NACSA licence in progress
HRDC Claimable · Minimum 5 Delegates · Custom Labs

In-House Corporate Cybersecurity Training

Bespoke cybersecurity training delivered at your offices or virtually. Labs tailored to your sector. HRDC SBL-Khas claim support from day one. Taught by practitioners who work in your industry.

Why in-house beats public intake for enterprise teams

Sector-specific labs

Your team practices on scenarios that reflect your actual environment — Malaysian bank AD topology, AWS VPC with your security group patterns, or OT/IT converged manufacturing floor — not a vendor's generic lab.

Cohort confidentiality

Closed cohort means participants can discuss real infrastructure, real incidents, and real weaknesses without concern about who else is in the room. Public intakes cannot offer this.

Your schedule, your pace

We fit the curriculum to your release calendar and team bandwidth — not the other way around. We can compress a 5-day course to a 3-day intensive or spread it across two weeks.

Better ROI per seat

At 10+ delegates, in-house per-seat costs fall below equivalent public intake prices — and HRDC SBL-Khas claims apply to the full invoice amount, not just a per-seat rate.

Integrated assessment

We can run a skills gap assessment before delivery and a competency evaluation after, giving L&D a measurable before/after score for each participant. Useful for BNM or NACSA training records.

White-label option

For organisations building an internal academy, we can deliver under your brand with your LMS and your documentation templates.

Available training tracks

Offensive / Red Team Track

For security teams building an internal red team or penetration testing capability.

CEH v13CPTEOSCP PrepCRTP (Active Directory)Burp Suite Practitioner

Defensive / Blue Team Track

For SOC analysts, IR teams, and IT security staff responsible for detection and response.

CompTIA Security+SOC Analyst FundamentalsIncident ResponseDigital ForensicsGCFA Prep

GRC / Compliance Track

For compliance officers, internal auditors, and GRC leads at regulated entities.

ISO 27001 Lead ImplementerISO 27001 Lead AuditorCISM PrepCISA PrepPDPA OfficerRMiT Workshop

Cloud Security Track

For cloud architects, DevSecOps engineers, and GRC teams operating in AWS, Azure, or Google Cloud.

CCSKCCSP PrepAWS Security SpecialtyAzure AZ-500/SC-100DevSecOps Practitioner

Sector-specific delivery

Banking & Finance

RMiT §10.49-aligned labs, BNM incident notification scenarios, AD attacks targeting a fictionalised bank network. ISACA CISA/CISM exam prep for the IS audit team.

Government & GLC

NACSA Cyber Security Act 2024 obligations, NCII operator gap workshops, PDPA training for HR and procurement, CompTIA Security+ for IT staff headcount requirements.

Healthcare

PDPA data subject rights in healthcare contexts, medical device security awareness, ransomware response tabletop, ISO 27001 Foundation for clinical IT managers.

Manufacturing & Oil & Gas

OT/IT convergence security awareness, NACSA NCII sectoral controls, Supply chain security workshop, ISO 27001 Lead Implementer for head-office security team.

Technology & Fintech

DevSecOps pipeline integration, cloud security deep-dives (AWS / Azure / GCP), bug bounty methodology for internal security engineers, CCSK for the cloud architecture team.

MNC Regional Hubs

English and Bahasa Malaysia delivery, compliance mapping to parent-company frameworks (NIST CSF, ISO 27001, SOC 2), co-delivery with regional L&D teams.

How it works — 5 steps

01

Scoping call

30-minute call to understand your team size, current certifications, sector, regulatory obligations, and training timeline.

02

Curriculum proposal

Within 3 working days we deliver a written curriculum proposal: objectives, modules, labs, duration, price, and HRDC documentation pack outline.

03

Lab customisation

We configure the cyber range (or use your live sandbox) to reflect your sector: financial network topology, cloud environment, OT DMZ, or generic enterprise estate.

04

Delivery

On your premises, at a KL city-centre venue we provide, or fully virtual. Standard cohort: 1-3 days. Full tracks: 5-10 days spread over 2 weeks.

05

Post-training assets

Competency assessment results, participant completion certificates, HRDC claim documentation pack, and a gap-analysis summary for each participant.

Frequently asked questions

What is the minimum group size for in-house training?

Five participants. Below that threshold the economics of custom lab configuration and dedicated trainer travel do not pencil out, and we recommend joining a public intake instead. For cohorts of 10 or more we offer a 15% group rate, and for 20+ we structure a two-parallel-cohort delivery to keep lab-to-participant ratios productive.

Can you deliver in Bahasa Malaysia?

Yes. Several of our trainers are bilingual (English and Bahasa Malaysia) and we can deliver course content, labs, and assessments in either language or a mixed-language format. For government clients requiring full BM delivery, confirm at scoping and we will assign the appropriate trainer. All official PECB courseware is in English; we provide a BM companion guide for Foundation-level courses.

How do you customise the labs for our sector?

We maintain scenario packs for the four most common Malaysian sectors: BFSI (Windows AD + core banking DMZ), government (Windows and Linux estate with Malaysian e-government app patterns), manufacturing (IT/OT converged flat network with HMI targets), and cloud-native (AWS or Azure VPC with intentionally misconfigured cloud services). We configure the correct scenario pack before delivery and can incorporate assets from your own sandbox or test environment if you provide access.

How does the HRDC claim work for in-house training?

nCrypt is a registered HRD Corp training provider. For in-house engagements we issue an HRD Corp-formatted quotation with the correct scheme code (SBL-Khas), course code, and training provider reference. Your HR or L&D admin submits the grant application through the Employer e-TRiS portal at least 5 working days before training. After training, we provide attendance sheets and certificates of completion for the reimbursement claim. We have guided dozens of Malaysian HR teams through this process.

Can nCrypt deliver training outside Kuala Lumpur?

Yes — we have delivered in-house programmes in Penang, Johor Bahru, Kota Kinabalu, Kuching, and across the Klang Valley. Travel and accommodation costs for out-of-KL delivery are invoiced separately at cost. Virtual VILT delivery eliminates logistics entirely and is suitable for distributed teams.

Can we white-label nCrypt training for our internal academy?

Yes. We offer a white-label programme for organisations running an internal cybersecurity academy. We provide the curriculum, labs, and trainer; your organisation runs it under your brand with your content management system. We can also certify 2-3 of your internal trainers to deliver foundational modules independently after completing our train-the-trainer programme.

Request a scoping call

Tell us your sector, team size, and training goals. We will respond within one working day with a curriculum proposal and indicative pricing.

Enquire about in-house training

We will respond within 1 working day with a curriculum proposal and HRDC-formatted quotation.

Reply within 1 business day. No spam, ever.

Not sure what you need?

Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.