Cybersecurity is becoming a critical supplier qualification requirement for Malaysian technology hardware companies serving the global semiconductor industry, as chipmakers tighten supply chain standards amid rising cyber threats, Kenanga Research said Thursday.
The brokerage said in a note that cybersecurity is evolving beyond a regulatory compliance issue into a core business requirement, joining traditional supplier selection criteria such as quality, cost, delivery and manufacturing capability.
Its channel checks with management teams at selected Penang-based technology companies found multinational semiconductor customers now routinely assess suppliers’ cybersecurity capabilities during qualification exercises and periodic audits.
“As semiconductor manufacturers strengthen supply chain resilience, suppliers are increasingly expected to demonstrate robust cybersecurity governance, recognized certifications such as ISO 27001 and effective cyber risk management,” it said.
The research house expects this trend to drive sustained investment in cybersecurity capabilities across Malaysia’s technology hardware sector, while creating opportunities for local cybersecurity solution providers and system integrators.
The shift comes as the semiconductor industry becomes increasingly digitalized, with manufacturing equipment, production systems and supply chains becoming more interconnected. While automation has improved productivity and efficiency, it has also increased manufacturers’ exposure to cyber threats.
Unlike many industries, cyberattacks on semiconductor companies can disrupt production while exposing valuable intellectual property, proprietary chip designs, customer data and sensitive manufacturing processes.
Kenanga noted that cybersecurity has become a broader environmental, social and governance (ESG) issue as semiconductor manufacturers and outsourced semiconductor assembly and test (OSAT) companies handle large volumes of confidential customer information and personal data.
Beyond maintaining business continuity, companies are expected to demonstrate stronger governance through comprehensive data stewardship, transparent incident reporting and compliance with global data privacy regulations, including the European Union’s General Data Protection Regulation (GDPR) and Malaysia’s Personal Data Protection Act (PDPA).
The industry’s growing focus on cybersecurity has also prompted greater collaboration.
In 2024, industry association SEMI established the Semiconductor Manufacturing Cybersecurity Consortium (SMCC) to strengthen cyber resilience across the global semiconductor supply chain through common standards and closer cooperation.
Among its initiatives are implementing the SEMI E187 cybersecurity standard for semiconductor manufacturing equipment, supporting compliance with new regulations such as the European Union’s Cyber Resilience Act, and developing a standardized cybersecurity assessment framework for suppliers.
Kenanga said these initiatives reflect the industry’s recognition that cybersecurity is now a strategic business risk rather than solely an information technology function.
Manufacturing has remained the world’s most targeted industry for cyberattacks for five consecutive years, according to SEMI.
The sector accounted for 27.7 percent of global cyberattacks in 2025, up from 23.2 percent in 2021, reflecting manufacturers’ growing dependence on digital technologies, industrial automation and connected production systems.
Kenanga said the trend reinforces the need for semiconductor manufacturers and suppliers to strengthen cyber resilience to protect business continuity and maintain customer confidence.
Cyber incidents have become increasingly common across the semiconductor value chain, affecting integrated device manufacturers, wafer fabs, chip designers, equipment suppliers and OSAT providers.
Major industry players including Samsung, TSMC, SK hynix, NVIDIA, AMD, ASML, MKS Instruments and Malaysia’s SilTerra have all experienced cybersecurity incidents ranging from ransomware attacks and data breaches to intellectual property theft and cyber espionage.
Since January 2026 alone, publicly disclosed cyber incidents involving semiconductor test equipment maker Advantest, testing services provider Trio-Tech International and Tata Electronics have highlighted the industry’s vulnerability to ransomware, unauthorized data disclosures and operational disruptions.
Kenanga said the breadth of these attacks demonstrates that cybersecurity is no longer an enterprise-level issue but a supply chain-wide imperative, where the security standards of individual suppliers can affect the resilience of the broader semiconductor ecosystem.
The research house also pointed to growing efforts to standardize cybersecurity requirements across the industry.
According to the SMCC, suppliers currently face multiple customer-specific cybersecurity assessments that often overlap and impose unnecessary compliance costs without significantly improving security outcomes.
To address this, the consortium is developing a semiconductor-specific supplier cybersecurity assessment framework aimed at harmonizing security requirements, simplifying supplier evaluations and accelerating the adoption of best practices.
Kenanga believes this will have positive implications for Malaysian technology hardware companies supplying multinational semiconductor manufacturers.
As leading chipmakers strengthen their own cyber defenses, they are expected to impose similar standards across their supply chains to safeguard intellectual property, manufacturing operations and business continuity.
This means suppliers are likely to face increasingly rigorous cybersecurity due diligence and will be expected to demonstrate recognized certifications, robust governance frameworks and effective incident response capabilities.
Companies that invest early in strengthening their cybersecurity capabilities are likely to improve their competitiveness, secure new programs and deepen relationships with Tier-1 semiconductor customers, Kenanga said.
Conversely, suppliers that fail to meet rising cybersecurity expectations may face greater difficulty qualifying for new contracts as cybersecurity becomes another key benchmark for participation in the global semiconductor supply chain.
The brokerage added that stronger cybersecurity adoption across the semiconductor industry should also support long-term demand for Malaysian cybersecurity specialists and system integrators as manufacturers seek to enhance cyber resilience and comply with evolving customer requirements.
AI is transforming climate-risk management across Malaysia’s industries – BIMB

