TURN on a tap and we expect clean water. Switch on a light and we expect electricity.
Pick up the phone and we expect a signal. Critical infrastructure is invisible when it works. When it fails, the consequences become immediate, human and costly.
Governments and mission-critical industries, including in Malaysia, recognise that cyber resilience is no longer only about defending networks.
It is about protecting the physical systems that keep the digital economy running.
That reality was underscored recently when more than 30 water systems across Minnesota were reportedly affected by a coordinated cyberattack targeting operational technology.
Attackers altered settings and passwords, causing pressure loss and flooding, while some facilities switched to manual operations.
The attacks prompted Five Eyes guidance under CI Fortify, advising operators to prepare vital systems for isolation from connected networks.
The message is clear: resilience is not only about preventing breaches, but the ability to keep operating through one.
For Malaysia, the lesson is not that a similar incident is inevitable. It is that essential services face a shared resilience challenge: how to keep operating when digital control systems, communications channels or trusted networks are degraded.
Water is becoming a strategic target
The US attacks are not isolated. Water infrastructure has been targeted in Denmark, Poland and France, while authorities have warned of attacks against industrial control systems across water, energy and manufacturing.
Malaysia is aware of these risks. CyberSecurity Malaysia has flagged threats to OT environments, including water treatment, electrical grids and other critical services.
MyCERT and Malaysia’s National Cyber Security Agency (NACSA) have also warned of attacks targeting water and wastewater operators, citing internet-exposed OT environments, ageing infrastructure, default credentials and insufficient maintenance.
The attraction of water as a target is obvious. Disrupt supply, and homes lose clean water, hospitals face pressure, manufacturers experience interruptions, and communities feel the consequences almost immediately.
Water is more than a utility. It is life – and part of the infrastructure powering Malaysia’s digital and industrial future.
It underpins much of Malaysia’s real economy, from semiconductor and manufacturing supply chains to crop and rubber processing, petrochemicals, fisheries and Sarawak hydropower.
The AI dimension
Artificial intelligence is also becoming a measure of economic competitiveness and national capability.
Malaysia’s 2030 AI ambitions are being supported by significant investment in digital infrastructure and data centres. Yet AI ultimately relies on very physical foundations.
Data centres need electricity. Electricity networks depend on communications.
Communications rely on digital infrastructure. And as AI workloads grow, the entire ecosystem increasingly depends on water for cooling.
Modern data centres require substantial cooling, making reliable water supplies a strategic dependency for digital growth.
Foreign investment may be accelerating Malaysia’s 2030 vision, but that momentum depends on infrastructure that operates reliably around the clock.
The Malaysian Government has projected that data centres across Selangor, Johor and Negeri Sembilan could require more than 445 million litres of water per day by the end of the decade.
That creates a direct link between water security, cybersecurity, economic security and ultimately –national security.
The Ripple Effect: attacking upstream
Attackers know the shortest route to disruption is often upstream. They do not need to breach a data centre directly if they can interrupt an essential service it depends on.
For attackers, electricity, water and telecommunications have become strategic points of leverage.
Disrupt one, and the effects can quickly reach emergency coordination, hospitals, manufacturing and digital infrastructure.
Malaysia’s Cyber Security Act 2024 (Act 854) recognises 11 National Critical Information Infrastructure sectors, including water, energy, healthcare, transportation and digital infrastructure.
Their protection must be treated as interconnected too.As AI adoption accelerates, protecting upstream infrastructure becomes essential to protecting the digital services downstream.
Preparation must assume not only that systems may be targeted, but that some may be compromised.
Preparing for compromise
The first responsibility of every critical infrastructure operator is still to make systems harder to breach.
Asset visibility, strong authentication, network segmentation, vulnerability management, protected backups and tested recovery processes remain fundamental.
But resilience requires more than prevention. Operators should ask a harder question: If our primary systems were compromised tomorrow, could leadership still securely command, communicate and coordinate a response?
Major incidents require fast decisions involving executives, engineers, regulators, emergency services and external partners.
Yet the usual channels for coordination may be unavailable, compromised or untrusted.
This is where trusted, independent communications become essential. Coordination cannot stop simply because normal systems do.
Malaysia already has strong foundations. The Cyber Security Act (Act 854) establishes responsibilities for NCII operators, while national cyber crisis arrangements provide a framework for serious incidents.
The next step is ensuring resilience planning extends beyond technology recovery to operational continuity.
Exercises should test not only whether systems can be restored, but whether leaders can communicate securely, verify identities, coordinate across organisational boundaries and maintain trusted decision-making throughout a crisis.
Securing the systems beneath Malaysia’s digital future
As Malaysia builds an economy driven by AI, cloud computing, advanced manufacturing and sovereign digital capability, protecting the physical systems beneath that future becomes a national security imperative.

That requires practical planning now: isolating systems, rehearsing crisis decisions, upskilling teams and ensuring trusted communication channels remain available when ordinary channels are disrupted, compromised or brought down by floods.
The attacks occurring globally are a reminder that the boundary between cyber and physical security is disappearing.
True resilience means more than preventing attacks. It means ensuring essential services, and the people responsible for them, can continue functioning when disruption occurs.—Oct 6, 2026
Jonathan Jackson is the Field CISO of BlackBerry Secure Communications, and will join the “Water and National Resilience” panel at the CyberDSA ‘Critical Infrastructure’ day on October 7 at MITEC. More here.




