Innovating technology risk management and cyber resilience within the corporate sector in Malaysia
Keywords:
Technology risk management, cyber resilience, corporate sector, InnovationAbstract
The Malaysian corporate sector operates in an increasingly digitalised environment, expanding exposure to sophisticated cyber and technology risks. Despite the issuance of five key regulatory instruments, including those from Bank Negara Malaysia, the Securities Commission, Bursa Malaysia, NACSA, and MCMC, the regulatory landscape is characterized by a complex "multi-statute architecture" with significant fragmentation in legal character and prescriptive intensity. This study aims to map these five principal instruments, compare them across analytical dimensions such as risk management approaches and reporting mechanisms, and identify points of convergence and tension to propose innovative strategies. Utilizing a doctrinal legal research design supplemented by qualitative comparative analysis, the research reveals a universal shift from prevention to proactive cyber resilience and a shared emphasis on board-level oversight. However, critical tensions persist, particularly regarding uneven treatment of emerging technologies like artificial intelligence and conflicting incident reporting timelines, which range from same-day notification to unspecified periods. These discrepancies create a heavy compliance burden and hinder coordinated national responses. Key implications suggest the urgent need for a formal inter-regulator memorandum of understanding to harmonise reporting thresholds and align regulatory expectations. Additionally, the study recommends a unified cross-sectoral framework for emerging technologies and extended third-party oversight. By addressing these gaps, Malaysia can transition from its current fragmented regime toward a coherent, resilience-based governance landscape that better safeguards market integrity and national security against evolving digital threats.










