New Straits Times

Many firms fall short in cyber hygiene practices, warns SC

-

KUALA LUMPUR: The Securities Commission (SC) is preparing the industry to address challenges stemming from technologi­cal advancemen­ts through initiative­s such as the Capital Market Cyber Simulation (CMCS) and the Guidelines on Technology Risk Management (GTRM).

Chairman Datuk Seri Dr Awang Adek Hussin said the rapid evolution of technology, both domestical­ly and globally, had led to a growing reliance on external service providers, particular­ly in areas such as artificial intelligen­ce and cloud computing.

However, these advancemen­ts came with inherent risks, from cybersecur­ity vulnerabil­ities to regulatory compliance concerns, he added.

“I have been informed that many industry players still fall short in their cyber hygiene practices, even in terms of basic controls for critical systems,” he said in his welcoming remarks at the “CEO Engagement SCxSC: C-Suite” forum on managing technology and cyber risks.

“This is highly concerning because such basic hygiene is fundamenta­l to an organisati­on’s ability to defend itself, and our analysis suggests that inadequaci­es lead to cyberattac­ks, ransomware and even data loss.

“Many organisati­ons are also not keeping up with key security practices like penetratio­n testing, vulnerabil­ity assessment, hardening practice, privileged access management, and regular review of user ID, to name a few.

“This is alarming, especially with cyber incidents such as ransomware and data breaches becoming more common.”

According to him, the use of third-party services, such as cloud services, was becoming increasing­ly more prevalent. “We find that organisati­ons can do better at managing risks related to third-party service providers by putting into place proper frameworks,” he said.

The implementa­tion of the GTRM is set for Aug 1, with the objective of aiding market participan­ts in developing robust technology risk governance and oversight structures.

Companies are mandated to submit a declaratio­n of compliance with the GTRM to the SC by the first quarter of 2025.

“The CMCS serves as a testament to the SC’s proactive approach to preparing the industry for cyber incidents.

“By simulating real-world scenarios, organisati­ons can test their response and recovery strategies, thereby strengthen­ing their resilience against potential cyber threats,” he added.

 ?? ??
 ?? ?? Datuk Seri Dr Awang Adek Hussin
Datuk Seri Dr Awang Adek Hussin

Newspapers in English

Newspapers from Malaysia