As Malaysian businesses process more data, rely on cloud services and digitalize core operations, internal threats are becoming harder to ignore. Sensitive information can be exposed not only by hackers, but also through accidental or deliberate leaks, employee negligence, conflicts of interest, misuse of access rights or risky user behavior.
We spoke with Lev Matveev, founder of SearchInform, about why insider threats are becoming a critical business risk in Malaysia and how companies can strengthen internal security.
SearchInform focuses on protection against insider threats. What exactly are these risks?
All cyber threats can generally be divided into two categories: external and insider threats. External threats include malware, phishing, ransomware, account compromise and other attacks from outside the organization.
Insider threats come from people who already have legitimate access to systems and data. They include deliberate or negligent data leaks, corporate fraud, document forgery, kickback schemes, conflicts of interest, client poaching, shadow IT and other risky user behavior.
The key problem is that such actions may look like normal work without proper visibility into data movement and employee activity. That is why insider threats often remain unnoticed until they cause financial, legal or reputational damage.
Can you share examples of the incidents companies most commonly face?
First of all, attempts to leak valuable and confidential information, including personal data, intellectual property and financial documentation.
One relevant example is a 2025 Industrial Court case involving Petroliam Nasional Berhad, or Petronas. A former employee filed a complaint claiming unfair dismissal. During the proceedings, Petronas presented evidence that the former head of a department had an improper relationship with a contractor’s CEO and had leaked confidential tender documents. The case involved the disclosure of confidential tender information, the use of a personal email account and transfer of information via USB.
What are other major threats businesses should protect from?
The second major category is corporate fraud. It can involve document forgery, manipulation of commercial offers, kickbacks, inflated procurement prices, conflicts of interest. I’ll reveal a few examples.
For example, in one SearchInform customer company from transport and logistics sector company the employee used to purchase truck spare parts. The employee knew which parts the company needed, found a familiar contractor and arranged procurement with a 45% markup. The incident was detected thanks to monitoring, performed with the help of our protective system, DLP class system.
In another company, the employee used to launch Photoshop, though his occupation didn’t require using it. Screenshots and videos capturing desktop activity showed that the employee faked price offers of other suppliers in order to lobby his “own ones”.
Another risky category is unsafe user behavior, which includes installation of unauthorized software, visiting risky websites, downloading suspicious files, using personal cloud storage for work documents or interacting with phishing emails. Such actions often open the door to malware, ransomware or data leakage.
Productivity issues are also widely spread. In case the company faces systematic idleness, this leads to significant financial losses and indirect damage by demotivation of other team members. In this regard there’s an illustrative case from our customer’s experience, when 5 out of 6 employees of IT department used to spend around 5 hours of paid working time on irrelevant activities, such as video streaming, online shopping and gaming.
Here are illustrative and typical cases, however, the final list depends on the specific company, its sphere of business activity and numerous other factors.
How does SearchInform help to ensure protection against these risks?
SearchInform is the information security and risk management solutions vendor. Our products help prevent leaks of valuable and confidential information, safeguard businesses against corporate fraud, document forgery, theft, unfair competition, inefficient time management. Our core product, Next-Gen DLP system enables to gain total visibility into actual processes and prevent risky incidents.
We started our way in information security more than 20 years ago and from the very beginning, we developed our systems based on customer needs. That is why we created not just a system for blocking data leaks, but a full-scale platform for incident analysis and investigation.
Many competing solutions do not provide a full incident history. Even leading global vendors often provide only limited visibility into security incidents – for example, showing that a sensitive file was sent and which employee sent it.
Our DLP system stores the full communication history, allowing companies to reconstruct the entire context of an incident. Security teams can investigate who else the employee interacted with and identify additional violators if necessary.
SearchInform DLP features nine search technologies for proactive threat detection, as well as automated reporting tools that streamline incident analysis and reduce the workload for security teams.
Another key advantage is the ability to block sensitive data transfers in custom applications. Most competing solutions monitor only a limited number of communication channels, and even fewer can effectively block data transmission. We developed a content-based blocking mechanism that can prevent labelled files from being sent through any channel – including email, messengers, cloud storage services, printers, and other applications.
This year, we also integrated the AI Assistant module into our DLP. It helps detect violations that traditional security policies may overlook, automatically translates foreign-language communications and documents, and generates incident summaries – helping information security teams save up to 20% of their time.
I could talk for hours about our advantages, but our company’s philosophy is simple: the real value of the solution is best demonstrated in practice. That is why we offer a one-month free trial, allowing companies to evaluate our DLP capabilities in a real business environment.
During this period, our specialists also conduct an internal security audit, help maximize the value of the platform, prepare incident reports, and provide recommendations on the management measures needed to strengthen security.
Malaysia is strengthening its data protection and cyber resilience agenda. How does this affect demand for DLP and DCAP solutions?
For example, Malaysia’s Personal Data Protection Act has been amended, introducing important changes such as stronger obligations around data protection and breach notification. Bank Negara Malaysia’s Risk Management in Technology framework is also an important reference point for financial institutions managing technology and cyber risks.
Businesses need tools to understand what sensitive data they store, where it is located, who has access to it, how it is used and whether it is being transferred through secured channels. This is where DCAP and DLP work together.
DCAP helps classify data, identify sensitive files and manage access rights. DLP protects data in motion, monitors communication channels, prevents leaks and supports incident investigation. In other words, these technologies help turn regulatory requirements into daily operational control.
This year, SearchInform opens the local representative office in Kuala Lumpur. How will it change the way you operate in the country?
Despite the fact that we’ve been operating in Malaysia for several years, we’re now opening a local office in Kuala Lumpur to be in close touch with customers and provide all-round support for our partner network. Malaysia is strengthening its data protection and cyber resilience agenda, which is driving demand for information security solutions, primarily DLP and DCAP-class systems. According to our estimates, the potential addressable DLP market in Malaysia is around USD 100 million.
Opening of the local representative office reveals our commitment to the Malaysian market for the long term. We are strengthening presales, sales, engineering and implementation support. This will ensure that partners and customers receive professional assistance at every stage of cooperation. We also plan to develop marketing and PR activities in Malaysia, share expertise through webinars and media publications, and support partners in working with incoming leads.
What practical recommendations would you give Malaysian businesses?
- First, educate employees. Many incidents happen not because people want to harm the company, but because they do not understand how serious the consequences of unsafe data handling can be.
- Second, identify and classify sensitive data. Organisations must know where their most valuable information is stored and who can access it.
- Third, protect communication and data transfer channels. Email, messengers, cloud services, USB drives, printers and web uploads are common channels through which data leaves the organisation.
- Fourth, monitor risky user behaviour. Companies should be able to detect unusual copying, mass printing, personal email usage, suspicious communication with counterparties, shadow IT and preparation for resignation.
- Finally, treat internal security as part of business resilience. If a company cannot see what is happening with its data and employee actions, it cannot properly manage risk.
Protection against insider threats is no longer optional. For Malaysian businesses, it is becoming a critical part of cyber resilience, compliance and long-term competitiveness.
Featured image by SearchInform

