This article is written based on an interview with Heng Mok, CISO in Residence (APJ) at Zscaler
Let’s be honest. Nobody actually likes their company VPN. For years, it has been the necessary evil of remote work and corporate compliance. You fire up your laptop, click connect, wait for the inevitable lag, and accept that your internet speed has just been halved. We tolerated this friction because the VPN was primarily used for basic tasks: checking corporate email, accessing static files, and logging into the occasional intranet portal.

But in 2026, the digital landscape has fundamentally shifted. The enterprise world is rushing headlong into the era of Generative AI. We are actively deploying tools like Microsoft Copilot, ChatGPT Enterprise, and custom internal language models to boost productivity. But there is a dirty little secret that many IT departments are quietly panicking about: you simply cannot run a modern, high-bandwidth AI strategy on a network architecture designed in the late 1990s.
The Physics of AI Data and the Heavy Compute Lift
To understand why our infrastructure is breaking, we have to look at the physics of network traffic and the reality of what AI actually demands from your hardware. Generative AI tools are not simple, static web pages. They are incredibly ‘noisy’. Every prompt you type, every generated image, and every line of code analysed requires constant, heavy, real-time data transfer.
More importantly, to prevent employees from accidentally leaking proprietary company data to a public Large Language Model (LLM), all of this traffic needs to be heavily encrypted and constantly inspected by the company’s security stack. This process, known as SSL inspection, is notoriously computationally expensive.

“Generative AI introduces continuous, high-volume encrypted traffic that must be inspected to prevent data leakage, and this simply doesn’t scale well through a VPN concentrator.”
Now, imagine trying to pipe all that heavy, encrypted AI traffic through a traditional VPN concentrator that backhauls everything to a central firewall in your company’s data centre. It is the digital equivalent of trying to drive a Formula 1 car on a kampung dirt road. The suspension will shatter. Legacy on-premises firewalls rely on finite, hardware-bound compute resources. When you suddenly flood them with the massive payloads generated by modern LLMs, the CPUs spike, the appliances hit their absolute limits, and the entire network begins to crawl. Latency goes through the roof, packets get dropped, and the user experience degrades from frustrating to entirely unusable.
The ‘Shadow AI’ Blind Spot: When Security Becomes an Inconvenience
This brings us to the core of the problem, which isn’t actually a technology problem at all; it is a human behaviour problem. Security almost always fails the moment it becomes an inconvenience.

“Users will always find the path of least resistance. If the VPN creates a bottleneck—like latency or poor application performance—they will bypass it, creating a Shadow IT risk.”
Users are incredibly pragmatic creatures. They will always seek the path of least resistance to get their jobs done. If a remote worker in Johor connects to the corporate VPN and finds that their AI summarisation tools take five minutes to load because the traffic is being tromboned back to a strained firewall in Kuala Lumpur, they are going to do what any frustrated employee would do. They will disconnect the VPN.
They will go directly to the internet. And in doing so, they create a massive blind spot for the IT department, a phenomenon known as ‘Shadow AI’. When employees bypass the sanctioned security perimeter to maintain their productivity, the very tool designed to protect the company becomes the catalyst for its vulnerability. The IT team loses complete visibility, and suddenly, highly sensitive customer data or unreleased source code is being pasted into public LLMs without any oversight. The friction of the legacy network essentially forces employees to choose between being secure and being productive.
Cutting the ‘Singapore Hairpin’ Latency Tax
So, how do we fix this bottleneck? The answer lies in shifting the compute burden away from finite, on-premises hardware and moving it into the cloud, right at the edge where the user is actually working. This is precisely why Zscaler’s recent expansion and the deployment of a new, fully co-located data centre in Kuala Lumpur is a massive deal for Malaysian enterprises.
For the longest time, Malaysian businesses have paid what I like to call a ‘latency tax’. To get enterprise-grade cloud security, our internet traffic often had to be routed—or ‘hairpinned’—through regional hubs in Singapore or Hong Kong for inspection before coming back to the user. That physical distance adds milliseconds of delay, which translates to the stuttering Zoom calls and spinning loading wheels we all despise.
By building a local Point of Presence (PoP) right here in KL, Zscaler effectively eliminates that hairpin. The traffic is inspected locally. But beyond just shortening the physical distance, it is about unlocking sheer compute power. Zscaler’s cloud architecture uses elastic compute. It scales dynamically to handle the massive processing load required by AI and SSL inspection without blinking. It changes the entire paradigm from ‘connecting to a corporate network’ to ‘connecting directly to the application securely’.
From ‘Dumb’ Firewalls to ‘Smart’ Edge Security
When you have the elastic compute power to actually inspect the traffic without causing a bottleneck, you can move away from ‘dumb’ security to ‘smart’ security. We aren’t just talking about blocking URLs or banning the word ‘ChatGPT’ across the entire organisation. That is an innovation killer that will leave your company lagging behind the competition.

“At this stage, moving away from legacy VPNs to modern, cloud-based security solutions becomes a functional requirement, better user experience and not just a security preference.”
With the heavy lifting done at the cloud edge, systems can employ inline Data Loss Prevention (DLP) and exact data matching. This means the system can contextually understand what the user is doing. It knows the difference between an employee asking an AI to draft a generic marketing email, versus an employee attempting to paste a snippet of unreleased, proprietary source code into the prompt box. It blocks the dangerous action in real-time, without halting the legitimate work. You get to maintain the speed of innovation while keeping the guardrails firmly in place.
Ultimately, the conversation around cybersecurity in Malaysia needs a fundamental reset. We need to stop viewing security as the ‘Department of No’—the barrier that slows everything down. As we integrate AI deeper into our daily operations, security must evolve into an enabler. If your infrastructure is choking on the compute demands of modern applications, you aren’t just facing a technical debt issue; you are facing a critical business continuity threat.
The death of the VPN is not just a trend for the sake of adopting new technology. It is a mathematical necessity for bandwidth and speed. By processing security locally and leveraging the elastic scale of the cloud, enterprises can finally ensure that the secure path is also the fastest path. And when the secure path is the easiest one to take, the Shadow AI dilemma simply disappears.
This article is written based on an interview with Heng Mok, CISO in Residence (APJ) at Zscaler

Heng Mok
CISO in Residence (APJ), Zscaler
Heng Mok is a practical cyber leader with over 20 years of experience spanning a range of industries and cyber disciplines. Heng has worked on some of the largest transformation programs in Australia in the financial services and energy sectors. He has written security standards for the Open Data Center Alliance and currently sits on a number of CompTIA Cybersecurity Certification committees.
Prior to Zscaler, Heng was the CISO at Australia’s largest integrated energy company, AGL Energy where he led cyber, data governance, and technology risk functions responsible for keeping employees, customers, data, systems, and OT assets safe.
Heng believes that as the adoption of cloud, AI, data analytics, remote working, and digital transformation gains traction, organizations need to have the right people, partners, process, and technology embedded to enable business outcomes.
