letter-spacing: 0.02em; margin-bottom: 32px; }.hero h1 span { color: var(–orange); }.hero-intro { font-size: 18px; font-weight: 300; color: rgba(255,255,255,0.72); max-width: 580px; margin-bottom: 48px; line-height: 1.7; }.hero-stats { display: grid; grid-template-columns: repeat(3, 1fr); gap: 2px; max-width: 600px; }.hero-stat { background: rgba(255,255,255,0.06); border: 1px solid rgba(255,255,255,0.1); padding: 20px 24px; backdrop-filter: blur(8px); }.hero-stat:first-child { border-radius: 8px 0 0 8px; } .hero-stat:last-child { border-radius: 0 8px 8px 0; }.hero-stat-num { font-family: ‘Bebas Neue’, sans-serif; font-size: 32px; color: var(–orange); line-height: 1; display: block; }.hero-stat-label { font-size: 11px; font-weight: 600; letter-spacing: 0.12em; text-transform: uppercase; color: rgba(255,255,255,0.5); display: block; margin-top: 4px; }/* ── ARTICLE LAYOUT ── */ .container { max-width: 820px; margin: 0 auto; padding: 0 24px; }.article-body { padding: 80px 0; }/* ── TABLE OF CONTENTS ── */ .toc { background: var(–light); border-left: 4px solid var(–orange); padding: 32px 36px; margin-bottom: 64px; border-radius: 0 8px 8px 0; }.toc h2 { font-family: ‘Barlow Condensed’, sans-serif; font-size: 13px; font-weight: 700; letter-spacing: 0.2em; text-transform: uppercase; color: var(–orange); margin-bottom: 16px; }.toc ol { list-style: decimal; padding-left: 20px; display: grid; grid-template-columns: 1fr 1fr; gap: 6px 32px; }.toc ol li a { color: var(–text); text-decoration: none; font-size: 15px; font-weight: 400; transition: color 0.2s; }.toc ol li a:hover { color: var(–orange); }/* ── SECTION HEADINGS ── */ .section-label { font-family: ‘Barlow Condensed’, sans-serif; font-size: 12px; font-weight: 700; letter-spacing: 0.25em; text-transform: uppercase; color: var(–orange); margin-bottom: 10px; }h2.section-title { font-family: ‘Bebas Neue’, sans-serif; font-size: clamp(36px, 5vw, 58px); line-height: 1; color: var(–navy); margin-bottom: 24px; letter-spacing: 0.02em; }h3.sub-title { font-family: ‘Barlow Condensed’, sans-serif; font-size: 22px; font-weight: 700; color: var(–navy); margin: 36px 0 12px; text-transform: uppercase; letter-spacing: 0.05em; }p { margin-bottom: 20px; color: var(–text); }/* ── PULL QUOTE ── */ blockquote.pull-quote { border: none; margin: 48px 0; padding: 36px 44px; background: var(–navy); border-radius: 4px; position: relative; }blockquote.pull-quote::before { content: ‘”‘; font-family: ‘Bebas Neue’, sans-serif; font-size: 120px; color: var(–orange); opacity: 0.3; position: absolute; top: -20px; left: 20px; line-height: 1; }blockquote.pull-quote p { color: var(–white); font-size: 20px; font-weight: 300; line-height: 1.6; font-style: italic; position: relative; z-index: 1; margin: 0; }/* ── STAT CARDS ── */ .stat-grid { display: grid; grid-template-columns: repeat(auto-fit, minmax(200px, 1fr)); gap: 16px; margin: 40px 0; }.stat-card { background: var(–light); border-radius: 8px; padding: 28px 24px; text-align: center; position: relative; overflow: hidden; transition: transform 0.2s; }.stat-card:hover { transform: translateY(-3px); }.stat-card::after { content: ”; position: absolute; bottom: 0; left: 0; right: 0; height: 3px; background: var(–orange); }.stat-card-num { font-family: ‘Bebas Neue’, sans-serif; font-size: 46px; color: var(–orange); line-height: 1; display: block; }.stat-card-label { font-size: 13px; font-weight: 600; text-transform: uppercase; letter-spacing: 0.1em; color: var(–muted); margin-top: 6px; display: block; }/* ── INCIDENT VISUAL BAR CHART ── */ .chart-section { background: var(–navy); border-radius: 12px; padding: 40px 36px; margin: 40px 0; }.chart-title { font-family: ‘Barlow Condensed’, sans-serif; font-size: 13px; font-weight: 700; letter-spacing: 0.2em; text-transform: uppercase; color: var(–orange); margin-bottom: 28px; }.bar-item { display: grid; grid-template-columns: 90px 1fr 52px; align-items: center; gap: 12px; margin-bottom: 10px; }.bar-label { font-size: 12px; font-weight: 600; letter-spacing: 0.08em; color: rgba(255,255,255,0.6); text-align: right; }.bar-track { background: rgba(255,255,255,0.08); border-radius: 2px; height: 22px; position: relative; overflow: hidden; }.bar-fill { height: 100%; border-radius: 2px; background: linear-gradient(90deg, var(–orange), var(–orange-light)); position: relative; animation: barGrow 1s ease-out forwards; transform-origin: left; }@keyframes barGrow { from { transform: scaleX(0); } to { transform: scaleX(1); } }.bar-value { font-family: ‘Bebas Neue’, sans-serif; font-size: 18px; color: var(–white); }/* ── RISK CARDS ── */ .risk-list { margin: 32px 0; }.risk-card { display: grid; grid-template-columns: 64px 1fr; gap: 0; margin-bottom: 20px; border-radius: 8px; overflow: hidden; border: 1px solid var(–border); }.risk-num { background: var(–orange); display: flex; align-items: center; justify-content: center; font-family: ‘Bebas Neue’, sans-serif; font-size: 38px; color: var(–white); }.risk-content { padding: 20px 24px; background: var(–white); }.risk-content h4 { font-family: ‘Barlow Condensed’, sans-serif; font-size: 18px; font-weight: 700; text-transform: uppercase; letter-spacing: 0.05em; color: var(–navy); margin-bottom: 6px; }.risk-content p { font-size: 15px; color: var(–muted); margin: 0; line-height: 1.6; }/* ── MITRE TABLE ── */ .data-table { width: 100%; border-collapse: collapse; margin: 32px 0; font-size: 15px; }.data-table thead th { background: var(–navy); color: var(–white); padding: 12px 16px; text-align: left; font-family: ‘Barlow Condensed’, sans-serif; font-weight: 700; letter-spacing: 0.08em; text-transform: uppercase; font-size: 13px; }.data-table tbody tr:nth-child(odd) { background: var(–light); } .data-table tbody tr:nth-child(even) { background: var(–white); } .data-table tbody tr:hover { background: rgba(232,74,12,0.06); }.data-table td { padding: 12px 16px; border-bottom: 1px solid var(–border); color: var(–text); }.data-table td:first-child { font-weight: 600; }.pct-badge { display: inline-block; background: var(–orange); color: white; font-family: ‘Bebas Neue’, sans-serif; font-size: 16px; padding: 2px 10px; border-radius: 3px; }/* ── THREAT INTEL HIGHLIGHT ── */ .intel-banner { background: linear-gradient(135deg, var(–navy) 0%, var(–slate) 100%); border-radius: 12px; padding: 48px 44px; margin: 40px 0; display: grid; grid-template-columns: 1fr 1fr 1fr; gap: 32px; text-align: center; position: relative; overflow: hidden; }.intel-banner::before { content: ”; position: absolute; top: -60px; right: -60px; width: 220px; height: 220px; background: var(–orange); opacity: 0.06; border-radius: 50%; }.intel-item-num { font-family: ‘Bebas Neue’, sans-serif; font-size: 40px; color: var(–orange); display: block; line-height: 1; }.intel-item-label { font-size: 12px; font-weight: 600; letter-spacing: 0.15em; text-transform: uppercase; color: rgba(255,255,255,0.5); display: block; margin-top: 6px; }/* ── INSIGHT CARDS ── */ .insight-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 20px; margin: 32px 0; }.insight-card { border-radius: 8px; overflow: hidden; border: 1px solid var(–border); }.insight-card-head { background: var(–orange); padding: 16px 20px; }.insight-card-head h4 { font-family: ‘Barlow Condensed’, sans-serif; font-weight: 700; font-size: 15px; text-transform: uppercase; letter-spacing: 0.08em; color: white; }.insight-card-body { padding: 20px; background: var(–white); }.insight-card-body p { font-size: 14px; color: var(–muted); margin: 0; line-height: 1.65; }/* ── COUNTRY TABLE ── */ .country-grid { display: grid; grid-template-columns: repeat(5, 1fr); gap: 12px; margin: 32px 0; }.country-card { background: var(–light); border-radius: 8px; padding: 20px 12px; text-align: center; border-bottom: 3px solid var(–border); transition: border-color 0.2s; }.country-card:first-child { border-color: var(–orange); }.country-flag { font-size: 28px; margin-bottom: 6px; display: block; }.country-pct { font-family: ‘Bebas Neue’, sans-serif; font-size: 26px; color: var(–orange); display: block; line-height: 1; }.country-name { font-size: 11px; font-weight: 700; letter-spacing: 0.1em; text-transform: uppercase; color: var(–muted); margin-top: 4px; display: block; }/* ── RECOMMENDATIONS ── */ .rec-list { margin: 32px 0; counter-reset: rec; }.rec-item { display: flex; gap: 20px; padding: 20px 0; border-bottom: 1px solid var(–border); align-items: flex-start; }.rec-item:last-child { border-bottom: none; }.rec-icon { width: 44px; height: 44px; background: var(–navy); border-radius: 8px; display: flex; align-items: center; justify-content: center; flex-shrink: 0; font-size: 20px; }.rec-item h4 { font-family: ‘Barlow Condensed’, sans-serif; font-weight: 700; font-size: 17px; text-transform: uppercase; letter-spacing: 0.06em; color: var(–navy); margin-bottom: 4px; }.rec-item p { font-size: 14px; color: var(–muted); margin: 0; line-height: 1.6; }/* ── CTA ── */ .cta-block { background: var(–navy); border-radius: 12px; padding: 56px 48px; text-align: center; margin: 64px 0 0; position: relative; overflow: hidden; }.cta-block::before { content: ”; position: absolute; inset: 0; background: radial-gradient(ellipse 80% 100% at 50% 0%, rgba(232,74,12,0.2) 0%, transparent 60%); }.cta-block * { position: relative; z-index: 1; }.cta-block h2 { font-family: ‘Bebas Neue’, sans-serif; font-size: clamp(36px, 5vw, 62px); color: var(–white); line-height: 1; margin-bottom: 16px; }.cta-block h2 span { color: var(–orange); }.cta-block p { color: rgba(255,255,255,0.65); font-size: 17px; max-width: 480px; margin: 0 auto 36px; }.btn { display: inline-block; background: var(–orange); color: var(–white); text-decoration: none; font-family: ‘Barlow Condensed’, sans-serif; font-weight: 700; font-size: 15px; letter-spacing: 0.15em; text-transform: uppercase; padding: 16px 36px; border-radius: 4px; transition: background 0.2s, transform 0.15s; }.btn:hover { background: var(–orange-light); transform: translateY(-1px); }/* ── SECTION DIVIDER ── */ .section-wrap { padding: 64px 0; border-bottom: 1px solid var(–border); }.section-wrap:last-of-type { border-bottom: none; }/* ── SVG VISUALS ── */ .visual-block { margin: 40px 0; border-radius: 12px; overflow: hidden; }/* ── FOOTER ── */ .article-footer { background: var(–light); padding: 32px 0; margin-top: 64px; text-align: center; border-top: 1px solid var(–border); }.article-footer p { font-size: 13px; color: var(–muted); margin: 0; }.tags { display: flex; flex-wrap: wrap; gap: 8px; margin: 40px 0; }.tag { background: var(–light); border: 1px solid var(–border); color: var(–muted); font-size: 12px; font-weight: 600; letter-spacing: 0.08em; text-transform: uppercase; padding: 6px 14px; border-radius: 3px; }/* ── RESPONSIVE ── */ @media (max-width: 680px) { .hero-stats { grid-template-columns: 1fr; } .hero-stat:first-child { border-radius: 8px 8px 0 0; } .hero-stat:last-child { border-radius: 0 0 8px 8px; } .toc ol { grid-template-columns: 1fr; } .intel-banner { grid-template-columns: 1fr; } .insight-grid { grid-template-columns: 1fr; } .country-grid { grid-template-columns: repeat(2, 1fr); } }/* ── PARTNER CARDS ── */ .partner-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 24px; margin: 36px 0; }.partner-card { background: var(–light); border-radius: 10px; overflow: hidden; border: 1px solid var(–border); display: flex; flex-direction: column; transition: transform 0.2s, box-shadow 0.2s; }.partner-card:hover { transform: translateY(-3px); box-shadow: 0 12px 32px rgba(13,27,42,0.1); }.partner-icon { background: var(–navy); text-align: center; font-size: 40px; padding: 28px; line-height: 1; }.partner-body { padding: 24px 28px; }.partner-body h4 { font-family: “Bebas Neue”, sans-serif; font-size: 28px; letter-spacing: 0.05em; color: var(–navy); margin-bottom: 10px; }.partner-body p { font-size: 15px; color: var(–muted); line-height: 1.7; margin: 0; }@media (max-width: 680px) { .partner-grid { grid-template-columns: 1fr; } }/* ══ PARTNER SECTIONS ══ */ .partner-section { padding-top: 72px; }.partner-header { border-radius: 10px; padding: 32px 36px; margin-bottom: 8px; }.starlight-header { background: linear-gradient(135deg, #0D1B2A 0%, #1a2535 100%); border-left: 5px solid #E84A0C; } .flawtrack-header { background: linear-gradient(135deg, #0D1B2A 0%, #121e2b 100%); border-left: 5px solid #E84A0C; }.partner-header-inner { display: flex; align-items: center; justify-content: space-between; flex-wrap: wrap; gap: 16px; }.partner-logo-svg { height: 56px; width: auto; }.partner-header-links { display: flex; gap: 10px; flex-wrap: wrap; }.partner-link-pill { display: inline-block; border: 1px solid rgba(232,74,12,0.6); color: var(–orange-light); background: rgba(232,74,12,0.08); font-family: “Barlow Condensed”, sans-serif; font-weight: 700; font-size: 13px; letter-spacing: 0.08em; padding: 7px 16px; border-radius: 4px; text-decoration: none; transition: background 0.2s, color 0.2s; } .partner-link-pill:hover { background: var(–orange); color: #fff; }.partner-data-label { margin-top: 12px; font-size: 12px; font-weight: 600; letter-spacing: 0.14em; text-transform: uppercase; color: rgba(255,255,255,0.45); }/* Ransomware year stats */ .ransom-year-grid { display: flex; align-items: center; gap: 16px; margin: 32px 0; flex-wrap: wrap; } .ransom-year-card { flex: 1; min-width: 130px; background: var(–light); border: 1px solid var(–border); border-radius: 10px; padding: 24px 20px; text-align: center; position: relative; } .ransom-year-card–hot { background: #fff4f0; border-color: rgba(232,74,12,0.35); } .ransom-year-label { display: block; font-family: “Barlow Condensed”, sans-serif; font-weight: 700; letter-spacing: 0.15em; font-size: 13px; text-transform: uppercase; color: var(–muted); margin-bottom: 6px; } .ransom-year-num { display: block; font-family: “Bebas Neue”, sans-serif; font-size: 60px; line-height: 1; color: var(–navy); } .ransom-year-sub { display: block; font-size: 12px; color: var(–muted); font-weight: 600; margin-top: 4px; } .ransom-year-badge { display: inline-block; background: var(–orange); color: #fff; font-size: 11px; font-weight: 700; padding: 3px 10px; border-radius: 20px; margin-top: 8px; letter-spacing: 0.05em; } .ransom-year-arrow { font-size: 28px; color: var(–muted); font-weight: 300; flex-shrink: 0; }/* Two-col tables */ .two-col-tables { display: grid; grid-template-columns: 1fr 1fr; gap: 20px; margin: 24px 0; }/* Two-col insight (offensive/defensive AI) */ .two-col-insight { display: grid; grid-template-columns: 1fr 1fr; gap: 20px; margin: 28px 0; } .insight-col { border-radius: 8px; overflow: hidden; border: 1px solid var(–border); } .insight-col-head { padding: 14px 20px; font-family: “Barlow Condensed”, sans-serif; font-weight: 700; font-size: 15px; text-transform: uppercase; letter-spacing: 0.08em; } .insight-col–threat .insight-col-head { background: var(–navy); color: #fff; } .insight-col–defend .insight-col-head { background: var(–orange); color: #fff; } .insight-ul { list-style: none; padding: 16px 20px; margin: 0; background: var(–white); } .insight-ul li { padding: 8px 0 8px 20px; position: relative; font-size: 14px; color: var(–muted); line-height: 1.6; border-bottom: 1px solid var(–border); } .insight-ul li:last-child { border-bottom: none; } .insight-ul li::before { content: “•”; color: var(–orange); position: absolute; left: 0; font-weight: 700; }/* Sector forecast grid */ .sector-forecast-grid { display: grid; grid-template-columns: repeat(3, 1fr); gap: 16px; margin: 24px 0; } .sector-fc-card { background: var(–light); border-radius: 8px; padding: 24px 20px; text-align: center; border-top: 3px solid var(–orange); } .sector-fc-icon { font-size: 32px; margin-bottom: 10px; display: block; } .sector-fc-card h4 { font-family: “Barlow Condensed”, sans-serif; font-weight: 700; font-size: 16px; text-transform: uppercase; letter-spacing: 0.06em; color: var(–navy); margin-bottom: 8px; } .sector-fc-card p { font-size: 13px; color: var(–muted); margin: 0; line-height: 1.6; }/* Thank You Cards */ .thankyou-card { display: flex; gap: 24px; border-radius: 10px; padding: 36px 36px; margin-top: 48px; align-items: flex-start; border: 1px solid rgba(232,74,12,0.25); } .starlight-ty { background: linear-gradient(135deg, #0D1B2A 0%, #162235 100%); } .flawtrack-ty { background: linear-gradient(135deg, #0D1B2A 0%, #0f1d2c 100%); }.ty-icon { font-size: 40px; flex-shrink: 0; margin-top: 4px; } .ty-body h4 { font-family: “Bebas Neue”, sans-serif; font-size: 28px; color: var(–white); letter-spacing: 0.04em; margin-bottom: 12px; } .ty-body p { color: rgba(255,255,255,0.7); font-size: 15px; line-height: 1.75; } .ty-links { display: flex; gap: 12px; flex-wrap: wrap; margin-top: 20px; } .ty-link-btn { display: inline-block; background: var(–orange); color: #fff; text-decoration: none; font-family: “Barlow Condensed”, sans-serif; font-weight: 700; font-size: 14px; letter-spacing: 0.1em; padding: 10px 22px; border-radius: 4px; transition: background 0.2s, transform 0.15s; } .ty-link-btn:hover { background: var(–orange-light); transform: translateY(-1px); }/* Exposure stat grid (Flawtrack) */ .exposure-stat-grid { display: grid; grid-template-columns: repeat(3, 1fr); gap: 14px; margin: 28px 0; } .exposure-stat-card { background: var(–navy); border-radius: 8px; padding: 22px 18px; text-align: center; } .esn { display: block; font-family: “Bebas Neue”, sans-serif; font-size: 34px; color: var(–orange); line-height: 1; } .esl { display: block; font-size: 11px; font-weight: 600; letter-spacing: 0.1em; text-transform: uppercase; color: rgba(255,255,255,0.5); margin-top: 6px; }/* Dark web findings */ .darkweb-findings { margin: 24px 0; } .dw-item { display: flex; gap: 20px; padding: 18px 0; border-bottom: 1px solid var(–border); align-items: flex-start; } .dw-item:last-child { border-bottom: none; } .dw-icon { font-size: 24px; flex-shrink: 0; width: 40px; text-align: center; } .dw-text strong { display: block; font-family: “Barlow Condensed”, sans-serif; font-weight: 700; font-size: 16px; text-transform: uppercase; letter-spacing: 0.05em; color: var(–navy); margin-bottom: 4px; } .dw-text p { font-size: 14px; color: var(–muted); margin: 0; line-height: 1.65; }/* Joint Acknowledgement Banner */ .joint-ack-banner { background: var(–navy); border-radius: 12px; padding: 48px 44px; margin: 56px 0 0; text-align: center; position: relative; overflow: hidden; } .joint-ack-banner::before { content: “”; position: absolute; inset: 0; background: radial-gradient(ellipse 80% 100% at 50% -10%, rgba(232,74,12,0.18) 0%, transparent 60%); } .jab-inner { position: relative; z-index: 1; } .jab-title { font-family: “Bebas Neue”, sans-serif; font-size: 38px; color: #fff; letter-spacing: 0.04em; margin-bottom: 16px; } .jab-desc { color: rgba(255,255,255,0.65); font-size: 16px; max-width: 640px; margin: 0 auto 36px; line-height: 1.75; } /* .jab-logos defined in logo card CSS above */ .jab-logo-btn { display: inline-block; text-decoration: none; font-family: “Barlow Condensed”, sans-serif; font-weight: 700; font-size: 15px; letter-spacing: 0.1em; padding: 12px 26px; border-radius: 4px; transition: transform 0.15s, opacity 0.2s; } .jab-logo-btn:hover { transform: translateY(-2px); opacity: 0.9; } .starlight-btn { background: rgba(255,255,255,0.1); color: #fff; border: 1px solid rgba(255,255,255,0.2); } .flawtrack-btn { background: var(–orange); color: #fff; } .jab-sep { color: rgba(255,255,255,0.3); font-size: 22px; font-weight: 300; }/* Responsive partner */ @media (max-width: 680px) { .two-col-tables, .two-col-insight, .sector-forecast-grid { grid-template-columns: 1fr; } .exposure-stat-grid { grid-template-columns: 1fr 1fr; } .ransom-year-grid { flex-direction: column; } .ransom-year-arrow { transform: rotate(90deg); } .partner-header-inner { flex-direction: column; align-items: flex-start; } .thankyou-card { flex-direction: column; } .jab-logo-btn { font-size: 13px; padding: 10px 18px; } }/* Real logo images */ .partner-logo-badge { height: 110px; width: auto; object-fit: contain; filter: drop-shadow(0 2px 8px rgba(0,0,0,0.4)); } .partner-logo-img { height: 56px; width: auto; object-fit: contain; filter: brightness(0) invert(1); } .partner-logo-link { display: flex; align-items: center; }/* Joint banner logo cards — ALL EQUAL SIZE 160x120px boxes */ .jab-partner-logo-wrap { display: flex; align-items: center; justify-content: center; width: 200px; height: 120px; padding: 16px 20px; background: rgba(255,255,255,0.07); border-radius: 10px; border: 1px solid rgba(255,255,255,0.14); transition: background 0.2s, transform 0.15s; text-decoration: none; flex-shrink: 0; } .jab-partner-logo-wrap:hover { background: rgba(255,255,255,0.14); transform: translateY(-2px); } /* All images contained within their equal-size card */ .jab-partner-img { max-width: 100%; max-height: 100%; width: auto; height: auto; object-fit: contain; } /* SD: wide wordmark — limit height so it fits card */ .jab-img-sd { max-height: 44px; } /* SL: square badge — let it fill the card nicely */ .jab-img-sl { max-height: 88px; filter: drop-shadow(0 2px 6px rgba(0,0,0,0.5)); } /* FW: wide wordmark — limit height, invert to white */ .jab-img-fw { max-height: 44px; filter: brightness(0) invert(1); }/* Joint banner layout */ .jab-logos { display: flex; flex-direction: column; align-items: center; gap: 24px; } .jab-top-row { display: flex; align-items: center; justify-content: center; gap: 24px; flex-wrap: wrap; } .jab-bottom-row { display: flex; justify-content: center; } /* Equal partner cards */ .jab-partner-logo-wrap { display: flex; align-items: center; justify-content: center; width: 220px; height: 140px; padding: 20px; background: rgba(255,255,255,0.07); border-radius: 12px; border: 1px solid rgba(255,255,255,0.14); transition: background 0.2s, transform 0.15s; text-decoration: none; } .jab-partner-logo-wrap:hover { background: rgba(255,255,255,0.14); transform: translateY(-2px); } /* Simply Data bottom card — wider */ .jab-sd-wrap { width: 460px; height: 110px; } .jab-partner-img { max-width:100%; max-height:100%; width:auto; height:auto; object-fit:contain; } /* Starlight badge — square, fills card */ .jab-img-sl { max-height: 100px; filter: drop-shadow(0 2px 8px rgba(0,0,0,0.5)); } /* Flawtrack — white wordmark, fills card width */ .jab-img-fw { max-height: 60px; max-width: 170px; filter: brightness(0) invert(1); } /* Simply Data — white+orange wordmark */ .jab-img-sd { max-height: 54px; max-width: 400px; } .jab-sep { color: rgba(255,255,255,0.35); font-size: 28px; font-weight: 200; line-height: 1; }/* Section-level teaser CTA */ .section-teaser-cta { display: inline-flex; align-items: center; gap: 6px; color: var(–orange); font-size: 13px; font-weight: 600; letter-spacing: 0.05em; text-transform: uppercase; text-decoration: none; border-bottom: 1px solid transparent; margin-top: 24px; padding: 8px 0; transition: border-color 0.2s; } .section-teaser-cta:hover { border-color: var(–orange); } .section-teaser-cta::after { content: ” →”; }/* Mid-article download banner */ .mid-download-banner { background: var(–navy); border: 1px solid rgba(232,74,12,0.3); border-radius: 12px; padding: 36px 40px; margin: 56px 0; display: flex; align-items: center; justify-content: space-between; gap: 24px; flex-wrap: wrap; position: relative; overflow: hidden; } .mid-download-banner::before { content: ”; position: absolute; inset: 0; background: radial-gradient(ellipse 60% 120% at 100% 50%, rgba(232,74,12,0.12) 0%, transparent 60%); } .mid-download-banner-text h3 { font-size: 20px; font-weight: 700; color: #fff; margin: 0 0 6px; } .mid-download-banner-text p { font-size: 14px; color: rgba(255,255,255,0.55); margin: 0; }

    Table of Contents

    1. Report Overview
    2. Incident Landscape
    3. Incidents by Log Sources
    4. Top Targeted Industries
    5. MITRE ATT&CK Breakdown
    6. Threat Intelligence
    7. Top 3 Risks Identified
    8. Strategic Insights
    9. Reflecting on 2024 Predictions
    10. Starlight Intelligence Data
    11. Flawtrack Dark Web Data
    12. 2026 Predictions & Recommendations
    Report Overview

    Malaysia Cybersecurity Threat Report 2025: Scale of Malaysia’s Threat Landscape

    Each year, Simply Data award-winning Security Operations Centre (SOC), ISO/IEC 27001 certified, CREST accredited, and CSM Collaboration Partner recognised, processes billions of security events — forming the evidence base for the Malaysia cybersecurity threat report 2025 — on behalf of organisations across Malaysia, Indonesia, and Singapore. The Malaysia Threat Report 2025, covering the full calendar year from 1 January to 31 December 2025, represents the most comprehensive view yet of the threats targeting Malaysian organisations.

    The data in the Malaysia cybersecurity threat report 2025, drawn from a customer base spanning Finance & Insurance, Government Agencies, Education, Logistics, Large Conglomerates, Property Developers, Energy, Manufacturing, Datacentre Providers, and Media & Entertainment, paints an alarming but actionable picture: threat actors are becoming more systematic, more patient, and increasingly focused on identity-layer exploitation.

    120.6B Total Logs Collected
    12.4M SIEM Alerts Triggered
    3,945 Incidents Escalated
    428.7M Unique IOC Lookups
    33.2M Bad Reputation IOCs
    7.75% TI Match Rate

    What makes the Malaysia cybersecurity threat report 2025 distinctive is that it is built on real SOC telemetry, not surveys or estimates. Every number represents an actual log line, a real alert, a genuine attacker behaviour observed inside a Malaysian organisation’s environment.

    Incident Landscape

    Incidents Month by Month

    Of the 12,379,396 alerts triggered across all monitored SIEM environments, Simply Data analysts escalated 3,945 confirmed security incidents, roughly 329 per month, as documented in the Malaysia cybersecurity threat report 2025. However, the monthly distribution is far from uniform, and the trend line tells a critical story.

    Escalated Incidents: Monthly Breakdown (2025)
    JAN 2024
    326
    FEB 2024
    211
    MAR 2024
    211
    APR 2024
    235
    MAY 2024
    219
    JUN 2024
    187
    JUL 2024
    267
    AUG 2024
    323
    SEPT 2024
    602
    OCT 2024
    497
    NOV 2024
    458
    DEC 2024
    409

    The Malaysia cybersecurity threat report 2025’s most alarming data point is September 2025, which saw 602 escalated incidents, the highest single month across the entire year and more than three times the June low. The Q4 2025 period (September through December) accounted for a disproportionate share of all annual incidents, suggesting that threat actors are ramping up operations in the second half of the year, possibly aligned with major product and fiscal cycle milestones.

    September 2025 alone saw 602 escalated incidents, the highest monthly count of the year, signalling a sharp escalation in adversarial tempo heading into Q4.

    Incidents by Log Sources

    Where Are Attacks Originating?

    Understanding which log sources generate the most incidents is critical for SOC prioritisation. The Malaysia cybersecurity threat report 2025 reveals that Microsoft 365 (O365) is the dominant attack surface, generating nearly a third of all escalated incidents.

    32.16% O365 LOGS #1 Ranked30.33% OS LOGS #2 Ranked14.91% NETWORK LOGS #3 Ranked

    The Malaysia cybersecurity threat report 2025 confirms the dominance of O365 logs (32.16%), as the MITRE ATT&CK mappings also show: Microsoft 365 environments are the primary initial access battleground for Malaysian organisations. Operating System logs (30.33%) follow closely, indicating significant endpoint-level activity, while Network logs (14.91%) round out the top three.

    Top 10 Incidents by Name

    The most frequently observed incident types reveal a consistent pattern: attackers are leveraging credential-based techniques before attempting to escalate privileges or exfiltrate data:

    Incident Type% of Total
    Potential Password Spraying of Microsoft 365 User Accounts6.53%
    Microsoft 365 Portal Logins from Impossible Travel Locations6.20%
    Successful O365 Login from Blacklisted IP4.74%
    Sensitive Directory Service Object Changed2.78%
    SMB (Windows File Sharing) Activity to the Internet2.43%
    Account Configured with Never-Expiring Password1.90%
    New User Created / Login Using Admin Privileges1.65%
    Successful Root SSH Login1.41%
    Privileged Account Brute Force1.17%
    File Changes at Sensitive Directory (FIM)1.17%
    Industry Analysis

    Top Targeted Industries

    When we look at which industries faced the highest number of escalated incidents, three sectors stand apart in the Malaysia cybersecurity threat report 2025. These sectors face a combination of high data value, complex supply chain dependencies, and often under-resourced security teams, a combination that threat actors actively exploit.

    ? EDUCATION #1 Most Incidents? LOGISTICS #2 Most Incidents? LARGE CONGLOMERATE #3 Most Incidents

    Education ranks first in incident volume in the Malaysia cybersecurity threat report 2025, a pattern consistent with global trends. Universities and schools hold vast amounts of personally identifiable information (PII), research data, and financial records, all while operating open-access networks designed for collaboration rather than security. Logistics companies, managing time-sensitive supply chains, are similarly vulnerable; operational disruption via ransomware or data theft carries significant financial penalty. Large Conglomerates present a broad attack surface with subsidiaries of varying security maturity, making them attractive for lateral movement and supply chain attacks.

    MITRE ATT&CK Framework

    How Attackers Operate in Malaysia

    Simply Data maps every escalated incident documented in the Malaysia cybersecurity threat report 2025 to the MITRE ATT&CK framework, providing a standardised view of adversary tactics and techniques. The 2025 results confirm that Malaysian threat actors are following a deliberate, structured kill chain that begins with credential theft and ends with data extraction.

    Top 5 Tactics (TA)

    Tactic IDTactic Name% of Incidents
    TA0006Credential Access25.38%
    TA0001Initial Access22.79%
    TA0003Persistence11.53%
    TA0010Exfiltration9.45%
    TA0011Command and Control8.29%

    Top 5 Techniques (T)

    Technique IDTechnique Name% of Incidents
    T1078Valid Accounts18.71%
    T1110Brute Force15.17%
    T1098Account Manipulation8.54%
    T1190Exploit Public-Facing Application5.77%
    T1048Exfiltration Over Alternative Protocol3.90%

    The Malaysia cybersecurity threat report 2025 tells a clear story: attackers enter via valid credentials (T1078, 18.71%) or brute-force methods (T1110, 15.17%), then manipulate accounts to establish persistence and escalate privileges. Command-and-Control infrastructure is then used to orchestrate data exfiltration. This is a textbook Advanced Persistent Threat (APT) pattern, no longer reserved for nation-state actors, but now widely adopted by financially-motivated cybercriminal groups targeting Malaysian organisations.

    Threat Intelligence

    Indicators of Compromise: The Numbers

    428.7M Total IOC Lookups
    33.2M Bad Reputation IOCs Matched
    18.027 Avg TI Feeds Matched per IOC

    Simply Data correlates every IOC — a methodology central to the Malaysia cybersecurity threat report 2025 — against an extensive threat intelligence ecosystem. Out of 428,681,768 unique IOC lookups, 33,213,117 were confirmed as malicious, a match rate of 7.75%. Critically, when a match was confirmed, it triggered an average of 18.027 separate threat intelligence feed hits, indicating that the malicious infrastructure being encountered is well-documented and actively tracked by the global threat intelligence community.

    Top Threat Source Countries

    The Malaysia cybersecurity threat report 2025 maps how Malaysia’s threat landscape is heavily influenced by infrastructure based in the following countries. Note that infrastructure location does not necessarily indicate attacker origin, as many threat actors deliberately route through cloud providers and VPNs in these jurisdictions.

    ?? 50.93% United States
    ?? 10.31% United Kingdom
    ?? 4.75% China
    ?? 3.85% Netherlands
    ?? 3.76% France

    The United States’ dominant share (50.93%) reflects the widespread use of major US-based cloud platforms such as AWS, Azure, Cloudflare, and similar providers, as attack infrastructure. This underscores the need for threat intelligence that goes beyond simple geo-blocking and focuses instead on behavioural indicators and reputation-based detection.

    Risk Analysis

    Top 3 Risks Identified

    01

    Identity and Credential Compromise

    Password spraying, brute-force attempts, and impossible travel login events are the most common threats documented in the Malaysia cybersecurity threat report 2025. Credential Access is the most prevalent MITRE tactic (25.38%) and Valid Accounts (T1078) is the most frequently observed technique at 18.71%. Microsoft 365 environments are the primary entry point, making identity security the single most critical control gap in Malaysian organisations today.

    02

    Weak Access Controls and Privilege Management

    The Malaysia cybersecurity threat report 2025 data reveals systemic weaknesses in identity governance: accounts configured with non-expiring passwords, newly created users being granted administrative privileges immediately, and unauthorised directory object modifications. Persistence tactics account for 11.53% of observed TTPs, while Account Manipulation (T1098) at 8.54% highlights the ease with which attackers escalate privileges once inside the environment.

    03

    Data Exfiltration Exposure

    The Malaysia cybersecurity threat report 2025 identifies exfiltration as the fourth most prevalent tactic at 9.45%, with SMB traffic to external destinations and exfiltration over alternative protocols as key indicators. When viewed alongside Command-and-Control activity (8.29%), it is evident that successful intrusions frequently progress to active data extraction, particularly in Education and Logistics, where sensitive personal and operational data is held at scale.

    Strategic Insights

    What the 2025 Data Really Tells Us

    The Malaysia cybersecurity threat report 2025 data uncovers three overarching themes when the full dataset is viewed holistically. These themes transcend any single incident or technique and describe the structural nature of Malaysia’s cybersecurity challenge in 2025.

    1. Identity Infrastructure Is the Primary Battleground

    According to the Malaysia cybersecurity threat report 2025, Microsoft 365 is consistently the first target. Adversaries predominantly rely on credential-based techniques such as password spraying, brute force, and anomalous login activity, to gain access. This risk is further amplified by extensive third-party and supply chain integrations with M365, where compromised external applications, OAuth permissions, or automation workflows can be leveraged to abuse trusted access paths. Identity compromise is no longer confined to direct user activity; it extends to every integrated tool and service.

    2. Governance Gaps Enable Attack Progression

    Once initial access is obtained — a recurring pattern in the Malaysia cybersecurity threat report 2025 — weaknesses in access controls, privilege management, and identity governance frequently allow attackers to progress through multiple stages of the kill chain. Indicators such as excessive privileges, non-expiring passwords, rapid elevation of newly created accounts, and risky directory changes point to configuration and enforcement gaps, not a lack of detection capability. Organisations are often detecting the right events; they are simply not enforcing the right preventative controls to stop attackers from exploiting the window of opportunity.

    3. High-Value Targets Drive Concentrated Risk

    The Malaysia cybersecurity threat report 2025 shows observed threat activity is highly concentrated around a limited number of attack techniques that directly enable access to sensitive systems and data. Credential Access, Valid Accounts, Persistence, and Exfiltration consistently appear together, indicating that attackers are prioritising efficiency and impact. Education and Logistics are disproportionately affected due to the nature of the data they manage, including personal information and critical operational data, combined with typically constrained security budgets.

    Attackers are selectively targeting environments where successful compromise is more likely to result in meaningful data access or operational leverage. This is precision cybercrime, not opportunism.

    Looking Back

    Reflecting on Our 2024 Predictions

    How well did last year’s predictions hold up? The Malaysia cybersecurity threat report 2025 allows us to measure accuracy — and the majority proved correct.

    2024 PredictionOutcome
    Rise of Supply Chain Compromise✓ Yes
    Password Compromise and Social Engineering✓ Yes
    Ransomware and Security Practices~ Partial

    Supply chain compromises were fully validated in the Malaysia cybersecurity threat report 2025, with third-party vendor risk materialising across multiple sectors. Password compromise and social engineering also played out as predicted, amplified by generative AI-powered phishing. Ransomware was partially realised: RaaS and EDR killer tools confirmed the threat, but progress on People, Processes, and Technology balance remained uneven across organisations.

    Starlight Cyber Threat Intelligence Malaysia
    starlightintel.com ↗ starlightcti.com ↗
    Data Contributor · Pages 10–11 · Ransomware & Threat Actor Intelligence
    Special Thanks: Threat Intelligence Partner

    Starlight Intelligence:
    Ransomware & Threat Actor Data

    Pages 10 and 11 of the Malaysia cybersecurity threat report 2025 were made possible through the exclusive contribution of Starlight Intelligence, a premier Malaysian cybersecurity firm and NACSA-licensed service provider, recognised as a Malaysia Digital Status company for its innovation in Artificial Intelligence. Starlight leverages its proprietary Starlight Neural Networks (SNN) to generate high-fidelity threat intelligence and assess risks with precision.

    Founded in 2019 and BSI-certified to ISO 27001:2022, Starlight Intelligence bridges the gap between high-end protection and budgetary constraints, delivering locally-developed, cost-effective cybersecurity solutions that directly serve the Malaysian market. Their meticulous research and data generosity have significantly elevated the quality of this report’s threat actor and ransomware analysis.

    This report was meticulously prepared with Starlight Intelligence’s ransomware and threat actor data, giving Malaysian organisations an unprecedented window into exactly who is targeting them and how.

    Malaysia Ransomware Statistics (Starlight Data)

    The Malaysia cybersecurity threat report 2025 confirms ransomware activity targeting Malaysia has escalated sharply. Starlight’s data reveals a more than doubling of incidents from 2023 to 2025, a trend that demands immediate attention from every sector.

    2023 20 Incidents
    →
    2024 21 Incidents
    →
    2025 45 Incidents +114% YoY

    Top 10 Ransomware Threat Actors in Malaysia

    Starlight Intelligence tracks the most active ransomware groups operating against Malaysian targets. LockBit continues to dominate, while newer actors like Qilin and Akira are rapidly gaining ground.

    Threat ActorIncidents
    LockBit 3.017
    Qilin13
    Direwolf9
    Ransomhub6
    Obscura5
    Threat ActorIncidents
    Hunter4
    Babuk24
    TheGentlemen4
    Akira3
    Lv2

    Key Threat Actor Profiles

    Threat ActorAffiliations / OriginsStrategic Focus & Tactics
    LockBit (3.0/5.0)Global RaaS / Eastern EuropeUses “invisible mode” and API harvesting; targets manufacturing sector
    Qilin (Agenda)Russia-linked RaaSUses Rust language for speed; primary threat to aviation and healthcare
    DirewolfSE Asia (Human-operated)Specialised in double-extortion against tech and legal sectors
    INDOHAXSECIndonesia-based HacktivistIdeologically motivated; targets government for data leaks
    AkiraGlobal RaaSFocuses on Windows and ESXi; highly prolific in late 2025

    2026 Outlook: AI as a Double-Edged Sword

    Starlight Intelligence’s forward-looking analysis warns that AI is no longer a future concept. It is a functional weapon already deployed by adversaries and defenders alike in the 2026 threat landscape.

    ⚔️ Offensive AI Threats
    • High-value Business Email Compromise (BEC) now uses AI-generated voice and video to impersonate CEOs
    • NLP used to craft “Manglish” (Malaysian English) localised phishing lures that bypass traditional filters
    • Strains like LAMEHUG and PROMPTFLUX use LLM interactions to re-generate source code on execution, making them invisible to signature-based EDR
    ?️ Defensive AI Capabilities
    • AI agents now handle the “volume problem”, triaging thousands of alerts to identify true positives in milliseconds
    • Shifting from detection to anticipation by identifying pattern anomalies before a breach occurs

    High-Risk Sectors for 2026 (Starlight Forecast)

    ?

    Healthcare

    Primary target due to critical nature of patient records and zero downtime tolerance

    ⚙️

    Manufacturing & Energy

    Increasing risk from IT-OT convergence; corporate breaches can trigger physical production halts

    ?️

    Critical Infrastructure

    Targeted by state-sponsored actors to sow economic chaos and disrupt essential public services

    ⭐

    Thank You, Starlight Intelligence

    Simply Data extends its deepest gratitude to the entire team at Starlight Intelligence for their exceptional contribution of Malaysia-specific ransomware statistics, threat actor profiles, and forward-looking intelligence to this report. Your commitment to building a safer Malaysian cyberspace through open collaboration and knowledge-sharing is an inspiration to the entire regional security community.

    Starlight Intelligence’s proprietary Neural Network-driven analysis has given Malaysian organisations a level of adversary insight that is rare, actionable, and genuinely life-saving for businesses navigating the 2025–2026 threat landscape.

    ? starlightintel.com ? starlightcti.com
    Flawtrack ASM and Dark Web Monitoring
    flawtrack.com ↗
    Data Contributor · Pages 12–13 · External Exposure & Dark Web Intelligence
    Special Thanks: ASM & Dark Web Intelligence Partner

    Flawtrack:
    External Exposure & Dark Web Observations

    Pages 12 and 13 of the Malaysia cybersecurity threat report 2025 are powered exclusively by data from Flawtrack’s Intelligence Platform, covering 2025 statistics on external exposure and dark web activity targeting Malaysian organisations. Flawtrack’s Attack Surface Management (ASM) and Dark Web Monitoring capabilities provide a critical outside-in view of Malaysia’s digital exposure, intelligence that internal SOC telemetry alone cannot capture.

    To complement the Malaysia cybersecurity threat report 2025 internal SOC findings, we collaborated with Flawtrack to analyse external exposure and dark web intelligence trends observed across Malaysian organisations. The result is one of the most complete pictures of Malaysian cyber exposure ever published.

    Overall Exposure Statistics: Malaysia 2025

    44,593 Malaysian Domains Exposed
    5,776,612 Total Credentials Compromised
    2,408,402 Unique Users Affected
    3,980 Government Domains (.gov.my)
    21,451 Commercial Domains (.com.my)
    5,404 Educational Domains (.edu.my)

    Sector Breakdown: Exposed Domains and Credentials

    The Malaysia cybersecurity threat report 2025 shows the Commercial sector leads in absolute credential volume, but Government’s exposure per domain is particularly alarming given the sensitivity of data held within those environments.

    SectorDomains AffectedTotal CredentialsUnique Users% of Total
    Commercial21,4512,249,263973,99838.9%
    Government3,9801,619,708712,99628.0%
    Education5,4041,013,829317,85917.5%
    Other13,753893,812403,54915.5%

    Compromised Endpoint Breakdown by Sector

    SectorEndpointsCredentialsUnique Users
    Commercial499,2651,909,848158,913
    Government460,8251,832,196159,825
    Education189,339918,72472,024
    Other182,867702,94858,135

    Compromised Device Operating System Distribution

    The Malaysia cybersecurity threat report 2025 shows Windows 10 dominates the compromised device landscape at 71.3%, a significant concern given Microsoft’s end-of-support timeline. Windows 11 devices yield the highest average credentials per device at 250, suggesting that even newer systems are heavily compromised once stealer malware takes hold.

    Operating SystemDevicesCredentials% of DevicesAvg Creds/Device
    Windows 1054,9948,307,51171.3%151
    Windows 1117,1854,297,12822.3%250
    Other3,103557,5064.0%180
    Windows 71,787143,6442.3%80
    Windows Server175,673<0.1%334

    Dark Web Marketplace Activity: Key Findings

    ?️
    Active Marketplace Trading

    The Malaysia cybersecurity threat report 2025 reveals Malaysian credentials are actively traded on underground marketplaces and forums, with fresh dumps appearing daily from large-scale infostealer campaigns.

    ?
    Premium Government & Banking Credentials

    Government and banking credentials command premium prices in dark web listings, reflecting high-value access to sensitive systems and financial infrastructure.

    ?
    Combo Lists Redistributed at Scale

    Combo lists containing Malaysian email addresses are frequently updated and redistributed across hacker forums, amplifying the reach of each breach.

    ?
    Stealer Logs Sold in Bulk

    Stealer logs from Malaysian endpoints, containing saved passwords, session cookies, and autofill data, bundled and sold in bulk packages, enabling low-skill attackers to execute large-scale account takeover campaigns.

    ?
    Credential Reuse Amplification

    As highlighted in the Malaysia cybersecurity threat report 2025, credential reuse across services significantly amplifies the impact of each individual breach. A single leaked password can unlock email, cloud storage, HR systems, and financial platforms simultaneously.

    ?️

    Thank You, Flawtrack

    Simply Data sincerely thanks the Flawtrack team for their outstanding contribution of Attack Surface Management and Dark Web Monitoring intelligence to this report. The external exposure data covering 44,593 Malaysian domains and 5.77 million compromised credentials represents a level of visibility that is uniquely valuable, and that no internal monitoring capability alone could provide.

    Flawtrack’s dedication to tracking Malaysia’s external threat surface and dark web exposure in real-time is a critical service to the nation’s cybersecurity ecosystem. We are proud to have Flawtrack as a data partner and look forward to continuing this collaboration in protecting Malaysian organisations from outside-in threats.

    ? flawtrack.com
    Malaysia Cybersecurity Threat Report 2025 SIEM SOC Malaysia MITRE ATT&CK Credential Compromise Microsoft 365 Security Dark Web Simply Data IoT Security Identity Threat Detection Cybersecurity Malaysia 2025
    Forward-Looking Analysis

    Prediction & Recommendations
    for 2026

    Building on the Malaysia cybersecurity threat report 2025 data and intelligence from Simply Data SOC, Starlight Intelligence, and Flawtrack, three primary threat categories are forecast to define the 2026 Malaysian cyber landscape.

    ? AI Agents Security Risk
    • AI agent and AI-driven workflow adoption will introduce new attack vectors not fully addressed by traditional application security controls
    • Prompt injection attacks are expected to increase, enabling attackers to manipulate agent behaviour to extract API keys, credentials, system prompts, or internal logic
    • Agent-to-agent phishing, where malicious agents impersonate trusted agents or inject malicious instructions into multi-agent workflows, which is likely to emerge as a viable technique in automated business processes
    Recommendations

    Implement strict input validation and output filtering for AI agents. Enforce least-privilege access for APIs and secrets, and isolate agent execution environments. Secrets should never be embedded directly in prompts or agent memory. Continuous monitoring of agent behaviour, strong authentication between agents, and human-in-the-loop controls for high-risk actions are critical to reducing the blast radius of successful prompt manipulation.

    ? Supply Chain Risk
    • Supply chain risk will remain significant and persistent in 2026 as organisations continue to rely on interconnected SaaS platforms, cloud services, and third-party integrations
    • Compromises affecting vendors, software dependencies, or trusted external services are expected to continue enabling indirect access to enterprise environments, including identity systems such as Microsoft 365
    Recommendations

    Strengthen third-party risk management by integrating threat intelligence feeds, attack surface managem

    to exposed assets, abused doid=”recommendations”>
    Actionable Recommendations

    What Malaysian Organisations Must Do Now

    Based on the Malaysia cybersecurity threat report 2025, Simply Data recommends four immediate priorities for Malaysian organisations.

    ?

    Implement Phishing-Resistant MFA Across All M365 Accounts

    Password spraying and credential theft are the leading attack vectors. Hardware tokens or FIDO2 keys should be mandatory for all privileged accounts and progressively rolled out to all users. Conditional Access policies must enforce MFA from every location, including trusted networks.

    ?️

    Deploy Identity Threat Detection & Response (ITDR)

    Traditional EDR is insufficient when the primary attack surface is the identity layer. ITDR solutions provide continuous monitoring of identity behaviours, detecting anomalous logins, privilege escalations, and directory object changes before they progress to full compromise.

    ?

    Conduct a Privilege Access Review Now

    The Malaysia cybersecurity threat report 2025 identifies accounts with non-expiring passwords, excessive admin rights, and immediate elevation of new accounts as persistent findings. A structured Privileged Access Management (PAM) programme with regular review cycles is essential to closing the governance gaps attackers rely on.

    ?

    Review and Restrict Third-Party OAuth Permissions in M365

    Compromised external applications and OAuth tokens represent a growing supply chain attack vector. Organisations should audit all connected applications, revoke unnecessary permissions, and implement Microsoft Defender for Cloud Apps to monitor OAuth abuse in real time.

    ?

    Adopt IoT-Specific Network Segmentation Controls

    IoT-related threats are forecast to increase in 2026, a key finding of the Malaysia cybersecurity threat report 2025. Organisations should segment IoT device traffic from core business systems using dedicated VLANs, enforce continuous traffic inspection, and maintain an up-to-date device inventory. Poorly secured IoT devices remain low-effort entry points for network-based attacks.

    ?️

    Monitor Dark Web Exposure Continuously

    Given the volume of Malaysian credentials documented in the Malaysia cybersecurity threat report 2025 trading on underground markets, dark web monitoring should be a standard component of any organisation’s threat intelligence programme. Early detection of leaked credentials enables proactive password resets and account lockdowns before adversaries can exploit them.

    ?

    Engage a 24/7 Managed SOC with Malaysian Threat Context

    The volume of alerts in the Malaysia cybersecurity threat report 2025 (12.4 million in 2025) is beyond the capacity of most internal security teams to triage effectively. A managed SOC with deep understanding of the Malaysian threat landscape, enriched threat intelligence, and 24/7 operational capability is the most effective way to reduce attacker dwell time and incident escalation rate.

    A Collaborative Intelligence Report

    The Malaysia cybersecurity threat report 2025 represents a unique three-way collaboration between Simply Data, Starlight Intelligence, and Flawtrack, combining internal SOC telemetry, ransomware & threat actor intelligence, and external attack surface visibility into one unified view of Malaysia’s cyber threat landscape. We are immensely grateful to both partners for making this the most comprehensive Malaysia threat report ever published.

    Starlight Cyber Threat Intelligence Malaysia × Flawtrack ASM and Dark Web Monitoring
    Simply Data
    /container
    Intelligence Briefing

    Want the Full Picture?

    Access the complete 40-page 2025 Malaysia Cybersecurity Threat Report — packed with incident breakdowns, threat actor profiles, sector-specific risk data, and actionable defence recommendations for Malaysian businesses.

    ✅

    Download Starting!

    Thank you. If your download doesn’t start automatically, click below.

    ⬇ Download Report (PDF)

    Complete the form to download

    Fill in your details below. Your report will download automatically after submission. To protect your business from the threats highlighted in this report, consider engaging a local cybersecurity company in Malaysia with proven SOC and VAPT capabilities. To protect your business from the threats highlighted in this report, consider engaging a local cybersecurity company in Malaysia with proven SOC and VAPT capabilities.

    — Select Industry — Finance & Insurance Government / Public Sector Technology & IT Healthcare Education Manufacturing Logistics & Supply Chain Energy & Utilities Media & Entertainment Property Developers Large Conglomerate Datacentre Provider Other
    (function() { var CF7_API = ‘https://www.simplydata.com.my/wp-json/contact-form-7/v1/contact-forms/26939/feedback’; var PDF_URL = ‘https://www.simplydata.com.my/wp-content/uploads/2026/02/simply-data-malaysia-threat-report-2025.pdf’;function sdSubmit(e) { e.preventDefault(); var form = document.getElementById(‘sd25-dl-form’); var btn = document.getElementById(‘sd25-btn’); var msgEl = document.getElementById(‘sd25-msg’);var name = (form.querySelector(‘[name=”your-name”]’).value || ”).trim(); var company = (form.querySelector(‘[name=”company-name”]’).value || ”).trim(); var jobtitle = (form.querySelector(‘[name=”your-jobtitle”]’).value || ”).trim(); var industry = (form.querySelector(‘[name=”industry”]’).value || ”).trim(); var email = (form.querySelector(‘[name=”your-email”]’).value || ”).trim(); var phone = (form.querySelector(‘[name=”your-phone”]’).value || ”).trim(); var accept = form.querySelector(‘[name=”acceptance-368″]’).checked;// Validate if (!name || !company || !jobtitle || !industry || !email || !phone) { msgEl.className = ‘sd25-form-msg error’; msgEl.textContent = ‘Please fill in all required fields.’; return; } if (!/^[^@]+@[^@]+.[^@]+$/.test(email)) { msgEl.className = ‘sd25-form-msg error’; msgEl.textContent = ‘Please enter a valid email address.’; return; } if (!accept) { msgEl.className = ‘sd25-form-msg error’; msgEl.textContent = ‘Please accept the Privacy Policy and Terms & Conditions.’; return; }btn.disabled = true; btn.textContent = ‘Submitting…’; msgEl.className = ‘sd25-form-msg’; msgEl.style.display = ‘none’;var fd = new FormData(); fd.append(‘_wpcf7’, ‘26939’); fd.append(‘_wpcf7_version’, ‘6.1.4’); fd.append(‘_wpcf7_locale’, ‘en_US’); fd.append(‘_wpcf7_unit_tag’, ‘wpcf7-f26939-sd25’); fd.append(‘_wpcf7_container_post’, ‘28446’); fd.append(‘your-name’, name); fd.append(‘company-name’, company); fd.append(‘your-jobtitle’, jobtitle); fd.append(‘your-industry’, industry); fd.append(‘your-email’, email); fd.append(‘your-phone’, phone); fd.append(‘acceptance-368’, ‘1’);// reCAPTCHA v3 — required by CF7 to pass spam filter var RCKEY = ‘6Lej5UwrAAAAAK8hNAWY3K3K4ubo9QreDH00wNZ1’; var doFetch = function(token) { if (token) { fd.append(‘_wpcf7_recaptcha_response’, token); }fetch(CF7_API, { method: ‘POST’, body: fd }) .then(function(r) { return r.json(); }) .then(function(data) { if (data.status === ‘mail_sent’) { // Hide form, show success document.getElementById(‘sd25-form-wrap’).style.display = ‘none’; document.getElementById(‘sd25-success’).classList.add(‘show’); // Auto-trigger download var a = document.createElement(‘a’); a.href = PDF_URL; a.download = ‘Simply-Data-Malaysia-Threat-Report-2025.pdf’; a.target = ‘_blank’; document.body.appendChild(a); a.click(); setTimeout(function() { document.body.removeChild(a); }, 1000); } else { var err = ‘Submission failed. Please try again.’; if (data.invalid_fields && data.invalid_fields.length) { err = data.invalid_fields.map(function(f) { return f.message; }).join(‘ ‘); } else if (data.message) { err = data.message; } msgEl.className = ‘sd25-form-msg error’; msgEl.textContent = err; btn.disabled = false; btn.textContent = ‘⬇ Download Full Report’; } }) .catch(function() { msgEl.className = ‘sd25-form-msg error’; msgEl.textContent = ‘Network error. Please check your connection and try again.’; btn.disabled = false; btn.textContent = ‘⬇ Download Full Report’; });}; if (typeof grecaptcha !== ‘undefined’) { grecaptcha.ready(function() { grecaptcha.execute(RCKEY, {action: ‘contactform’}) .then(function(token) { doFetch(token); }) .catch(function() { doFetch(”); }); }); } else { doFetch(”); } }// Attach submit handler — works whether script runs before or after DOM ready function sdInit() { var form = document.getElementById(‘sd25-dl-form’); if (form) { form.addEventListener(‘submit’, sdSubmit); } } if (document.readyState === ‘loading’) { document.addEventListener(‘DOMContentLoaded’, sdInit); } else { sdInit(); } })();

    What were the key findings in the 2025 Malaysia Cybersecurity Threat Report?

    The report revealed increasing ransomware targeting Malaysian SMEs and government agencies, rising phishing and social engineering attacks, and a significant skills gap in Malaysian cybersecurity teams.

    Which sectors face the highest cyber threat levels in Malaysia?

    Financial services, healthcare, government, and critical infrastructure face the most severe threats according to the report. SMEs across retail and manufacturing are also increasingly targeted.

    How should Malaysian businesses respond to the threat landscape identified in this report?

    Implement zero-trust security models, invest in SOC capabilities, conduct regular security awareness training, maintain updated backup systems, and establish incident response plans aligned with Malaysian regulatory requirements.

    • Credential Compromise
    • Cyber Threats
    • Dark Web
    • Malaysia
    • Malaysia Cybersecurity 2025
    • MITRE ATT&CK
    • Ransomware
    • SIEM
    • soc
    • Threat Report

    Post navigation

    Previous
    Next

    Search

    Categories

    • Announcements (8)
    • Cybersecurity Tips (40)
    • Industry Insights & Trends (10)
    • Regulatory & Compliance (4)
    • Service Spotlight (8)

    Recent posts

    • vulnerability assessment malaysia 1 1024x683
      Vulnerability Assessment Malaysia vs Penetration Testing: Key Differences Explained
    • what does a dfir report contain 1 1024x683
      What Does a DFIR Report Contain? Inside a Simply Data Digital Forensics Investigation
    • what does a compromise assessment report contain 1 1024x683
      What Does a Compromise Assessment Report Contain? A Complete Guide for Malaysian Organisations

    Tags

    2026 Trends AI Threats apm Certification China CCTV cloud-security Company News Compliance Compromise Assessment Cost-Benefit Analysis Credential Compromise cyber-security-act cybersecurity-malaysia Cybersecurity News Cybersecurity Spending Cyber Threats Dark Web DFIR Digital Forensics Hardware Security Hikvision Incident Response IOC IoT Security IoT VAPT iso27001 Malaysia Malaysia Cybersecurity 2025 Managed Services MITRE ATT&CK nacsa Network Security PDPA penetration-testing Ransomware ROI SIEM SME Budget SME Security soc threat-intelligence Threat Hunting Threat Report vapt Web Application Security

    Related posts

    what does a dfir report contain 1 1024x683
    Cybersecurity Tips

    What Does a DFIR Report Contain? Inside a Simply Data Digital Forensics Investigation

    May 28, 2026

    Home – What Does a DFIR Report Contain? Inside a Simply Data Digital Forensics Investigation What Is a DFIR Report? A DFIR report is the final deliverable from a Digital Forensics and Incident Response engagement. Unlike a standard IT incident report, a DFIR report is structured as forensic evidence — meaning every finding is tied […]

    what does a compromise assessment report contain 1 1024x683
    Service Spotlight

    What Does a Compromise Assessment Report Contain? A Complete Guide for Malaysian Organisations

    May 28, 2026

    Home – What Does a Compromise Assessment Report Contain? A Complete Guide for Malaysian Organisations What Is a Compromise Assessment Report? A compromise assessment report is the formal deliverable produced at the end of a Compromise Assessment engagement. It documents every suspicious activity detected across your environment during a defined observation window, the analyst’s investigation […]

    IoT penetration testing Malaysia blog thumbnail
    Cybersecurity Tips

    IoT Penetration Testing: Real Findings from 7 Enterprise IoT Devices

    April 2, 2026

    What actually happens during IoT penetration testing? Our team physically tested 7 enterprise IoT devices — CCTV, NVR, intercoms, facial recognition — and found real vulnerabilities including a live firmware extraction proof-of-concept.

    simply data logo

    Started in 2022, Simply Data is a CREST certified and NACSA Licensed (No. 20007-01 & 20007-02) Cyber Security company in Malaysia that provides cyber security services including Network & Security IT Managed Service, Security Operation Centre (SOC), Cyber Threat Intelligence, Vulnerability Assessment & Penetration Testing (VAPT) service, Application Performance Monitoring (APM) services, and more.

    • B-03A-03, 3RD Floor, Block B Setiawalk, Persiaran Wawasan, Pusat Bandar Puchong, 47100 Puchong, Selangor
    • +603 5886 2714
    • contactus@simplydata.com.my
    Quick Links
    • Home
    • About Us
    • Innovation
    • Technology Vendor Partners
    • Blog / News
    • Career Opportunities
      Hiring
    • Become a Simply Data Partner
    • Cybersecurity Readiness Assessment
    • Malaysia CyberSecurity Act 854
    CyberSecurity Services
    • Cyber - 911 - DFIR Services
    • Compromise Assessment
    • Security Operations Center (SOC)
    • Extended Threat Intelligence
    • Security Posture Assessment (SPA) Services
    • Network & Security Configuration Audit & Hardening
    • Phishing Email Simulation
    Managed Network & Security Services
    • Managed Network & Security Services
    Observability Application Performance Monitoring
    • Observability APM as a Service
    • Cloud Monitoring
    • Database Performance Monitoring
    • Web Application Monitoring
    • Synthetic Testing Monitoring
    • Real User Monitoring
    • Stress Test / Load Test – Performance Assessment
    Consultancy Services
    • NCSB Risk Assessment
    • Security BluePrint™ Consultancy Services

    © 2025 Simply Data Sdn Bhd. All rights reserved.

    • Terms & Conditions
    • Data Protection & User Privacy
    • Privacy Policy
    • Cookie Policy