AI Infrastructure & Economy / AI news for Malaysia
From the archive · Source report date 21 August 2024
AWS opened Malaysia's second Direct Connect site. Here is what 100Gbps and MACsec meant
The Cyberjaya location added another physical entry point to AWS and upgraded the existing Menara AIMS option. Private connectivity still required deliberate encryption, resilience and last-mile design.

In brief
- AWS opened Malaysia's second Direct Connect location at CSF Telcohub 1 near Kuala Lumpur on 21 August 2024.[1]
- The new site offered dedicated 10Gbps and 100Gbps connections with MACsec available, while the existing Menara AIMS location also gained 10Gbps and 100Gbps MACsec services.[1]
- AWS documentation says MACsec protects the Layer 2 link to the Direct Connect location; it is not end-to-end encryption across every subsequent network segment.[4][5]
AWS expanded Malaysia's private cloud-connectivity choices on the same day it launched the local Region
Malaysia gained a second physical on-ramp to Amazon Web Services on 21 August 2024. AWS said the new Direct Connect location sat inside CSF Telcohub 1 near Kuala Lumpur and could connect Malaysian networks directly to public AWS Regions outside China, AWS GovCloud Regions and Local Zones.[1]
The headline speeds were 10 gigabits and 100 gigabits per second, with MACsec encryption available. AWS simultaneously added the same high-speed MACsec service options to its existing Menara AIMS location. The change expanded the building blocks available to enterprises; it did not create an automatic secure or resilient architecture by itself.[1][4]

The new site added a second Malaysian entry point, not a second AWS Region
Direct Connect is a physical network service that links a customer data centre, office or colocation environment to AWS. The new CSF Telcohub 1 presence became Malaysia's second Direct Connect location alongside Menara AIMS. It was an access point into AWS's network, not another cloud region or availability zone.[1][2]
AWS launched the separate Asia Pacific Malaysia Region with three Availability Zones on the same day. The paired announcements mattered because local compute and local private connectivity solve different parts of an architecture: the Region hosts workloads, while Direct Connect provides a dedicated route from an organisation's network into AWS.[2][1]
A second location can create another design option, but organisations must still procure circuits, arrange cross-connects, configure routing and verify whether last-mile paths, power and providers are genuinely independent. Two dots on a map do not by themselves prove failover.[1][3]

100Gbps increased the ceiling, but workload design still determined the useful capacity
AWS listed dedicated 10Gbps and 100Gbps connections at CSF Telcohub 1 and added both MACsec service speeds at Menara AIMS. The larger port created room for high-volume transfer, replication, analytics and AI data movement, but it did not mean every customer automatically received or needed 100Gbps.[1]
Actual performance depends on purchased capacity, customer equipment, carrier design, routing, application behaviour and the destination service. AWS describes Direct Connect as a way to bypass the public internet for more consistent network performance, not as a blanket latency or uptime guarantee.[1][3]
For a Malaysian team, the sizing exercise should begin with measured traffic, peak transfer windows, recovery objectives and expected growth. A smaller connection with tested redundancy may be more useful than one large circuit with an untested single path.[3]
MACsec protected one Layer 2 link; it did not make Direct Connect end-to-end encrypted
AWS documents MACsec as point-to-point Layer 2 encryption between the customer's edge device and the Direct Connect device. It provides confidentiality, integrity and data-origin authenticity on that cross-connect when supported equipment and keys are correctly configured.[4]
The boundary is important. AWS says Direct Connect traffic is not encrypted by default and states that MACsec is not end-to-end protection across multiple sequential segments. Depending on the workload, teams may still need application encryption, TLS, VPN overlays, key rotation and controls beyond the Direct Connect handoff.[4][5]
MACsec availability also did not mean every connection used it. The customer's router had to support the feature, key material had to be provisioned and the encryption mode had to be chosen. Security evidence therefore comes from the deployed configuration and tests, not the service announcement.[4]
Regulated and AI workloads needed an architecture review, not only a port order
Private connectivity can help Malaysian banks, public services, healthcare organisations and large enterprises control network paths for sensitive workloads. It does not certify compliance on its own. Data classification, encryption, logging, identity, recovery and vendor responsibilities remain separate controls.[5][3]
AI workloads add practical questions about moving training data, retrieving business information and serving latency-sensitive applications. Teams should document which data crosses the link, where it is stored, what happens during failover and whether the public internet becomes an emergency route.[3][2]
The 2024 expansion was therefore meaningful infrastructure progress: another local access point, larger dedicated-port options and link-level encryption capability. Its business value depended on how well Malaysian organisations converted those options into a measured, tested network design.[1][4]
Why Malaysia should care
For Malaysian enterprises, the second location expanded local connectivity choices for cloud and AI workloads, but it did not remove the need to engineer encryption, redundancy, routing and provider diversity.
Enterprise technology teams
A second local facility expanded choices for dedicated AWS connectivity and potential path diversity.[1][3]
Practical move: Map carrier, facility, power and routing dependencies before claiming redundancy.
Security and risk teams
MACsec can protect the Layer 2 cross-connect, but Direct Connect is not encrypted by default or end to end.[4][5]
Practical move: Define the MACsec mode, key lifecycle and additional application or VPN encryption required.
Business and AI owners
Higher port capacity can support large data movement, but value depends on measured demand and recovery needs.[3]
Practical move: Size from traffic evidence and test normal, peak and failover performance before scaling.
What Malaysians can do now
- Inventory application traffic, peak transfers and recovery objectives before selecting port capacity.
- Verify physical and provider diversity across both Malaysian Direct Connect paths.
- Test MACsec, additional encryption, routing failover and monitoring as one end-to-end control set.
What we still do not know
AWS announced the service options; customer deployment and outcome data were not published.
- How many Malaysian organisations activated the new location and at which port speeds after 21 August 2024.
- How many connections enabled MACsec and which encryption modes customers selected.
- What measured latency, availability or cost changes individual Malaysian workloads achieved.
Sources
- 1.AWS announces new Direct Connect location and expansion in Kuala Lumpur, Malaysia Amazon Web Services, 21 August 2024
- 2.Now open — AWS Asia Pacific (Malaysia) Region Amazon Web Services, 21 August 2024
- 3.AWS Direct Connect Amazon Web Services
- 4.MAC Security in Direct Connect Amazon Web Services
- 5.Encryption in AWS Direct Connect Amazon Web Services
- 6.Digital Realty set to enter Malaysia, will acquire 1.5MW data center outside Kuala Lumpur Data Center Dynamics, 20 January 2026
- 7.AIMS launches data center in Kuala Lumpur, Malaysia Data Center Dynamics, 22 July 2024
- 8.PM urges AWS to prioritise Malaysia in strategic partnerships BERNAMA, 26 September 2024


