By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: IdemiaPublished September 3, 2026

TL;DR: Malaysia's 98% digital usage rate sits alongside 87% concern about digital fraud and 91% concern about personal data theft, according to Idemia Secure Transactions' IPSOS BVA study across 11 countries with more than 3,300 respondents. The gap between usage, understanding, and trust means security must be built into identity, authentication, and transaction flows rather than bolted on later.


At a glance

What this is: This is a consumer trust and digital adoption study showing that Malaysian users are highly digital but increasingly anxious about fraud, data theft, and unclear cyber risk.

Why it matters: It matters to IAM and identity teams because user trust, authentication friction, and fraud exposure increasingly shape how identity controls are designed and accepted in digital services.

By the numbers:

👉 Read Idemia's study on Malaysian digital adoption and cybersecurity trust


Context

Digital adoption has created a governance problem as much as a usability one. When nearly everyone is using digital services, user trust becomes part of the security control surface, especially where authentication, transaction verification, and fraud prevention determine whether people continue to engage. In Malaysia, the signal is not low adoption but a widening gap between comfort with digital services and understanding of the cyber risks behind them.

That gap matters across identity verification, customer authentication, and fraud controls. Consumers may accept digital experiences only if security is visible enough to reassure them but unobtrusive enough not to damage convenience, which pushes organisations toward stronger identity assurance and better transaction integrity. The starting position described in the study is increasingly typical in digitally mature markets, not an outlier.


Key questions

Q: How can organisations reduce fraud without creating excessive user friction?

A: By moving from single-check trust to layered evidence and risk-based escalation. Low-risk journeys can stay fast, but higher-risk actions should require stronger proof, additional context, or step-up review. That reduces blanket friction while making the most valuable trust decisions harder to fake.

Q: Why does user understanding of cyber risk matter to identity and fraud controls?

A: Controls only work when users recognise legitimate prompts and can spot suspicious ones. If people do not understand what fraud looks like, they are more likely to approve fake requests, ignore warnings, or abandon secure flows. Good identity design therefore includes explanation, not just enforcement, so the user becomes part of the protection model.

Q: What signals show that digital trust controls are not keeping pace with fraud risk?

A: Look for rising abandonment during login or verification, repeated support contacts about account access, and user reports that security prompts are confusing or inconsistent. Those are practical indicators that assurance is not landing with the audience. If controls are technically sound but poorly understood, their effectiveness is already being reduced in the field.

Q: How should identity teams prepare for AI-driven fraud and longer-term cryptographic change?

A: Treat them as parallel governance problems. Strengthen fraud detection and transaction monitoring now, while also inventorying which authentication and encryption dependencies would need to change if cryptographic assumptions evolve. The important step is to avoid leaving today’s customer identity experience dependent on future-proofing that has not yet been designed.


Technical breakdown

Digital trust gaps in consumer identity journeys

Consumer digital trust is not a soft sentiment issue. It directly affects whether identity verification, login, step-up checks, and transaction confirmations are accepted or abandoned. When users do not understand how fraud works, they rely on visible signals such as brand trust, friction levels, and the clarity of consent prompts. That makes identity design part of the security model, not just the user experience layer. In practical terms, weak explanation of risk can undermine even sound controls because people bypass, mistrust, or misread them.

Practical implication: design identity flows so users understand why a control appears and what threat it is addressing.

How fraud expectations reshape authentication and verification

The study points to a broader shift in how authentication is judged. Users now expect stronger protection without a corresponding increase in friction, which puts pressure on credential-based models alone. In identity and fraud prevention terms, that means organisations need layered assurance, contextual signals, and adaptive step-up decisions rather than relying on static challenge patterns. This also intersects with privacy and data minimisation, because trust depends on both preventing abuse and limiting unnecessary exposure of personal information.

Practical implication: pair authentication strength with contextual risk scoring and minimise the personal data collected at each step.

AI-driven fraud and quantum risk are changing the threat narrative

The article ties consumer concern to two emerging ideas: AI-driven attacks and quantum computing. AI changes the scale and realism of fraud attempts, while quantum discussions are shaping long-term confidence in cryptographic assurance. For identity programmes, the key point is not speculative future disruption but expectation management today. Users increasingly want proof that their digital interactions are protected against both current fraud techniques and future cryptographic risk. That makes cryptographic agility and fraud monitoring part of the same governance conversation.

Practical implication: start planning for cryptographic agility while strengthening fraud detection and transaction assurance now.


NHI Mgmt Group analysis

Digital trust is now an identity control issue, not just a branding issue. When users feel vulnerable online, their willingness to complete authentication, consent, and transaction verification becomes part of the control environment. That shifts the burden onto identity teams to make assurance understandable as well as technically sound. The better framing is not how to remove friction entirely, but how to make trust legible across identity journeys.

Consumer fraud anxiety exposes the gap between awareness and effective protection. A user who knows cyber risk exists is still poorly protected if the digital journey does not help them recognise fraud attempts or validate legitimate requests. This is where identity verification governance overlaps with fraud prevention and transaction security. Organisations should treat the user’s understanding of risk as a dependency for control effectiveness, not a secondary communication problem.

Encryption, authentication, and tokenization remain the practical baseline for secure digital trust. Those controls matter because they reduce exposure without requiring users to become security experts. The study reinforces a familiar lesson: secure-by-design mechanisms must be embedded into the service flow if trust is to scale. That aligns with NIST SP 800-53 Rev 5 Security and Privacy Controls and with identity governance practices that reduce reliance on user judgement.

Trust and security are becoming measurable product requirements across digital ecosystems. Financial services, telecoms, automotive, IoT, and public-facing digital platforms now compete on whether users feel protected enough to keep using them. This creates a governance problem for identity leaders because assurance, user experience, and fraud resistance are converging. Teams should treat trust signals as operational requirements, not afterthoughts.

What this signals

Verification trust gaps are becoming a programme design issue for identity teams. As users expect stronger protection with less friction, organisations will need to measure how authentication and fraud controls affect completion rates, complaint volume, and abandonment. The next phase of identity governance is not only about stronger controls but about whether those controls are understood and accepted by the people using them.

Cryptographic agility will matter more as digital trust becomes tied to future-proofing. AI-enabled fraud and quantum risk are pushing security leaders to think beyond today’s authentication patterns and review how long-lived identifiers, tokens, and encrypted data are managed. For practitioners, that means building inventory and transition plans now, before a technology shift turns into a governance gap.


For practitioners

  • Embed assurance into high-risk customer journeys Add contextual step-up checks, transaction confirmation, and clear risk messaging to login and payment flows so users understand why extra verification appears.
  • Reduce reliance on static authentication alone Combine device, session, and behavioural signals with identity proofing so fraud controls can adapt when risk changes during a session.
  • Strengthen customer-facing fraud communications Explain common fraud patterns in plain language inside the product experience, because awareness without comprehension does not improve protection.
  • Plan for cryptographic agility in long-lived services Review how authentication, tokenization, and encryption dependencies would change if cryptographic assumptions shift, especially for services that store sensitive personal data.

Key takeaways

  • Malaysia's digital maturity is high, but user trust is under strain from fraud and data-theft concerns.
  • Identity and fraud controls now have to be understandable to users as well as technically strong.
  • Organisations that ignore trust signals risk weakening the effectiveness of their own security journeys.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt.32The study covers personal data theft concerns and trust in digital services.
Review identity journeys and transaction flows to ensure personal data protection is built in by design.
NIST SP 800-63SP 800-63CDigital trust and federation depend on secure, understandable identity assertions.
Strengthen identity assurance and federation controls where users rely on digital services at scale.
NIST CSF 2.0PR.AC-1Authentication and access control are central to consumer digital trust.
Map customer identity flows to access control outcomes and verify they support business risk tolerances.
NIST SP 800-53 Rev 5IA-2Identity proofing and authentication underpin the secure-by-design controls discussed in the study.
Apply authentication controls consistently across high-risk digital interactions and step-up journeys.

Review identity journeys and transaction flows to ensure personal data protection is built in by design.


Key terms

  • Digital Trust: Digital trust is the set of cryptographic and identity controls that allow systems, users, and services to verify each other reliably. It includes PKI, federation, certificates, and authentication foundations that must remain adaptable as technologies and threat conditions change.
  • Identity verification: Identity verification is the process of confirming that a user, workload, or agent is the entity it claims to be before access is granted. In AI-heavy environments, that verification must include the requester, the system acting on its behalf, and the sensitivity of the action.
  • Adaptive Authentication: Adaptive authentication changes the strength of login checks based on context such as device, location, source network, and session history. It helps IAM teams respond to suspicious access without forcing every user through the same high-friction path.
  • Cryptographic agility: The ability to change cryptographic algorithms, key lengths, or trust models without reworking every application. For machine identities, it reduces the risk that long-lived services will fail when standards shift or when post-quantum migration becomes necessary.

What's in the full report

Idemia's full report covers the survey detail this post intentionally leaves for the source:

  • Country-by-country response patterns across the 11 surveyed markets, including how Malaysia compares with other regions
  • The survey methodology and weighting approach behind the 3,300-plus respondent sample
  • Additional findings on how consumers interpret AI-driven attacks, quantum computing, and digital trust
  • The broader IDEMIA Secure Transactions perspective on secure-by-design technologies such as encryption, authentication, and tokenization

👉 Idemia's full study includes the survey detail, market comparisons, and methodology behind the findings.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and workload identity. It helps security practitioners build the governance foundations needed across identity, access, and machine-led workflows.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 4, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org