At least 90 government websites are still considered “not secure” despite the government’s announcement on conducting cybersecurity audits on them five months ago.

Malaysiakini’s special report in late July this year found that at least 175 of nearly 700 government websites were “not secure”, which experts warned could lead to personal data breaches and other cybersecurity risks.

Websites are identified as “not secure” when the URL begins with “HTTP” instead of “HTTPS”.

Following that, the Malaysian Communications and Multimedia Commission (MCMC) stated that a cybersecurity audit would be conducted on those websites.

Five months after the announcement, Malaysiakini revisited those websites, on Dec 28, 2021, and found that the security status of 90 websites remained unchanged.

The websites include those of the Enforcement Agency Integrity Commission (EAIC), the Public Complaints Bureau of the Prime Minister’s Office, Istana Budaya, Hospital Kuala Lumpur and websites of local councils of various states.

Of the 90 websites, eight of them, such as the Kedah state government portal and Shah Alam City Council (MBSA), still contain malicious elements, phishing and spam attacks, based on the analysis result on Virustotal, an online tool for malware detection.

Six websites, such as the website of Sultan Ismail Hospital, National Hydraulic Research Institute (NAHRIM) and the Office of Sabah Federal Secretary (PSUP Sabah), were no longer accessible.

Nonetheless, the government has, during the same period, upgraded the security status of 76 websites from HTTP to HTTPS, while removing spam and malicious elements from four websites.

The websites include the National Palace, Defence Ministry and the Covid-19 Malaysia monitoring site.

The URLs of some websites have been changed to reflect the upgraded security status. The websites include the MySMS portal, Institute for Rural Advancement (INFRA), Department of Biosafety (JBK) and some district councils in Terengganu and Sabah.

While some websites have upgraded to HTTPS, visitors on the HTTP websites were not redirected to the HTTPS sites.

The websites, among others, were those of the Anti-Doping Agency (Adamas), National Youth and Sports Department (JBSN), Kuala Terengganu City Council (MBKT) and Federal Territories' Sports Council (MSWP).