Insights That Keep You Ahead of Cyber Threats
Frontline Analysis from Our Experts — For IT Leaders & Decision Makers
How do attackers really think? What does a new vulnerability actually mean for your business? The AKATI Sekurity Insights Blog is where our experts answer the hard questions — publishing frontline analysis and forensic discoveries to give you the practical, technical, and strategic knowledge you need to build a stronger defence.
SC Malaysia Guidelines on Technology Risk Management
Malaysia's capital market has tested the SC's technology risk guidelines against real incidents. The clauses that bind, and the 2026 deadlines.
PCI DSS v4.0.1 MFA Requirements
PCI DSS MFA requirements are scored at the CDE boundary. What 8.4.2, 8.4.3 and 8.5.1 each cover, the documented exception, and what a QSA asks for.
Identity Is the New Perimeter
A Teams help-desk vishing campaign reached a domain controller while malware tools stayed quiet. What identity attacks abuse, and what ITDR fixes.
Why Submitting Your RMiT Gap Analysis in 2026 Was Only Step One
The reissued RMiT obliges continuous compliance, not a one-time gap analysis, and key resilience duties fall due in 2027.
Zero Trust Without the Product Pitch
What zero trust means in NIST SP 800-207 and CISA's maturity model, the five pillars, and the sequence that holds up in production.
Securing Payment Pages Under PCI
How e-skimming runs in the browser, and how PCI DSS Requirements 6.4.3 and 11.6.1 break the attack path on merchant payment pages.
An Incident Response Plan That Works
An incident response plan works only if your team can run it under pressure. What the first hour, roles, and NIST 800-61r3 require.
What BNM Requires of Merchant Acquirers
What BNM's merchant acquiring rules require of registered acquirers: overseeing payment facilitators, sub-merchants, and PCI DSS across the chain.
Business Email Compromise: The Quiet Heist
Business email compromise is a financial fraud in which criminals gain control of, or convincingly imitate, a trusted email account and use it to redirect a legitimate payment into an account they control.
MSSP or In-House SOC?
MSSP vs In-House SOC: What You Can't Outsource
MSSP or in-house SOC gets sold as cost versus capability. The real question: which failures can you own around the clock, and can you staff for them?
Internal Scans, ASV Scans, Pen Tests
ASV Scan vs Pen Test vs Internal Scan
PCI DSS v4.0.1 requires internal scans, ASV scans, and pen tests. Each proves something different, and a clean scan is not proof you are secure.
How Ransomware Lands in 2026
How Ransomware Gets In: Initial Access in 2026
Ransomware is the final move of an intrusion, not the first. How attacks get in, how fast they move, and where defenders have real leverage in 2026.
EPP, EDR, SIEM, XDR: What's Next ?
EPP, EDR, SIEM and XDR each watch something different. Learn what each covers, what stays your job, and how to read the next acronym.
Scoping and Segmenting the CDE
PCI Scope Reduction: Segmenting the CDE
PCI DSS does not require segmentation; it is how you reduce scope. What the CDE is, the three scope categories, and why out-of-scope must be proven.
Malaysia's AI Governance Bill and Incident Reporting
Malaysia's AI Governance Bill: Who Must Report. Malaysia's proposed AI Governance Bill covers any organisation that develops or deploys AI. See who is in scope and when an AI incident must be reported.
How Singapore Widened the Net
Singapore's 2024 Cybersecurity Amendment now reaches overseas-hosted and vendor-run critical systems, and signals where the region's rules are heading.
Nobody Knows Where Their Crypto Is. PCI Made That a Finding.
Title: PCI DSS 12.3.3, Crypto Inventory & Post-Quantum Exposure
Meta: PCI DSS doesn't mention quantum once. But Requirement 12.3.3 asks for the exact inventory a post-quantum migration needs. A QSA's read on what it means.
Shadow AI Tripled to 45%. The Real Gap Is Who's Logged In.
Employee AI use tripled to 45% in a year, and two-thirds runs through personal logins nobody monitors. Shadow AI is an access problem.
What PCI ASV Scans Require
A passing PCI ASV scan needs zero CVSS 4.0+ findings, a PCI-listed vendor, and a scope you define. Who must run them under PCI DSS v4.0.1, explained.
From Security to Resilience: Can You Recover?
Prevention has a ceiling. Resilience is the rehearsed ability to recover fast, and regulators now require you to prove it. What that demands operationally.