The following commentary is contributed by Fastly Area Vice President for ASEAN, Greater China, and South Korea Rachel Ler
Ask many business leaders in Malaysia where they believe their next major cyber incident will come from, and the typical answer will cite ransomware groups, state-backed threat actors or highly orchestrated phishing campaigns designed to exploit a single moment of human error. Yet, Fastly’s latest research suggests the bigger threat may already exist within their own software.
New research from Fastly reveals that software bugs contributed to 54% of cyber incidents across Asia Pacific last year, surpassing external attackers, which accounted for 43%. This marks a significant shift, showing that internal software risks are becoming more pronounced as organisations accelerate digital transformation and release software more rapidly. For Malaysian organisations, which are under growing pressure to modernise in step with the MyDIGITAL blueprint, that trade-off is increasingly difficult to ignore.
Speed without guardrails is a liability
As Malaysian organisations accelerate artificial intelligence (AI) adoption, AI-assisted software development is enabling engineering teams to build and release applications faster than ever. However, the rapid increase in AI-generated code and infrastructure changes also expands the potential for software bugs and security vulnerabilities to reach production. Fastly’s research found that many senior developers believe a significant share of AI-driven productivity gains is offset by the time spent identifying and fixing errors in AI-generated code. As a result, the challenge is no longer just delivering software quickly, but ensuring applications are built and deployed securely from the outset.
Scale amplifies self-inflicted risk
The issue is not that AI-generated code is inherently less secure. Rather, as Malaysian organisations accelerate AI adoption, tighter delivery timelines and insufficient review processes increase the risk of vulnerabilities, coding errors and misconfigurations reaching production. Under pressure to deliver quickly, development teams may prioritise speed over security.
The impact becomes even clearer at scale. Organisations with more than 10,000 employees averaged 57 cyber incidents in 2025, nearly 40% above the overall average of 40. Larger security budgets and broader tooling alone cannot compensate for weaknesses introduced during software development and release.
Malaysian organisations today operate across increasingly complex digital environments. Cloud platforms, application programming interfaces, third-party integrations and automated deployment pipelines form the backbone of their operations.
AI-powered development is accelerating the pace of change across these systems, which means that bugs, security vulnerabilities and configuration errors are more likely to slip into production if organisations fail to implement robust testing and governance practices.
The impact of those failures rarely stays contained within engineering. A single faulty deployment can trigger outages, expose sensitive data or invite regulatory scrutiny well before the team responsible has finished its post-mortem. Reputational damage and loss of customer confidence tend to follow quickly.
These incidents highlight how internal processes and decision-making gaps can become sources of exposure, even in the absence of deliberate external attacks. Simply put, internal weaknesses during production do not need to be targeted by a cybercriminal for the organisation to experience a damaging incident.
Security must live where the risk is built
Many organisations still structure cybersecurity around centralised security teams focused primarily on compliance checks, perimeter defences and incident response. Yet, the sources of modern security risk increasingly sit in source code repositories, infrastructure-as-code templates, continuous integration and delivery pipelines, and AI-enabled development workflows.
Despite that, few organisations in Malaysia have shifted security responsibilities towards platform engineering or DevOps teams, even as bugs and misconfigurations become a bigger factor in security incidents.
A more resilient operating model embeds security directly into software delivery processes. Instead of operating as a separate gatekeeping function, security teams work alongside engineering and platform teams to influence architectural decisions, tooling choices and AI adoption policies from the outset.
This also requires clearer governance. Policies governing code review, testing and deployment approval need to apply equally to AI-generated and human-written code. Under delivery pressure, these controls are often treated as optional rather than essential.
Finally, Malaysian organisations need to demarcate ownership clearly. Even among AI-first organisations, Fastly found that more than 31% grappled with opaque accountability structures, leaving uncertainty over who is responsible for incident response and risk management. Establishing clear ownership for incident response, escalation procedures and decision-making before systems go live helps turn governance from a compliance exercise into an effective operational safeguard.
Stop bolting security on and start building it in
Building security in from the outset rather than addressing vulnerabilities later is not a new concept. What has changed is the cost of overlooking it. Gartner has warned that by 2027, more than 40% of AI-related data breaches will stem from improper use of generative AI across borders.
Put another way, while Malaysian organisations are rightly accelerating digital transformation, this should not prioritise speed over resilience, especially as the nation advances the Malaysia Madani agenda and expands digital trade opportunities through regional initiatives. Furthermore, organisations, even those outside its direct scope, risk exposure to the Cyber Security Act 2024, Malaysia’s first dedicated cybersecurity legislation.
Despite the common belief that resilience slows innovation, organisations that invest in strong security and governance can adopt AI with greater confidence while maintaining development speed. Rather than relying on manual checks, automation and continuous oversight improve software quality. AI systems should also be treated as high-value assets, with strong access controls, continuous monitoring and disciplined change management throughout their lifecycle.
A truly secure-by-design approach starts well before software reaches production. Security architects and technology leaders should be involved early in the development process, helping to guide how AI is embedded into applications, platforms and delivery pipelines before design decisions become costly technical debt or introduce unnecessary risks.
Resilience and speed are not a trade-off
AI is helping Malaysian organisations develop and deploy software faster, but it is also making weaknesses in internal processes more visible and costly to fix. Keeping security separate from engineering while relying mainly on perimeter defences is no longer enough as businesses accelerate AI adoption.
A stronger approach is to treat software flaws and coding mistakes as security risks from the start. Embedding security into engineering workflows and strengthening resilience throughout the software development lifecycle enables organisations to innovate with confidence without slowing delivery.
The real test for Malaysian organisations won’t be how quickly they adopt AI or release new digital services. It will be a question of whether they can do so without compromising resilience.
The organisations that succeed won’t simply build faster. They’ll build securely enough to keep innovating with confidence. Those that continue to treat security as something to bolt on after development risk turning innovation into their greatest source of exposure.





