
This week, Level Five sat down with Anon Security's leadership and technical teams to walk through SSHepherd, our attack surface management platform. The meeting ran longer than scheduled as the technical team kept finding new angles to test.
That is usually a good sign.
Attack surface management has a branding problem. It sounds like a scanning tool, something a security analyst runs once a quarter and files away. In practice, for organisations tied to national critical infrastructure, it is closer to a live inventory of every door left unlocked, updated in real time, and cross-referenced against who is actually trying the handles.
Open ports are the clearest example. A single misconfigured service, exposed during a routine deployment and forgotten, is often how attackers get their first foothold. Traditional scanning catches this weeks later, if at all. SSHepherd's cloaking approach works differently — reducing what is visible to unauthorised probes in the first place, rather than waiting to detect what already got through.
What made the Anon Security conversation useful was the pushback from their technical team on remediation speed. Visibility alone is not the win. The gap between "we found an exposed port" and "it is closed" is where damage happens, and that gap needs to be measured in hours, not audit cycles.
This is also why we keep circling back to a point that shows up across most of our conversations with cybersecurity teams in Malaysia and the region: the technology is rarely the hardest part. Getting leadership and technical teams into the same room, agreeing on what "acceptable exposure" actually means for their organisation, is the harder problem. SSHepherd gives teams the data to have that conversation with facts instead of guesswork.
With Merdeka 2026 approaching, it was a fitting week for the conversation — a reminder that the infrastructure underpinning national security, financial systems, and critical services depends on this unglamorous, ongoing work of closing gaps before someone else finds them.
Level Five will continue working alongside teams like Anon Security's on this, as a shared problem we will work closely to solve in order to build digital resilience in Malaysia.