Loading...
Loading...
Free scoping call. Four-week gap assessment. Board-ready remediation plan. Get ahead of NACSA before your sector regulator gets ahead of you.
The Cyber Security Act 2024 (Act 854) is Malaysia's first dedicated cyber security statute. It puts NACSA on a statutory footing, establishes designated National Critical Information Infrastructure (NCII) operators, and creates binding obligations: a sector-specific code of practice, mandatory risk assessments, mandatory audits, and a mandatory incident-notification regime with statutory time limits.
For most boards, this is the first time cyber-security non-compliance has carried direct statutory criminal liability rather than indirect sectoral penalties.
Most organisations do not fail because they have no controls. They fail because obligations, evidence owners and decision timelines are scattered.
A hospital, bank, ministry and utility do not need the same evidence pack, incident path or security roadmap.
BNM RMiT, payment systems, SWIFT, SOC and third-party risk.
Patient records, clinical uptime, PDPA breach handling and ransomware readiness.
Citizen services, identity systems, public-sector procurement and NCII reporting.
OT/ICS, grid reliability, outage response and safety-critical operations.
• Act came into force: 26 August 2024.
• Risk assessments: required at the cadence prescribed in the Risk Assessment and Audit Compliance Regulations 2024 — typically at least annually for designated NCII assets.
• Audits: required at least once every two years, performed by an audit firm or auditor licensed under section 25.
• Incident notification: material cyber incidents must be reported within the prescribed time window under the Notification Regulations 2024.
• Penalties: fines and imprisonment under sections 20-22 — up to RM500,000 and up to 10 years depending on the offence.
Confirm whether your organisation, asset or service is likely in NCII scope.
Map Act 854 obligations to existing governance, SOC, incident response and risk processes.
Prioritise gaps by statutory exposure, business impact and remediation effort.
Run a board briefing and tabletop exercise to test notification decisions.
Prepare the audit evidence pack before formal regulator or auditor review.
No slide deck, no obligation. We'll tell you straight whether you're likely in NCII scope and what a sensible compliance path looks like.