Urgent.News

What's breaking now, across thousands of outlets.

Tech

Cybersecurity must go hand in hand with cyber resilience

LETTER: FOR years, our approach to digital vulnerability has been straightforward: secure the perimeter, authenticate users, encrypt data and pass compliance audits.

Cybersecurity must go hand in hand with cyber resilience

For years, the approach to digital vulnerability has been simple: secure the perimeter, verify users, encrypt information and meet compliance standards. However, incidents still happen, not due to insufficient security measures but because we often mix cybersecurity with cyber resilience. An organization can possess numerous certifications and employ robust security controls yet still experience significant disruption when a crucial system or dependency fails.

Estonia provided an early warning. In 2007, a prolonged cyberattack damaged government, banking, and media services, illustrating how digital reliance can transform a cyber incident into a disruption of fundamental societal functions. Each organization may seem secure within its own domain, but its ability to function relies on external systems outside its control.

A failure at one point in the ecosystem can thus spread across organizations and sectors. Cyber resilience entails designing systems and institutions to continue operating despite any disruption. Malaysia has bolstered its cybersecurity legislation, institutions, and regulatory frameworks, establishing a crucial foundation. However, compliance frameworks primarily query whether required controls are in place.

They do not, on their own, address the question resilience demands: what happens when those controls fail, a supplier ceases operation, or a critical service becomes unavailable? This is significant as our nation becomes increasingly dependent on interconnected and digitalized critical infrastructure across government, healthcare, finance, transportation, energy, and other essential services.

Therefore, we must ensure that a failure in one system does not turn into a failure across the entire ecosystem. When the next major disruption occurs, whether due to a cyber attack, human error, software failure, or technical breakdown, will hospitals continue to treat patients? Will airports continue to manage passengers? Will banks continue to transfer money?

Will government agencies remain able to communicate with citizens? These are not merely cybersecurity questions. They are questions of societal resilience. The next phase of digital development must be resilience by design. Professor Dr Selvakumar Manickam, Director of the Cybersecurity Research Centre at Universiti Sains Malaysia, states that these views are his own and do not necessarily reflect those of the New Straits Times.

Written by urgent.news from New Straits Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at nst.com.my →

More in Tech

More from Tuesday 25 August →