Insights That Keep You Ahead of Cyber Threats
Frontline Analysis from Our Experts — For IT Leaders & Decision Makers
How do attackers really think? What does a new vulnerability actually mean for your business? The AKATI Sekurity Insights Blog is where our experts answer the hard questions — publishing frontline analysis and forensic discoveries to give you the practical, technical, and strategic knowledge you need to build a stronger defence.
Scoping and Segmenting the CDE
PCI Scope Reduction: Segmenting the CDE
PCI DSS does not require segmentation; it is how you reduce scope. What the CDE is, the three scope categories, and why out-of-scope must be proven.
Malaysia's AI Governance Bill and Incident Reporting
Malaysia's AI Governance Bill: Who Must Report. Malaysia's proposed AI Governance Bill covers any organisation that develops or deploys AI. See who is in scope and when an AI incident must be reported.
How Singapore Widened the Net
Singapore's 2024 Cybersecurity Amendment now reaches overseas-hosted and vendor-run critical systems, and signals where the region's rules are heading.
Nobody Knows Where Their Crypto Is. PCI Made That a Finding.
Title: PCI DSS 12.3.3, Crypto Inventory & Post-Quantum Exposure
Meta: PCI DSS doesn't mention quantum once. But Requirement 12.3.3 asks for the exact inventory a post-quantum migration needs. A QSA's read on what it means.
Shadow AI Tripled to 45%. The Real Gap Is Who's Logged In.
Employee AI use tripled to 45% in a year, and two-thirds runs through personal logins nobody monitors. Shadow AI is an access problem.
What PCI ASV Scans Require
A passing PCI ASV scan needs zero CVSS 4.0+ findings, a PCI-listed vendor, and a scope you define. Who must run them under PCI DSS v4.0.1, explained.
From Security to Resilience: Can You Recover?
Prevention has a ceiling. Resilience is the rehearsed ability to recover fast, and regulators now require you to prove it. What that demands operationally.
What the Dark Web Already Knows
The credentials, source code and deal intelligence already listed and traded, how actors weaponise it, and what monitoring really delivers.
Beyond the Act 854 Checklist
Why Malaysian NCII entities should run Act 854's Code of Practice and risk assessments as a continuous operating model the board owns, not paperwork.
The Holes in Your Cyber Policy
Carriers now exclude state-backed attacks, control lapses, and AI incidents. A forensic read of the cyber policy clauses that trigger a denied claim.
When the NCII Reporting Clock Starts
Act 854 requires NCII entities to notify NACSA within six hours of a suspected incident. What counts as reportable, and how to build the reflex first.
83 Tools, Still Breached
Why tool sprawl widens blind spots, and how consolidating onto fewer platforms speeds detection and eases the load on the team.
What PCI Counts as a SIEM, and Why Your EDR Does Not
PCI DSS Requirement 10 demands centralised logging, automated daily review and twelve-month retention. Here is why an EDR cannot stand in for a SIEM.
Inside Act 854 CED No.8's Audit Mandate
Malaysia's CED No.8 mandates a biennial cyber audit for NCII entities under Act 854. What it tests across compliance, risk and technical lenses.
Inside a PCI DSS 4.0.1 Audit: What Assessors Expect
A plain walk through a PCI DSS v4.0.1 assessment: the 12 requirements, the Defined and Customized Approaches, and the evidence assessors expect.
Are You an (NACSA) NCII Entity Without Knowing It?
Act 854 scopes organisations by what their systems do, not their industry. A plain reading of Section 17, the eleven NCII sectors, and supply-chain risk.
The 31% Problem: Why Software Flaws Just Overtook Stolen Passwords
In 2026, software flaws overtook stolen passwords as the top way breaches begin. What the 31% shift means for your patch strategy now.
The AI Vulnerability Storm Is Here. Is Your Security Program Ready?
Claude Mythos discovered thousands of zero-days across every major OS and browser. Here is what changed, what it means for your team, and what to do this week.
The Accounts Nobody Owns Are Running Your Business
Machine identities outnumber humans 80:1 in enterprise environments. Learn what NHIs are, why attackers target them first, and the 5 steps to govern them.
Harvest Now, Decrypt Later
Your encrypted data does not need to be readable today to be stolen today. The attack strategy known as Harvest Now, Decrypt Later (HNDL) involves adversaries collecting and archiving encrypted corporate data now, then decrypting it once quantum computers become capable of breaking RSA and elliptic curve cryptography, a threshold most experts place between 2029 and 2033.