Monday, September 21, 2026

Migrating a payments service: How to scale secure, real-time payments for Malaysia

A successful migration of the entire cloud-native solution that preserved the cloud active architecture built on Kubernetes, managed AWS services, and agile practices.

Payments infrastructure is designed to be invisible. When it performs as intended, transactions complete in seconds, and customers never ever have to consider the complex processes that had to happen for them to achieve the desired result.

This is not the case for a Malaysia-based provider of large-scale payment networks and gateways. Its CTO Zainol Zainuddin recently shared about its process of migrating its core system from AWS’ Singapore region to the Malaysia region, and the thorough planning it underwent that had to consider performance, security, availability and cost.

Zainol Zainuddin

Zainol shared, “The primary business driver for migrating our payments arm service from the AWS  Singapore region to the AWS Malaysia region was cost optimisation.” Besides taking advantage of substantial incentives offered through the migration acceleration programme, ongoing operational costs in the Malaysia region were anticipated to be lower, due to regional pricing differences and infrastructure efficiencies.

It also helped greatly that this payment processor’s core audience could enjoy lower latency 10 to 20 milliseconds (ms) compared to the 50-60 ms if it had to access services from the Singapore region.

“This  reduction in round-trip time results in faster response times for payment  processing, real-time transactions, and overall user interactions, leading to a  noticeably better experience for our customers in Malaysia.”

Forward-thinking

According to Zainol, this migration can be viewed as a proactive step to enhance data  sovereignty and data residency preparedness. “By hosting our workloads in the local  AWS Asia Pacific (Malaysia) Region (launched in 2024), we are better positioned to  align with potential future evolutions in Malaysia’s data protection landscape, such  as emerging trends under the Personal Data Protection Act (PDPA) amendments  or sector-specific expectations for financial services.”

By keeping the legacy system operational in parallel and  migrating only a small pilot group initially, we ensured no widespread business  disruptions, achieving effective zero-downtime for the majority of operations while  progressively transitioning to the Malaysia region.

Zainol Zainuddin

However, the regional migration also served as a strategic enhancement within the organisation’s  larger modernisation initiative to build and deploy a next-generation payment gateway platform as a fully cloud-native solution.

Zainol explained, “Developed entirely by our in-house IT team, the new platform will replace the  legacy monolithic Payment Gateway System; once all merchants are migrated to the new Payment Orchestration Solution. Its primary objective is to significantly  improve customer experience while enhancing the overall capabilities, security,  scalability, and flexibility of our payment processing infrastructure to meet modern  demands.”

Re-architecting a platform

The team had decided to pursue full refactoring or re-architecting of the platform for the region migration.

In summary, the architecture was designed for controlled, low-impact migration rather than true active-active multi-region (which would eliminate most risks but add complexity and cost). 

Zainol explained, “By keeping the legacy system operational in parallel and  migrating only a small pilot group initially, we ensured no widespread business  disruptions, achieving effective zero-downtime for the majority of operations while  progressively transitioning to the Malaysia region.”

The platform transformation project which began in July 2023, enables it to seamlessly integrate with major online payment channels, and also aligns with Malaysia’s national vision to be a premier data centre hub for hyperscalers.

“By relocating our solution to the Malaysia region, we are proud to support this government initiative to position the country as a digital and cloud innovation leader in Southeast Asia.”

The CTO was also quick to point out that this is a successful migration of the entire cloud-native solution, because it preserved the cloud active architecture built on Kubernetes, managed AWS services, and agile practices.

Proactive

Zainol described the migration as being proactive as there had been no strict regulatory requirements to do so. 

He explained, “While the Bank Negara’s Risk Management in Technology (RMiT) guidelines emphasise robust risk assessments, data security, and oversight for cloud usage, they do not enforce mandatory in-country data storage for our type of operations (as a payment processor).”

In terms of sovereignty and residency preparedness however, it was the right move to make as it enables the payment processor to align with the evolution of Malaysia’s data protection landscape.

For example, Personal Data Protection Act (PDPA) amendments or sector-specific expectations for financial services can be better addressed, and overall helps to keep customer payment data within Malaysia’s borders. 

Cat Yong
Cat Yong
Cat Yong is Editor-in-Chief of Enterprise IT News, a regional news website which began in Malaysia circa 2011. A common theme in all of her work - opinions, analysis, features and more - is how technology and innovation drives business and outcomes. A career tech journalist for 22 years, her work has evolved to also encompass narratives of tech powering human potential.
Powered byspot_img

Read more

News

Powered byspot_img