
By: Sonny Zulhuda(*)
Trust has always been fundamental to human relationships. It is built gradually through consistent actions, reliability and the confidence that others will act responsibly. In the digital environment, however, trust has become more complex. We increasingly rely on digital platforms, automated systems and online services that we may never physically encounter, while entrusting them with our personal information and digital identities.
This is why digital trust has become a critical foundation of the digital society. Technology alone cannot guarantee trust. People will only embrace digital transformation when they believe that their information is protected, their privacy is respected and organisations are accountable for their actions.
From my engagement with cybersecurity, privacy and technology law, I have come to appreciate that digital trust is not created through promises or technical capabilities alone. It must be earned through responsible governance, transparency and consistent commitment to protecting individuals and society.
Cybersecurity and privacy laws therefore should not be viewed merely as compliance obligations. Their greater purpose is to guide organisations towards responsible practices and stronger accountability. When individuals provide their personal information, they are placing their confidence in an organisation. They expect that information to be handled carefully, protected appropriately and used responsibly. Once trust is lost, rebuilding it can be extremely challenging.
Malaysia’s evolving cybersecurity and privacy framework reflects this growing responsibility. The Personal Data Protection Act 2010, together with its recent developments, strengthens the obligations of organisations that collect and process personal data. It reinforces the principle that personal information is not simply a business asset, but something entrusted to organisations that must be protected.
Similarly, the Cyber Security Act 2024 strengthens cybersecurity governance, particularly in relation to critical information infrastructure and essential services. It highlights that cybersecurity is not merely a technical issue, but a matter of organisational leadership, governance and resilience.
The development of cybercrime-related legislation further demonstrates that digital threats require a comprehensive approach. Effective cybersecurity is not only about preventing incidents, but also about ensuring that organisations are prepared to respond, recover and maintain confidence when challenges occur.
For this reason, compliance should not be seen as a burden. A mature organisation complies not merely because the law requires it, but because responsible practices build confidence among customers, employees and stakeholders. Compliance encourages organisations to understand risks, establish accountability and develop appropriate measures to protect information and systems.
At the same time, technology alone cannot create digital trust. Strong governance remains essential. Organisations need clear responsibilities, informed leadership and a culture where privacy and security are shared values rather than merely technical requirements.
Ultimately, digital trust is built through competence, integrity and accountability. Organisations must demonstrate that they have the ability to protect information, the commitment to act responsibly and the willingness to be accountable when things go wrong.
The future of digital trust lies in the concept of “trust by design”. Security, privacy and accountability must be considered from the beginning when designing digital services, business processes and emerging technologies.
For cybersecurity and governance professionals, the role is therefore evolving. They are no longer simply ensuring compliance with standards and regulations. They are helping organisations build resilience, confidence and trust in an increasingly connected world.
Cybersecurity and privacy laws provide the foundation. Good governance provides the direction. Resilience provides the strength to withstand uncertainty.
Ultimately, the organisations that succeed in the digital age will not only be those that innovate quickly, but those that demonstrate that they can be trusted.
(*) Sonny Zulhuda is the Chairman of ICMI Malaysia. He teaches Cyber Law at Universitas Al-Azhar Indonesia (UAI) Jakarta, and the International Islamic University Malaysia (IIUM), Kuala Lumpur.
Leave a comment