AI Security Arms Race: What Malaysian SMEs Must Do Now

AI Security Arms Race: What Malaysian SMEs Must Do Now — featured image

by

AI Is Making Software Safer—and Cyber Risk More Complicated

If you run a Malaysian SME, the most important part of the current AI security debate is not whether governments can still use hacking tools. It is what happens when artificial intelligence changes the balance between people attacking your systems and people defending them.

A recent TechCrunch report examines an argument from cryptography professor Matthew Green: AI could become so effective at finding software weaknesses that companies may eventually patch bugs faster and make systems harder to exploit. That sounds positive for your business. However, the same technology can also help attackers discover weaknesses, create convincing scams and exploit mistakes in software built quickly with AI tools.

For a business with between one and 50 employees, security is no longer only an IT department issue. Your accounting system, customer database, WhatsApp conversations, online banking access, cloud documents and point-of-sale tools may all be connected. A single compromised password can affect operations, customers and your reputation.

What Happened

The debate began after Green published a widely discussed blog post and a thread on X about the future of government hacking. His concern was that if AI helps software companies find and fix vulnerabilities at an unprecedented scale, law-enforcement and intelligence agencies may have fewer undisclosed bugs—often called zero-days—to use when legally targeting criminals.

Historically, governments have argued that strong encryption can make investigations more difficult. The “going dark” argument became prominent after former FBI director James Comey discussed the challenge of encrypted communications in 2014. Services such as Signal, WhatsApp and Apple’s iMessage use end-to-end encryption, while modern devices increasingly encrypt stored data by default.

Instead of demanding universal backdoors, governments have often relied on purchasing or developing hacking tools that exploit weaknesses in devices. Green’s argument is that if those weaknesses become scarce, some governments may again call for exceptional access or built-in backdoors. Privacy advocates warn that a backdoor designed for authorities can eventually be abused by criminals, hostile states or insiders.

Experts interviewed by TechCrunch did not fully agree. Some believe AI will make vulnerabilities easier to find but that valuable, complex flaws will remain difficult. Others argue that AI will help both defenders and offensive researchers. The report also highlights an important practical issue: discovering a bug does not guarantee that a vendor can patch it quickly. Modern software may depend on many suppliers, integrations and older systems.

For your business, the central lesson is simple: do not assume that new AI security features will automatically protect you. Your strongest defence remains disciplined access control, timely updates, reliable backups and staff who know how to verify unusual requests.

Why This Matters for Malaysian SMEs

Many Malaysian SMEs use a mixture of cloud accounting, e-commerce platforms, payroll applications, customer relationship tools, shared drives and messaging apps. This makes productivity easier, but it also creates a wider “attack surface”—the collection of accounts, devices, applications and connections that an attacker may try to abuse.

Consider a small wholesale business in Shah Alam. A staff member receives an email that appears to come from a supplier asking for a bank account change. At the same time, an attacker has gained access to a shared mailbox through a reused password. No sophisticated zero-day is required. The real weakness is poor identity protection and the assumption that a familiar email thread is trustworthy.

Or consider a Malaysian clinic, tuition centre or professional-services firm using AI to draft documents and answer customer questions. If staff paste confidential customer information into an unapproved AI service, the problem may not be a software vulnerability. It may be uncontrolled data handling. You need clear rules about what information can be entered into AI tools, who can access generated files and how long records should be retained.

The issue also matters when you build or customise software. AI coding assistants can help you create a booking form, inventory dashboard or internal automation faster. But generated code can contain insecure settings, weak authentication or unsafe handling of uploaded files. A fast prototype should not be treated as a production system until someone tests it, updates its dependencies and removes unnecessary access.

Business area Practical risk Action you can take
Email and messaging Impersonation, account takeover and payment redirection Enable multi-factor authentication and verify payment changes using a separate channel
Cloud applications Excessive permissions or exposed files Review user access monthly and remove accounts when staff leave
AI tools Confidential data being shared without approval Create a written list of information that must never be uploaded
Custom software AI-generated code containing security weaknesses Use code review, dependency updates and basic security testing before launch
Backups Ransomware affecting both live files and backups Keep a separate backup that attackers cannot modify through normal staff accounts

What You Should Do This Month

Start with your most important accounts. List your email administrator, domain registrar, cloud storage, accounting platform, online banking access and customer database. Confirm that each account has a unique password, multi-factor authentication and a named owner. Avoid sharing administrator accounts among several employees.

Next, map your business data. Identify where you store customer identification details, invoices, employee records, supplier information and intellectual property. You do not need an expensive enterprise system to begin. A simple spreadsheet can show which applications hold sensitive data and which employees can reach it.

Ask your technology providers how they handle security updates, breach notifications, data access and account recovery. Keep a record of vendor contacts. When a service experiences an outage or suspicious activity, you should know whom to call and which credentials may need to be reset.

Finally, practise a short incident response process. Decide who will disconnect an affected device, who will contact your bank, who will communicate with customers and who will preserve evidence. Test your backups by restoring a sample file. A backup that has never been tested is only an assumption.

The Bigger Picture

The AI security race will not produce a permanent winner. As AI improves vulnerability discovery and automated defence, attackers will adapt their methods. They may target human behaviour, exposed credentials, third-party suppliers and poorly configured services instead of relying only on software bugs.

The debate over government backdoors also has a direct business implication. Strong encryption protects ordinary companies from criminals, competitors and opportunistic insiders. If systems are deliberately weakened to provide special access, every user inherits additional risk. You should therefore be cautious about technology claims that promise convenience through hidden access, permanent administrator accounts or shared “master” passwords.

There is also a governance lesson. Better software security does not remove the need for responsible use of surveillance tools, transparent oversight or clear legal boundaries. For SMEs, the equivalent principle is accountability: know who can access your systems, record important changes and review whether access is still necessary.

AI may make some technical weaknesses harder to find, but it will not eliminate careless permissions, reused passwords, untrained staff or rushed processes. Your practical advantage is to reduce those everyday weaknesses now. Treat AI as a tool that can strengthen security when supervised—not as a replacement for basic controls, good judgement and preparation.

Ready to Streamline Your Operations?

Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →