Enterprise IT News’s recent interview with Nicole Quinn, VP of Public Policy and Government Affairs for APJ at Palo Alto Networks, highlighted the importance of critical infrastructure at the national, business, and citizen levels, as well as the need to understand attack surfaces, adopt secure-by-design approaches, and foster regional partnerships.
She emphasised that critical infrastructure (CI) is about understanding and protecting the interconnected systems essential for society to function smoothly – national infrastructures that deliver daily services that citizens rely on, such as utilities, transportation, government services, and logistics.

Reframing this interconnectedness from a Southeast Asia perspective, Nicole said, “We live in an interconnected world – especially in ASEAN, where cross-border cooperation is essential. If critical infrastructure entities experience significant breaches, it undermines trust, impacting not just individual countries but the entire region and beyond. That’s why we have a responsibility to take the delivery and protection of our critical infrastructure very seriously.”
Given the highly volatile, fast-paced, unpredictable, and risky landscape of modern cyber security, governments like Malaysia have enhanced their cybersecurity legislation—a move Nicole lauded as proactive in protecting and strengthening the country’s resilience.
The Interconnected World
Nicole shared Australia’s journey with critical infrastructure legislation as an example.
High-profile breaches in 2022 involving a telecommunications company and a health insurance provider in Australia expanded cyber security conversations beyond technical teams and boardrooms to public spaces like pubs, due to the pervasiveness of the impact – personal details of nearly half the Australian population were exposed on the dark web.
These incidents had several significant consequences. Nicole observed, “Those two businesses certainly lost customers. They lost shareholder value, they lost trust, and that takes time to rebuild. Bottom lines were impacted, reputations were damaged, and those companies have had to work really hard to mitigate the effects and respond to customers’ expectations that their data needs to be held securely.”
At the same time, these breaches prompted the Australian government to re-examine how it stored and secured data.
“A lot of the customer data was very old, but there was a legislative requirement to keep it for a certain duration. There was a real conversation at the government level about what we are mandating, why we are mandating this storage of data, how it is being secured, and whether it now presents a cybersecurity risk.”
Shared Responsibility- but address visibility first
Shared responsibility is a recurring topic at many cybersecurity conferences.
Rather than service providers, vendors, and customers pointing fingers at each other after a data breach, there must be recognition that modern cyber security is about more than just prevention.
Visibility and understanding of the entire attack surface – having a comprehensive inventory of all endpoints, potential vulnerabilities, and the entire IT environment – are crucial.
Nicole commented, “The legislative approach has really turned the spotlight on that because of the audits and risk filings required around your cyber security posture. You need to understand all your endpoints, especially for critical infrastructure.”
Additionally, this enables “an understanding of where your partners or suppliers fit within your cyber security frameworks, and ensures you have mechanisms to keep each other accountable regarding expectations.”
Resilience – the ability to ‘bounce back’ after an attack- and preparation to respond rapidly and effectively to potential threats are equally important. Metrics like ‘mean time to detect’ and ‘mean time to respond’ to incidents are critical for developing mechanisms to mitigate and address breaches, as well as for creating strategies to respond effectively if critical systems are compromised.
Nicole highlighted two key areas: a secure-by-design mindset and platformisation.
“What we’ve seen is that cybersecurity has sometimes been an afterthought. Some organisations with over 60 different vendors and products have IT and cyber security teams overwhelmed by complexity and logistics.
We’re advocating for simplification – having a single pane of glass for understanding your environment, access points, and potential vulnerabilities.”
Creating Trust Forums – Government-led, private sector-driven
Cyber security capabilities primarily reside within private sector businesses, not just government services. Nicole emphasised the mutual obligation both parties have to make initiatives like ‘trust forums’ work. As a result, delivering cybersecurity legislation is inherently collaborative, requiring active participation and adaptation from both government and private sectors.
Governments may set frameworks, but private businesses must adapt them to specific conditions and risks on the ground. Companies are often hesitant to report data compromises to regulatory bodies due to fears of reputational damage and loss of customer trust.
This underscores the need for government-created forums or legislative requirements for safe reporting environments – platforms where companies can share insights without excessive risk exposure. Such intelligence sharing is critical for other organisations to learn from incidents and take steps to improve their own cybersecurity posture.
The broader cyber security ecosystem benefits when companies can safely share breach insights, enabling collective improvement of security practices across industries. Nicole also suggested practical steps to establish trust forums or safe environments, such as joint workshops, resilience exercises, and even red teaming scenarios.
These sessions can bring together government, cybersecurity experts like Palo Alto Networks, and companies affected by cyber attacks, to find a balanced approach that protects individual organisations and strengthens cyber security resilience.









