Biometric Systems Flagged As High-Risk In Southeast Asia

Kaspersky’s latest ICS CERT analysis shows that biometric systems used for identity verification and access control remain a high-risk category globally, with 27.2% of systems experiencing cyberattacks.

In Southeast Asia (SEA), the exposure rate is similarly high at 23.7%, highlighting ongoing vulnerabilities across multiple threat vectors.

Malaysia is seeing increasing adoption of biometric technologies across public services, financial institutions, healthcare, transportation and energy sectors.

The domestic market was valued at US$135.27 million in 2024 and is projected to reach US$570.52 million by 2033, representing a compound annual growth rate of 15.48%.

Kaspersky found that cyber threats targeting biometric systems are most commonly delivered via the internet (9.9%) and email (8.49%), with smaller contributions from removable media and network folders.

Threats include phishing pages, malicious scripts, spyware, infected documents and worms, exploiting the networks and systems that support operational biometric infrastructure.

Simon Tung, General Manager for ASEAN and AEC at Kaspersky, said, “Much of the risk stems from the broader systems and networks, rather than the biometric components themselves. Effective cyber defence relies on understanding these interconnections, supported by threat intelligence that helps organisations preserve the integrity of their operational processes.”

The report also highlights structural weaknesses in SEA’s operational environments, including high rates of self-propagating malware such as viruses and AutoCAD-based threats.

Malaysia recorded the highest rate of email-borne threats among ICS computers at 7.51% and the second-highest spyware detections in the region after Myanmar.

To mitigate these risks, Kaspersky recommends maintaining an updated inventory of operational technology (OT) assets, conducting regular security assessments, applying timely patches, deploying endpoint detection and response (EDR) solutions, and building OT-specific cybersecurity skills across IT and operational teams.

As biometric systems become increasingly integrated into high-traffic, identity-dependent processes, strengthening both the supporting infrastructure and workforce capabilities will be essential to safeguard against evolving cyber threats.

Latest News

Must read