Maybank’s repeated outages disrupted its mobile banking platform and MAE app. CIMB was penalised for lapses in response and recovery that turned incidents into prolonged service loss for customers and counterparties.
BNM’s Risk Management in Technology policy document leaves little room for interpretation. It states:
Cumulative unplanned downtime affecting user interfaces must not exceed four hours on a rolling 12-month basis, with a maximum tolerable downtime of 120 minutes per incident.
In simpler terms, financial businesses and other regulated entities do not have the luxury of unplanned downtime when it comes to disaster recovery related to multicloud in Malaysia.
Four hours is all the budget you have in a year, and two of those hours can disappear in a single afternoon if things go south.
That budget is being tested harder than it was in 2024, with Forrester cloud predictions indicating that ‘AI data centre upgrades will trigger two major multiday cloud outages.’
For institutions running workloads across several cloud providers, cloud resilience is harder to protect than it looks because failures rarely stay inside one environment. They surface at the intersections: between platforms, between providers, and also between the teams responsible for each.
Each environment carries its own recovery plan, tooling and logs, so when an outage strikes or a ransomware alert flashes, it can take a while to even figure out the source of the problem.
Meanwhile, the cost of standing still is already on the books. IT leaders, for one, replicate infrastructure across providers, staff duplicate teams, and absorb overlapping costs.
This is the high price a business pays when its multicloud strategy in Malaysia is not built with continuity in mind.
The critical question to ask on cloud disaster recovery in Malaysia is this: when disruption hits, and it most probably will, how quickly can the business contain, recover, and account for it afterwards?
How to Enable Truly Effective Cloud Disaster Recovery
Most recovery plans are sound inside a single cloud. The weakness is the journey between them. Replication and restore traffic moving between providers typically crosses the public internet, where latency, routing and throughput are outside anyone’s control.
Time Cloud Xchange Hub addresses this at the network layer. It replaces public internet routing between clouds with a dedicated, private Layer 2/3 connection into a multi-cloud fabric, with separate legs out to each cloud provider, like AWS and Microsoft Azure.
What changes is how recovery traffic moves. Backup and restore between two cloud environments route directly, cloud to cloud, through Time’s multi-cloud router. Data replication remains natively managed by the respective cloud platforms.
Time Cloud Xchange Hub governs the path that replication travels. This has a compounding operational effect. Private, deterministic replication paths shorten recovery times.
The need for redundant physical DR sites falls away, and ultimately, multi-cloud environments consolidate under a single control fabric.
For regulated institutions, recovery workflows become auditable, as recovery traffic that travels one governed path is easier to trace.
So, for example, when a bank has to account to BNM for time spent down, there is a single record to point to rather than three sets of logs and a reconciliation exercise.
Why Is Sovereign Cloud Gaining Ground?
Sovereign cloud is the infrastructure where data, the systems processing it and the keys securing it all remain within a defined jurisdiction, with its operators subject to that jurisdiction’s law.
Directors are increasingly expected to know where workloads run, who can reach them, under whose law, and how quickly they can be brought back.
Lester Pang
“Sovereignty has evolved beyond policy compliance – it’s now a foundation for operational efficiency and digital trust,” explained Lester Pang, Head of Cloud, Time.
A single private connection into a governed fabric keeps recovery traffic within a defined jurisdiction and under a known operator.
It also gives the institution the holistic visibility that is otherwise difficult to assemble when every environment reports separately.
Time Cloud Xchange Hub functions in this precise manner, delivering a unified multi-cloud architecture that supports innovation and protects data integrity.
Through one singular connection, you gain stronger security and complete visibility across all your workloads, enabling your team to focus on outcomes rather than be riddled by infrastructure challenges.
The next institution called to account for its downtime will be judged on whether it can show its workings accurately, and before its time runs out.
Time’s CxO Brief examines where resilience breaks in multicloud Malaysia estate, why sovereignty and governance have become board-level concerns, and what a unified cloud architecture requires in practice.
Featured image edited by Fintech News Malaysia based on an image by user6724086 on Magnific