Malaysia's AI ambitions need security built in from day one, say government and IBM leaders

By IBM

At a roundtable co-organised by GovInsider and IBM Malaysia, government and industry leaders unpacked what security, trust and interoperability require as Malaysia races toward its 2030 AI-nation target.

Malaysia wants to be an artificial intelligence (AI)-driven nation by 2030. But getting there will take more than ambition. Image: GovInsider

Malaysia wants to be an artificial intelligence (AI)-driven nation by 2030. But getting there will take more than ambition.

 

It will take data that agencies can trust, systems that can talk to each other, and security that is designed from the start, not patched in after something breaks.

 

That was the key takeaway of a fireside chat on building a secure, trusted and interoperable AI-enabled government ecosystem, held at an executive roundtable event co-organised by GovInsider and IBM Malaysia.

 

Moderated by Dr Nuraini Muhammad Naim, Head of the Clinical Research Centre at Hospital Sungai Buloh, Ministry of Health, the conversation brought together Mohd Firdaus Bin Mohamed Khairi, Senior Assistant Secretary at the Digital Incubator Division, Ministry of Digital, and Sourabh Mallick, ASEAN Technical Sales Leader for Data Security and Quantum Safe at IBM.

Security can't be an afterthought

 

Firdaus set out the starting point, which is that agencies need quality, well-governed data before interoperability is even possible.

 

He pointed to Malaysia's data dictionary for the public sector as a head start, which serves as a common reference that lets agencies' systems speak a shared language.

 

Sourabh elaborated on where things tend to go wrong after that.

 

AI initiatives, he said, are usually owned by business users rather than security teams, and only reach security "as part of the clearance" process. By this point, the system has already been built.

 

"They get shocked that they haven't considered security at all," he said, "and then they blame the security team for delaying things."

 

Especially for governments, he highlighted the stakes are different because citizens hand over health, financial and other personal data on the assumption that agencies will protect it.

 

The lesson was to infuse security into the earliest planning and design stages, treat content safety as part of the core design rather than a bolt-on, and set clear AI governance around what data a system touches and why.

 

Cross-agency collaboration needs the same discipline, he added, sharing only what is required for a given purpose, not everything an agency holds.

Sharing data without the big rebuild

 

Malaysian agencies have long guarded their own data, even from each other, Firdaus admitted.

 

He recalled how, during his time at a state digital office in the Covid-19 pandemic, divisions within the same organisation were reluctant to share data internally, let alone across ministries.

 

The government's answer, he said, was the Data Sharing Act 2025 to push for agencies to first agree on common ground before deciding what and how to share.

 

Sourabh's advice for agencies starting that journey was not to attempt a wholesale rebuild of decades-old systems.

 

"Government isn't like a startup," he said. "We're talking about technology that's been in place for 15 years or more, not two or five."

 

Rather than a big bang transformation, he recommended wrapping legacy applications in application programming interfaces (APIs), agreeing on a common data model, and sharing strictly on a need-to-know basis.

 

"If I want to apply for a credit card, all I need to share is my credit score and not my balance across every bank I have," he said.

 

He pointed to Singapore's MyInfo and SGFinDex as examples of this principle in practice.

 

These are shared infrastructure that releases only the specific data another party is authorised to see, through secured APIs rather than manual document transfers.

 

Firdaus added a related point on digital sovereignty, which was that control matters more than location.

 

Malaysia doesn't need every dataset sitting on domestic servers, he said, adding that a hybrid approach can work, provided the security around it is properly designed wherever the data lives.

Preparing for the quantum shift

 

On quantum-safe cryptography, Sourabh said: "Accept this as a risk first as that's the most important thing."

 

From there, he laid out a sequence of steps for agencies to follow.

 

First, appoint someone to own the problem full-time rather than folding it into an existing security role. Second, run a discovery and inventory of every cryptographic system in use.

 

Then, prioritise based on confidentiality, integrity and availability, and on how long the underlying data needs protecting. Lastly, build crypto-agility so systems can adapt as new algorithms and threats emerge, backed by governance aligned to both local regulations and guidelines.

 

He framed AI and quantum readiness as leadership and culture challenges as much as technical ones, urging organisations to "take it as a strategy for the future, not just an IT initiative," with procurement, governance and software development teams all playing a part alongside security.

 

Just as organisations run phishing-awareness drills, he suggested similar campaigns for AI and quantum safety, paired with sustained investment in local talent instead of outsourcing.

 

Firdaus echoed the same theme from the government side. Leaders need to embrace change themselves first, then bring their people along with clear messaging and a proper change management plan.

 

Asked what needs to happen next, Firdaus called for agencies to agree on common ground and priority use cases before scaling anything up.

 

Sourabh highlighted the importance of educating the organisation, building a phased roadmap, investing in local talent, getting AI-ready data and governance foundations right, and start talking to vendors as soon as possible.

 

The speakers agreed that Malaysia's 2030 ambition will need sustained, close collaboration between government, industry and the wider digital ecosystem; and not a one-off push.

 

Read also: Malaysia wants to be AI-ready by 2030. First, it has to own its digital future, June 30, 2026