Data from the Kaspersky Security Network (KSN) shows that Malaysia recorded over 24 million on-device cyberattacks in 2025, with one in four users exposed to threats that can quietly compromise devices and disrupt business operations.
Originating directly from endpoints such as laptops, desktops and removable media, these infections, once embedded within everyday business devices, can weaken system reliability and increase the likelihood of downtime and financial impact if left unaddressed.
National reporting data from Malaysia Computer Emergency Response Team (MyCERT) reflect double-digit increases in malicious code, intrusion and data breach incidents between Q2 and Q3 2025, signalling emerging momentum in threat activity within a single quarter.
As Malaysia progresses with national digitalisation initiatives, including phased e-invoicing implementation and online compliance reporting, businesses across sectors are relying more heavily on digital systems to manage daily operations. From SMEs handling accounting and payroll to larger organisations coordinating cross-department workflows, device access and endpoint reliability form part of the operational foundation for businesses.
When on-device threats are left unaddressed, infections may spread beyond the initial workstation. Compromised endpoints can provide unauthorised access to internal networks, or enable lateral movement across connected systems, potentially leading to exposure of sensitive business or customer data.
An article by CyberSecurity Malaysia highlights the financial, reputational and regulatory consequences associated with data breach incidents may affect organisational resilience and stakeholder trust. Citing Gartner research, it is estimated that operational downtime may cost organisations approximately US$5,600 (RM21,806) per minute, depending on business scale and sector. In connected business environments, endpoint oversight is crucial in limiting the spread and duration of a cyberattack as well as reducing financial losses.
“The conversation around cybersecurity strategy often prioritises external defences, yet many incidents begin within day-to-day business operations. As Malaysia’s digital landscape accelerates, the resilience of individual workstations carries greater operational weight. Managing what happens inside the organisation is therefore just as important as defending against threats from outside, particularly in the context of broader operational risk management,” Adrian Hia, Managing Director for Asia Pacific at Kaspersky.
Beyond Malaysia, similar patterns are observed across Southeast Asia. Sustained digital expansion has coincided with significant local threat activity. In 2025, Vietnam recorded the highest volume of detected local incidents at over 109 million, followed by Indonesia with nearly 40 million, while Malaysia reported more than 24 million incidents during the same period.
In light of this evolving threat landscape, businesses are encouraged to strengthen endpoint-level control practices with the following measures:-
- Maintain updated operating systems and business applications to reduce exposure to known vulnerabilities.
- Implement strict control over removable media and external storage devices to limit offline malware transmission.
- Enhance employee awareness of cyber hygiene, malware threats identification and best practices for handling removable media. Kaspersky Automated Security Awareness Training (ASAP) offers targeted training on practical skills that cover all key cybersecurity topics.
- Strengthen endpoint monitoring and response capabilities to detect suspicious activity early and limit lateral movement across connected systems with solutions that integrate endpoint protection with EDR and XDR visibility, such as Kaspersky Next.
- Incorporate timely threat intelligence insights to help security teams identify emerging risks earlier and refine internal response procedures.

