Visa Malaysia has launched its 2026-2028 Security Roadmap which outlines six priorities aimed at strengthening the country’s digital payments ecosystem as AI, automation and organized scams continue to change the cyber threat landscape.
The latest roadmap is Visa Malaysia’s third edition, following earlier versions introduced in 2019 and refreshed in 2023. It provides market-specific guidance for Visa and its industry partners, with a focus on payment security as fraud increasingly involves authorized transactions driven by social engineering, urgency and manipulation rather than only the unauthorized use of stolen credentials.
Visa said the need for stronger payment security comes as Malaysia’s digital economy continues to expand. Information, communications technology and e-commerce contributed RM451.3 billion, or 23.4%, to the national economy in 2024, while Malaysians lost RM2.97 billion to financial scams in 2025.
“As Malaysia’s digital economy continues to expand, maintaining confidence in digital payments is fundamental to ensuring that consumers and businesses can participate fully in that growth,” said Jason Phua, Head of Clients, Visa Malaysia. He said maintaining trust requires cooperation between financial institutions, regulators, merchants, technology providers and consumers, with the roadmap providing a common direction for improving the resilience of Malaysia’s payments ecosystem.
Visa Malaysia Security Roadmap 2026-2028 Priorities
The roadmap identifies six areas covering cybersecurity, authentication, tokenization, e-commerce, payment standards and fraud prevention. Visa aims to strengthen cybersecurity through improved cyber readiness, oversight and management of third-party vulnerabilities; it also plans to encourage the adoption of authentication methods beyond SMS one-time passwords (OTPs), including biometrics, in-app authentication and payment passkeys.
The roadmap also promotes tokenized payments, which replace sensitive payment credentials such as personal account numbers (PANs) with tokens, reducing the value of stolen payment data. For e-commerce, the company is calling for more secure checkout processes, including its Click to Pay service. Other priorities include strengthening fraud reporting, merchant onboarding, third-party accountability and compliance, alongside greater use of network-level intelligence and real-time risk detection to address fraud and scams.
Visa said the roadmap assigns responsibilities across different participants in the payments ecosystem. Issuers can strengthen real-time transaction decisions, customer guidance and authentication, while acquirers and merchants can improve onboarding, monitoring and checkout security.
Third-party service providers are expected to maintain data protection, compliance and operational resilience, while regulators and industry bodies can support intelligence sharing, common standards and responsible innovation. Consumers can also reduce exposure to scams by using secure authentication, enabling transaction alerts and remaining alert to suspicious activity.
Visa said it currently has more than 150 AI and machine-learning models in production. Its security capabilities include Visa Advanced Authorization for real-time transaction risk assessment, Visa Consumer Authentication Service, Visa Provisioning Intelligence and Visa Protect for account-to-account payments. The company also cited behavioral analytics from Featurespace, which analyses more than 400 behavioral signals in milliseconds to detect anomalies and potential fraud.
The company also pointed out it has invested more than US$12 billion globally in technology over the past five years to reduce fraud and strengthen network security. Through Visa Scam Disruption, it identified and disrupted more than US$1 billion in fraud attempts over a one-year period and worked with law enforcement agencies to dismantle more than 25,000 scam merchants globally.
Pokdepinion: Stronger payment security will need cooperation across the industry as scams become more sophisticated.

