About

About

I’m Kenneth Wong. I’m based in Kuala Lumpur, and I work on two things: the business side of healthcare operations, and Malaysian cyber security compliance.

My background is in economics and management — I read for my degree at the London School of Economics — and most of my working life has been operational rather than technical: running the administrative and business side of a general practice clinic, and more recently medical tourism. That turns out to be a useful grounding for compliance work. Obligations don’t arrive as abstractions; they arrive as contracts, procedures, deadlines and evidence, which is the same material I’ve been handling for years.

Malaysian cyber security compliance

The Cyber Security Act 2024 changed what’s expected of a number of Malaysian organisations. A lot of what’s written about it is second-hand, and some of it is wrong — including a widely repeated “72-hour breach notification rule” that doesn’t exist anywhere in the law.

So I went to the primary sources instead: the Act itself, the four sets of regulations made under it, all ten of the Chief Executive’s Directives, the National Cyber Security Baseline, and NACSA’s Code of Practice template.

The result is a plain-language guide, free to read:

The Cyber Security Act 2024: What It Actually Means for Your Business

It’s written for businesses trying to work out whether the Act applies to them at all — and it says plainly when the answer is “it doesn’t,” which is the answer for most of them. It also covers the part almost nobody writes about: how the Act’s obligations reach ordinary suppliers through their customers’ contracts, often without the Act ever being mentioned.

My working rule for that material is simple. Every claim should trace back to a primary source. Where the law is genuinely unsettled, I say so rather than guess.

Learning notes

The rest of this site is learning notes. I’m working through security fundamentals — networking, operating systems, how data is actually represented and moved — and writing up what I learn as I go.

These are honest notes rather than authoritative guides. I write them partly to sharpen my own understanding, partly in case they’re useful to someone walking the same path, and I correct them when I get something wrong. Where a note reaches past what I actually know, I try to say so.

I have prior self-directed technical experience, including building quantitative trading systems and doing data analysis, and my interest in security sits mostly on the defensive and governance side: security operations, incident response, and how organisations demonstrate they’re doing what they said they would.

Contact

You can reach me at kenneth@chuinwei.com, or find my code on GitHub.