Loading...
Loading...
Cybersecurity for Malaysian ministries, agencies, GLCs and statutory bodies. Cyber Security Act 2024 readiness, the full NCII obligation lifecycle, licensed-provider trust language, and procurement-friendly evidence packs designed for audit, internal risk and NACSA scrutiny.

Public-sector entities sit at the intersection of three threat streams: sustained state-aligned collection against ministerial communications and citizen identity datasets; hacktivist defacement and denial-of-service around geopolitical flashpoints; and criminal ransomware, which has demonstrated public administration is squarely in the target set. A fourth pressure point is the supply chain — a compromised panel systems integrator yields access into many agencies at once, the same pattern behind SolarWinds and Kaseya globally.
Identify which systems constitute NCII; assess risk annually; commission an independent audit at least once every two years; report incidents to NACSA and the sector lead within the prescribed timeframe; remediate with re-test attestation. The Cyber Security Act 2024 also introduces a licensing regime for cybersecurity service providers offering prescribed services — initially SOC monitoring and penetration testing.
Delivered as a licensed-provider engagement, mapping the entity against NCII obligations — risk assessment cadence, biennial audit readiness, incident reporting workflow, policy framework.
Scoped around production constraints for citizen-facing portals, identity systems and legacy mainframes. Non-disruptive on production, intensive on mirrored staging.
Annual cybersecurity risk assessment evidence pack and biennial audit preparation, aligned to NACSA and sector-lead expectations.
Pre-positioned forensics, named regulator-notification workflow aligned with CSA 2024 reporting timelines, and after-action documentation designed to survive audit.
Policy framework build, control mapping and governance documentation suitable for the biennial audit and internal risk function.
Recurring vulnerability assessment across citizen portals, identity, hybrid cloud and third-party SI access surfaces, feeding the annual risk assessment.
Whether the computer systems the entity owns or operates are essential to service delivery within one of the prescribed NCII sectors, and whether disruption would have a debilitating impact on national security, the economy, public health or public order.
30-minute scoping call with a sector-credentialed consultant.
Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.