Why data leaks are no longer “someone else’s problem” and how to protect yourself from them
ℹ️ Source: SearchInform
Data governance has moved from the IT department to the boardroom.
MALAYSIA – 3 SEP 2026 – An RM90 million judgment against Public Bank has turned a 13-year banking dispute into a landmark case for data governance in Malaysia. What began with misconduct by two employees ended with the Federal Court placing responsibility on the organisation and making governance of confidential information a board-level priority.
Francis Yeoh, Country Director, SearchInform Malaysia, explains why data governance is the ultimate priority for Malaysian businesses and provides an actionable checklist to introduce efficient security processes.
The Case That Moved Data Governance into the Boardroom
In June 2025, Malaysia’s Federal Court ordered Public Bank to pay RM90 million to National Feedlot Corporation (NFCorp) for the unauthorised disclosure of confidential banking information. It is one of the country’s largest awards for a breach of confidentiality. Yet the case did not involve hackers, ransomware, or a cyberattack. Instead, it emphasised a new level of board accountability – data governance.
The dispute began in 2012, when confidential banking records belonging to NFCorp and several related companies were accessed from within Public Bank and later leaked into the public domain. Public Bank’s investigation found that two employees had accessed and printed the documents without authorisation. Both were disciplined, while the bank argued throughout the litigation that they had acted independently and that the institution should not be held responsible.
Initially, the High Court dismissed NFCorp’s claim entirely. In 2023, the Court of Appeal overturned that decision and found Public Bank liable for breaching confidentiality, but limited compensation to RM10,000. Two years later, the cost of inadequate data governance increased 9,000-fold. After reviewing audited financial statements, expert testimony, and evidence of commercial losses, the Federal Court found that the lower courts had failed to properly assess the financial evidence presented. It raised the award from RM10,000 to RM90 million, comprising RM30 million each in equitable, aggravated and exemplary damages, plus interest.
By rejecting Public Bank’s argument that liability rested solely with two employees, the Federal Court reaffirmed that an organisation’s duty to protect confidential information cannot be delegated to individuals or avoided by treating misconduct as an isolated incident.
Malaysia Is Raising the Bar on Data Standards
Over the course of this 13-year case, the courts’ approach to corporate responsibility for data governance evolved. What began as a dispute over employee misconduct ended with a Federal Court judgment that placed responsibility on the organisation. For boards, this elevates oversight of access to confidential information from an IT issue to a matter of governance and legal accountability.
This evolution takes place as Malaysia sets digital trust, which is impossible without proper data security, as a national priority. The country’s data protection framework has changed significantly since the Personal Data Protection Act (PDPA) came into force in 2010. Among the most significant changes are mandatory data breach notification requirements, direct security obligations for data processors, and the recognition of biometric information as sensitive personal data.
As Malaysia accelerates digital transformation across both the public and private sectors, expectations around data governance are rising. Businesses can no longer neglect them.
How to Protect Your Business and Your Customers
The Public Bank judgment sends a clear message. Data governance is no longer the responsibility of the CISO, DPO, or IT team alone. As governance failures have become a business risk with legal and financial consequences, the processes require thorough oversight from top management and the board.
Here are five practical steps to mitigate emerging risks.
- Classify your data. Map confidential data: customer records, financial data, intellectual property, contracts, and strategic documents. Tag it by sensitivity and assign a business owner for each category. Without knowing what data matters most, it is impossible to prioritise protection or govern access effectively.
-
Restrict access to sensitive information. Grant access only when there is a documented business need. Review permissions whenever an employee joins, changes roles, or leaves the organisation. Conduct regular organisation-wide access reviews to remove outdated or excessive permissions before they become a risk.
-
Support governance with the right technology. Implement tools that provide visibility into where sensitive information is stored, who can access it and how it is being used. For example, a DLP system can help detect unauthorised transfers of confidential information and support investigations, while regular reviews ensure technical controls continue to reflect business requirements.
-
Build a structured incident response plan. Define in advance who investigates an incident, who makes business decisions, and who communicates with regulators, customers, and the media. Document notification procedures, escalation paths, and decision-making responsibilities. Test the process through tabletop exercises so teams can respond quickly rather than creating procedures under pressure.
-
Build security awareness into everyday work. Train employees during onboarding, refresh training regularly, and tailor it to different roles. Run phishing simulations, explain how to handle confidential information, and ensure staff know how to report suspicious activity immediately. Measure participation and test whether employees can apply the guidance in practice.
Boards are not expected to operate security systems. Their accountability is to oversee the governance behind them. Ensuring that access to confidential information is properly governed, regularly reviewed, and supported by clear accountability is becoming part of the board’s responsibility for organisational resilience.
About SearchInform:
SearchInform is an information security and risk management product vendor as well as an MSS provider. The company’s clients are more than 4000 companies in 20+ countries. Today, the team has products and services for comprehensive protection against insider threats at all levels of corporate information systems: FileAuditor (the DCAP class solution); DLP system with extended functionality; Risk Monitor (advanced AI-powered platform for internal threat mitigation); SIEM system, Information Security outsourcing service.
For more information, please contact:
Vadim K SearchInform External PR media@basedboys.com