Maxis is a Malaysian telecommunications operator with a national attack surface worth taking seriously. Founded in 1995 and publicly listed, the company runs over 11,000 network sites, maintains 96% 4G population coverage, and operates more than 23,000km of fibre - touching 7.5 million premises. That's a converged infrastructure spanning mobile, fixed broadband, 5G, and satellite connectivity, which means the threat model cuts across radio access, core network, fibre backhaul, and the consumer-facing digital stack.
The digital lifestyle layer adds further exposure: the Maxis app and the Sooka entertainment platform are customer-facing endpoints that sit alongside traditional telecom services. Security teams here aren't just defending base stations and BSS/OSS systems - they're protecting app-layer authentication, payment flows, and content delivery at national scale.
Maxis serves both consumer and enterprise markets, which splits the defensive mandate between protecting millions of individual subscribers and securing managed services for business clients. The converged solutions push means cloud-native architectures and API-driven integrations are likely in play, expanding the surface further. For anyone working telecom security in Southeast Asia, this is infrastructure that matters.





