When Malaysian companies discuss environmental, social and governance (ESG), cybersecurity is rarely the first issue mentioned. Carbon emissions, renewable energy, diversity, board independence and responsible business practices tend to dominate the conversation.
But that is increasingly difficult to justify.
In a digital economy, a company’s sustainability and governance credentials cannot be separated from its ability to protect data, maintain critical services and withstand cyberattacks. A ransomware attack that brings a manufacturing plant to a standstill, a data breach that exposes customers’ personal information, or a compromised supplier that disrupts operations can have consequences far beyond the IT department.
They can affect employees, customers, investors, regulators and the wider community. In other words, they are ESG issues.
For Malaysia, this is becoming particularly important. Businesses are digitising at a rapid pace, from financial services and manufacturing to healthcare, telecommunications and retail. At the same time, organizations are becoming increasingly dependent on cloud platforms, third-party technology providers and interconnected supply chains.
The more digital the economy becomes, the greater the potential impact when those systems fail.
This is why cybersecurity needs to move higher up the ESG agenda — and onto the boardroom table.
The environmental connection may seem less obvious. Yet Malaysia’s growing dependence on digitally connected industrial and critical infrastructure means that a serious cyberattack could have consequences beyond lost data or unavailable systems. Attacks on operational technology can disrupt factories, utilities and other essential infrastructure, potentially resulting in physical damage, operational failures and, in extreme cases, environmental harm.
There is also a less obvious environmental cost to cybersecurity itself.
Modern organizations generate vast amounts of security data. Logs are collected, stored and analysed continuously. Backup systems are maintained, security operations centres run around the clock and increasingly sophisticated artificial intelligence tools require significant computing power.
All of this consumes energy. That does not mean companies should compromise their security controls in pursuit of sustainability targets. It does mean CISOs and technology leaders should start asking harder questions about efficiency. Are organizations retaining security data they no longer need? Are they duplicating infrastructure unnecessarily? Can cloud and security architectures be designed to deliver stronger protection with lower resource consumption?
Good cybersecurity and sustainability should not be competing objectives. Done properly, they can reinforce one another.
The social dimension is even clearer. Every day, Malaysians hand over personal information to banks, retailers, telecommunications companies, hospitals, insurers, government-related services and online platforms. Customers expect that information to be protected.
When a company fails to protect it, the consequences are not abstract. A data breach can expose people to fraud, identity theft and financial loss. It can cause anxiety and undermine confidence in digital services. For companies, the reputational damage can persist long after the technical incident has been resolved.
This is why data protection should not be treated simply as a compliance exercise. It is part of a company’s social responsibility.
The same applies to service availability. Imagine a cyberattack that prevents patients from accessing hospital systems, disrupts financial transactions or affects telecommunications services. The question is no longer how many computers were infected. The question becomes how many people were affected.
That is an ESG question. Cybersecurity is arguably most closely connected to the governance pillar. A board that takes governance seriously must understand the cyber risks facing the organization and, more importantly, know who is accountable for managing them.
It should be able to ask straightforward questions: What are our most critical systems? How quickly can we detect a major attack? How long can we operate if those systems are unavailable? Which suppliers have access to sensitive information? What would a prolonged cyber incident cost the company? And who has the authority to make critical decisions when an incident occurs?
These are no longer technical questions. They are questions of business resilience and corporate governance.
Malaysia’s regulatory landscape is moving in the same direction. The Cyber Security Act 2024 has strengthened the country’s cybersecurity framework, particularly around National Critical Information Infrastructure. Personal data protection requirements continue to place responsibilities on organizations handling personal information, while expectations around corporate governance and sustainability reporting are also evolving.
Taken together, these developments send a clear message: cybersecurity is increasingly becoming a matter of corporate accountability.
For listed companies, the stakes are even higher. Investors are not only interested in quarterly earnings. They want to know whether a company can protect its operations, reputation and long-term value.
A major cyber incident can affect all three. There is also a supply-chain problem that Malaysian companies cannot afford to overlook.
Malaysia’s economy is deeply integrated into global manufacturing and services networks. Local companies rely on international technology providers, software companies, logistics operators, cloud platforms and managed service providers.
This means a company’s cybersecurity is only as strong as the wider ecosystem on which it depends.
A vendor with weak security controls can become the entry point into an otherwise well-protected organization. Yet many companies continue to rely heavily on annual questionnaires and compliance certificates when assessing suppliers.
That approach is increasingly inadequate. Third-party risk needs to be monitored continuously, particularly where suppliers have privileged access to systems or sensitive information. Security certifications can provide useful assurance, but they are not a guarantee that a supplier will remain secure tomorrow.
This is where ESG and supply-chain governance intersect. Responsible companies need to understand not only their own risks, but also the risks created by the organizations they depend on.
The same principle applies to cyber insurance. Insurance remains an important component of risk management, but it cannot become a substitute for good governance. Insurers are becoming more demanding about security controls, incident preparedness and resilience. Organizations with weak security practices may find that coverage is more expensive, more restrictive or simply harder to obtain.
The better strategy is to build resilience first and treat insurance as one layer of protection rather than the safety net for inadequate controls.
There is another reason cybersecurity deserves a place in the ESG discussion: the credibility of ESG reporting itself.
Companies are increasingly relying on digital systems to collect information about emissions, energy consumption, employee data, governance practices and other sustainability indicators. If those systems are compromised or the underlying information is manipulated, the credibility of ESG disclosures can be called into question.
In other words, cybersecurity helps protect the integrity of ESG reporting.
This is an issue that deserves greater attention as Malaysian companies face increasing expectations to provide transparent and reliable sustainability information.
For chief information security officers, the implication is significant. The CISO’s role can no longer be confined to firewalls, security alerts, vulnerability management and incident response.
The CISO increasingly has a seat in a much bigger conversation about corporate resilience.
That conversation must involve the board, risk officers, compliance teams, legal advisers, sustainability professionals, procurement teams, internal auditors and business leaders. Cybersecurity cannot remain an isolated technology function when the consequences of a cyber incident can affect virtually every part of the business.
Perhaps the biggest change required is cultural. Companies need to stop asking whether cybersecurity is an ESG issue and start asking how cybersecurity contributes to their ESG performance.
A company cannot claim to be socially responsible while failing to protect its customers’ personal data. It cannot claim to have strong governance while the board has limited visibility into material cyber risks. And it cannot claim to be resilient if a single cyber incident can bring critical operations to a halt.
Malaysia’s digital economy has much to gain from technology. But digitalisation also comes with responsibilities.
As companies pursue their ESG ambitions, cybersecurity should be treated as one of the foundations supporting those ambitions — not as an afterthought.
The message for Malaysian boardrooms is simple: sustainability is not only about reducing carbon emissions or publishing an ESG report. It is also about building an organization that people can trust, that investors can rely on and that can continue operating when things go wrong.
In a digital economy, protecting data, systems and digital trust is part of responsible business. Cybersecurity is therefore no longer just an IT concern. It is a fundamental test of ESG, corporate resilience and good governance.
Ramani Parkunan is a cybersecurity advocate who champions greater awareness and understanding of cybersecurity through his writing.









Leave a Reply