Breaking News

How Malaysian Businesses Can Protect Corporate Data from Leaks, Fraud, and Employee Mistakes

Francis Yeoh, Country Director at SearchInform Malaysia, reveals how local companies can protect themselves from data leaks, human error, internal fraud and other insider risks, posing a threat to data security.

Malaysia’s digital economy is growing rapidly, and so is the responsibility of businesses to protect their information assets. The business impact of data-related incidents is significant. In 2025, the average cost of a data breach in Malaysia reached around RM3.2 million, making data protection not only a cybersecurity issue but also a matter of business resilience.

In this interview, Francis Yeoh, Country Director at SearchInform Malaysia, explains where internal risks actually come from, how they are detected in practice, and which measures work for local businesses.

What risks threaten the cyber resilience of Malaysian businesses?

There are two types of risks: external and internal ones. External risks include viruses, hacker attacks, DDoS attacks, social engineering, and other harmful activities coming from outside. Internal risks include those originating from employees. The consequences of these risks are often underestimated, as external ones remain in the focus of public attention. However, the situation is slightly changing as internal threats are coming to the fore. In practice, we usually divide internal risks into five major groups:

1. Data leaks: leakage of sensitive corporate data, such as trade secrets and proprietary know-how, customer databases, financial records, and personal data;

2. Corporate fraud: document forgery, manipulation of commercial offers, theft, kickbacks, side-business conflict of interest.

3. Risky user behaviour: use of work devices for unrelated activities, downloading suspicious files, using shadow IT or visits to risky websites or use of unapproved cloud services.

4. Misuse of working hours and corporate resources, which can reduce productivity and lead to financial losses.

5. Internal conflicts and discipline abuse, preparation for resignation and other behavioural signals that may indicate increased risk.

These risks may look different, but they have one thing in common: they originate inside the organisation and can remain unnoticed without proper internal threat detection and prevention tools.

Can you provide some real-life examples/use cases of such incidents from customers’ practice and how they were prevented?

An illustrative case of data leak prevention occurred at a manufacturing company. A project manager attempted to upload a trove of work documents to his personal cloud storage. Our protective system blocked the operation and notified the information security specialist regarding the incident. What’s more, the system triggered another suspicious activity – the employee used to spend a lot of time on social networks. During the thorough investigation of user activity on the social network, it was revealed that the manager got in touch with the company’s market competitors and copied data for its ongoing resale to leak it to the market competitor. That’s why he attempted to upload secret data to his personal cloud storage.

Let’s proceed with a corporate fraud case. The protective system detected suspicious messaging based on the security policy. The investigation revealed that a procurement department employee discussed a deferment in payment for the rental of special equipment with an external contact. However, the company had always paid the rental within the agreed term. During the investigation, it was revealed that the employee established a side company and rented the equipment; later, he subleased this equipment to his employer at an inflated price.

I also mentioned productivity issues. The core risk in this regard is systematic idleness, which leads to both direct and indirect loss of money. I recall the case when five specialists of the IT department of one of our customers used to spend five hours per day on irrelevant activities, such as streaming videos, online shopping and gaming. Such inefficiency leads to direct financial losses, caused by inefficient waste of paid working hours. In the case of this company, due to employees’ misallocation of working time, the company lost MYR 37,500 per month. What’s more, such behaviour demotivates other team members and affects overall productivity.

Besides, there are also less obvious use cases for DLP system implementation. For example, one company used the Next-Gen DLP by SearchInform system to evaluate the effectiveness of its IT tools and discovered that many licensed applications were barely being used or weren’t used at all, despite high subscription costs. Without affecting productivity, the company reduced expenses by thousands of MYR per month.

So, in order to detect and prevent such threats, companies are required to implement specific protective systems?

Yes, exactly. The key measure for ensuring protection is the implementation of protective solutions, especially DCAP&DLP class systems. SearchInform self-developed protective systems enable the mitigation of threats posed to corporate security. Our team has been operating in the sphere of information security for more than 20 years. We work across the MENA, LATAM, and CIS regions, and since 2026 we have also expanded into Vietnam, Malaysia, and Indonesia. We’ve been operating in SEA, including Malaysia, for several years, and now we are opening a local office in Kuala Lumpur to be closer to customers and expand our partner network.

Our core principle has always been to cooperate closely with our customers. This enabled us to proactively respond to arising threats and fine-tune solutions in accordance with practical requirements of customers from all spheres of business activity.

Our flagship product, Risk Monitor, is the next-generation DLP system designed for comprehensive business protection. It helps customers to prevent the leakage of valuable and confidential information, safeguard against corporate fraud, document forgery, theft, and unfair competition, as well as to combat lobbying efforts.

Malaysia is strengthening its data protection and cyber resilience agenda. How does SearchInform support this direction?

Malaysia’s Cyber Security Strategy 2020-2024 already highlighted that insider threats remain a significant cybersecurity risk to organisations – and this was an important signal for businesses. Currently, numerous regulations aimed at ensuring data protection are coming into force or have yet to be implemented. These include Malaysia’s Personal Data Protection Act, Bank Negara Malaysia’s Risk Management in Technology framework, and other sector-specific regulations. Our products help organisations meet data protection and information security requirements, including these major acts, and ensure reliable protection against internal threats.

How do you support your customers and partners?

To ensure comprehensive support for our partners and customers at all steps and stages, we decided to establish a local representative office in Malaysia. Our local representative office will provide:

1) Pre-sales and sales support for partners;

2) Assistance with customer deployments;

3) User and partner training;

4) Local technical support;

5) Marketing and PR promotion.

Customers will benefit from the system from day one, while partners gain opportunities for long-term partnerships and support across all processes.

Which practical measures should companies take to protect against internal threats? Please share some practical advice in conclusion.

First, companies should remember that information security is part of corporate culture. It is not only the responsibility of the IT department. Every employee who works with data must understand its value.

Second, companies should classify information. It is important to know which data is confidential, where it is stored and who should have access to it.

Third, access rights should follow the principle of necessity. Employees should have access only to the data they need for their work.

Fourth, companies should control channels through which information can leave the organisation: email, messengers, cloud services, printers, removable devices and web uploads.

Fifth, companies should implement technical tools such as antivirus or EDR, DLP, DCAP and user activity monitoring.

Finally, companies should review incidents regularly. Security policies must reflect real business processes, not only formal requirements.

For Malaysian businesses, this approach is especially important now. Digitalisation creates new opportunities, but it also increases the value of data. Companies that protect their internal information today will be better prepared for tomorrow’s risks.

This press release has also been published on VRITIMES

Leave a Reply

Your email address will not be published. Required fields are marked *

*

*

CAPTCHA