Okta’s AI Security Purchase Is a Signal for Malaysian SME Owners
You’ve probably spent the last year figuring out how to use AI in your business. Maybe you run a customer service chatbot, use an AI tool to write product descriptions, or let a virtual assistant triage your emails. It feels great — until you stop to think about one awkward question: what exactly is that AI allowed to do?
That’s the exact issue that just drove Okta, one of the world’s biggest identity management companies, to acquire Permiso Security, a startup that watches what AI agents do after they’re granted access to your network. The TechCrunch report on the deal isn’t just Silicon Valley gossip. It’s a warning for Malaysian SMEs that are adopting AI without thinking about the security side.
In this post, I’ll break down what the Okta-Permiso deal actually means, why it matters for a 10-person shop in Penang or a 40-person logistics company in Johor, and the practical steps you can take today.
TL;DR: Okta bought Permiso Security to strengthen its ability to monitor AI agents and machine identities. In plain language: the big security players believe AI bots will become a target for hackers. For your SME, this means you need to review what your AI tools can access, who controls them, and how you would notice if they were misused. You don’t need a huge security budget — but you do need attention.
What This Means: AI Identities Are Now a Security Issue
When you log into your email or your accounting software, you prove you are who you say you are — often with a password and a one-time code. That’s identity management. But what about the AI chatbot on your website? It also gets a login to your customer database, your inventory system, and maybe your payment processor. That AI has an identity. Security experts call it a machine identity.
Permiso Security, which emerged from stealth in 2022, specialises in detecting attacks that use stolen or compromised identities to move through cloud infrastructure. Its founders are former FireEye executives — they know how hackers think. More importantly, Permiso introduced SandyClaw in April, a platform that tests AI agents in a sandbox to spot malicious behaviour before they are deployed. So this isn’t just about logging in anymore. It’s about watching what the AI does after it’s inside.
Okta buying Permiso means this type of monitoring is becoming part of the standard identity security market. In the future, any serious identity management product will likely include AI agent monitoring. But what does that mean for a small bakery in Kuala Lumpur that uses an AI scheduling tool? Everything, eventually. But first, you need to understand the risk.
“Your AI tools are not just software. They have access to your business. If someone takes over your AI assistant, they don’t need to steal your password — they are the password.”
How This Applies to Malaysian SMEs
Let me give you three realistic scenarios that affect Malaysian businesses right now.
Scenario one: your customer service chatbot. Many Malaysian SMEs use chatbots on WhatsApp or on their websites. The chatbot is connected to your customer database to look up order statuses or answer queries. Now ask yourself these questions: How many people have admin rights to change what the chatbot can say? Is the chatbot’s connection to your customer database protected by multi-factor authentication? If a former employee still has access to the chatbot dashboard, could they use it to pull customer mobile numbers without you noticing? These are the exact kinds of gaps that Permiso’s software hunts for. You don’t need their tool, but you need to ask the same questions.
Scenario two: your marketing AI tools. You probably use something like an AI social media scheduler or an AI email writer. These tools often request permissions to post on your behalf. Some of them store your account credentials on the tool’s server. If that tool vendor has a security lapse, a hacker could post scams from your page or send phishing emails to your customers. A Malaysian SME I know of had this happen last year — their social media account was hacked through a third-party scheduling tool. The fix wasn’t complicated. They revoked access for all third-party apps and reconnected only the essential ones.
Scenario three: your finance and operations AI. If you use AI to generate invoices or reconcile payments, that AI often has read and write access to your accounting system. What would happen if someone tricked that AI into changing a bank account number on an invoice? The Permiso approach is to monitor AI agents for suspicious behaviour — like changing transaction details when no human has asked for it. You can replicate that in a simple way by reviewing your AI tools’ activity logs every week. Ask your software provider if they keep logs of every action taken by an AI agent. If they don’t, consider switching.
Keep in mind that Malaysia’s Personal Data Protection Act (PDPA) already requires you to take reasonable steps to protect customer data. If you are processing personal data through AI agents, you need to know what those agents are doing. The National Cyber Security Agency (NACSA) has also been underlining the importance of identity and access management for businesses of all sizes. This is not a “big company only” concern.
Practical Takeaways: What to Do This Week
- List your AI tools. Write down every software you use that has access to customer data or financial data. Include chatbots, scheduling tools, and anything with “AI” in the name.
- Review the permissions. For each tool, check who has admin access. Remove people who no longer work with you. Change passwords if you’re unsure.
- Turn on multi-factor authentication (MFA) everywhere. At least for your email, your business platform, and your AI dashboards. This is non-negotiable.
- Ask your vendors about AI activity logs. Send an email to your chatbot provider and your marketing automation provider: “Do you log every action taken by the AI?” If the answer is no, you have no way to audit what the AI is doing.
- Test your own AI. Try a few unusual requests on your chatbot to see if it does anything beyond its scope. For example, ask it to give you a list of all customer phone numbers. If it cheerfully complies, you have a problem.
A Simple View of AI Risks for Common SME Tools
| AI Use Case | What It Accesses | Potential Risk |
|---|---|---|
| Customer support chatbot | Customer database, order history | Data theft if the chatbot is compromised |
| AI marketing scheduler | Social media accounts, brand identity | Hackers posting malicious content on your behalf |
| AI accounting assistant | Invoices, payment details, bank account numbers | Unauthorised changes to payment details |
| AI email auto-responder | Email inbox, contacts, attachments | Phishing emails sent from your domain |
The Bigger Picture
Okta’s decision to buy Permiso tells us that the security industry expects AI agents to multiply quickly. Every employee in your company might soon have a personal AI assistant that can read their emails, schedule meetings, and maybe even reply to clients. That means your business will have dozens of machine identities, not just one. If you don’t know who controls those identities and what they can access, you’re flying blind.
But you don’t need to wait for the next security product to come to Malaysia. The groundwork is simple: know what you have, reduce access to the minimum, and watch the activity logs. This is the same advice security professionals have been giving for years — the only difference is now the AI is in the picture. Start by owning the list of your AI tools. Then set a policy that any tool connecting to your customer data must support MFA and provide audit logs. When security vendors start selling easier solutions, you’ll be ready to adopt them because you’ve already built the habit.
The Okta-Permiso deal is not about a fancy startup. It’s about the reality that AI can be tricked into doing bad things. For a Malaysian SME, the cost of ignoring this is much higher than the cost of a few hours of attention this week.
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
