Cyber Security Act 2024 (Malaysia): What It Actually Means for Your Business

Cyber Security Act 2024 (Malaysia): What It Actually Means for Your Business

A plain-language guide for Malaysian businesses. Written from the primary sources — the Act, the four regulations, and all ten of the Chief Executive’s Directives.


Start here: the 30-second answer

Most Malaysian businesses are not regulated by the Cyber Security Act 2024.

The Act applies to a National Critical Information Infrastructure entity — an “NCII entity.” You do not become one by being large, by being in an important industry, or by handling sensitive data. You become one because a sector lead formally designates you, and sends you a letter.

There is no register you can look yourself up in. The register exists, but it is classified. There is no self-assessment that makes you one. There is no threshold you cross.

If no letter has arrived, you are not an NCII entity.

But that does not mean the Act cannot affect you. It reaches most businesses through a different route, and usually without anyone mentioning the Cyber Security Act at all.

Work out which of these three you are:

 Your situationGo to
1A designation letter arrived. You are an NCII entity.Door 1
2No letter — but you supply, or want to supply, an organisation that received one.Door 2
3Neither.Door 3

Three doors: Door 1, you received a designation letter. Door 2, you supply an organisation that received one. Door 3, neither.

Door 2 is where most readers belong, and few realise it. Door 3 gets a straight answer, not a sales pitch.


First, the thing many people get wrong

You have probably seen this list, described as “the 11 industries covered by the Act”:

Government · Banking and finance · Transportation · Defence and national security · Information, communication and digital · Healthcare services · Water, sewerage and waste management · Energy · Agriculture and plantation · Trade, industry and economy · Science, technology and innovation

That list is real. It is in the Schedule to the Act. But it is a list of sectors, not a list of who is regulated.

Being in a listed sector does not make you an NCII entity. It identifies the sector in which a sector lead has the power to designate certain entities in that sector. Most businesses in every one of those eleven sectors are not designated and never will be.

Look at one of the sectors on that list: “Trade, industry and economy.” Almost every company in Malaysia is involved in trade or industry in some way. So if simply being in a listed sector made you regulated, nearly every company in the country would be regulated. That is obviously not what the Act was meant to do. The sector list tells you where a sector lead may designate. It does not tell you who has been designated.

If someone tells you that you are “covered by the Act because you are in healthcare,” they are either mistaken or selling you something. Ask them to show you the designation.


Door 2 — Your customer got the letter. The obligations arrive in your contract.

Read this door even if you think you are in Door 3.

How the Act reaches an ordinary business

Every NCII entity must implement its sector’s Code of Practice. That Code requires the entity to manage the security of its supply chain. An NCII entity must:

  • Keep a register of every external service provider, recording the services provided, what sensitive data that provider can access, process or store, an assessed risk level, and their compliance status.
  • Require suppliers to show compliance with a recognised security standard — ISO/IEC 27001 certification “or an equivalent framework.”
  • Put security requirements into supplier contracts — data protection measures, rights to conduct security assessments, breach notification, and compliance with applicable law.
  • Monitor supplier compliance on an ongoing basis, and review the register at least once a year.
  • Have NDAs signed by vendors, contractors and partners before giving them access to anything sensitive.

Read that from your side of the table. Your customer now has a legal duty — carrying a maximum penalty of RM500,000 and 10 years, which cannot be settled out of court, and with personal liability for their directors — to assess you, score you, document you, and bind you by contract.

They will not be relaxed about it.

The part that catches people out

Most guidance assumes this arrives as a security questionnaire: a spreadsheet with 200 questions and a deadline. That does happen, and if it has happened to you, you already know you have a problem.

But there is a second way these obligations reach you, and it is easier to miss.

The obligations arrive as clauses in your contract. A large organisation with a good legal team does not always send a form. It updates its standard contract terms instead. So at your next renewal, the agreement picks up a new data protection schedule, a security addendum, an audit rights clause, a warranty that you hold certain certifications, a breach notification deadline — and an indemnity that makes you pay if any of it turns out to be untrue.

Nobody attaches a note to highlight and say to you: “these are our Cyber Security Act supply chain obligations, now passed on to you.” It reads like standard wording. Your lawyer notes “some new security clauses,” you sign, and the file closes.

You now have ongoing obligations that you have never assessed, cannot prove you meet, and did not know you had taken on.

That is the real risk for most suppliers. Not failing a questionnaire — failing a clause you already signed.

One important distinction, stated honestly

If you are a supplier, the Cyber Security Act 2024 does not make you legally answerable to NACSA. The Act’s duties sit on the designated entity. Nothing in it turns a supplier into a regulated party.

Your exposure is contractual, not statutory. You owe these obligations to your customer, under the agreement you signed. They are enforced through the contract: indemnities, termination, non-renewal, and losing the account. If your revenue depends on that customer, contractual exposure is not a smaller risk. It is a different one, and it should be described accurately.

Separately, and regardless of the Cyber Security Act, the Personal Data Protection Act 2010 (PDPA) applies to you if you handle personal data. Most supplier contracts carry PDPA-driven clauses whether or not the customer is an NCII entity. That duty is statutory, and it is yours.

What to do this week

Three things you can do yourself, at no cost:

  1. Find your most recent contract or renewal with your largest customers. Look for sections headed Confidentiality, Personal Data Protection, Data Security, IT, Service Levels, Audit, or Compliance.
  2. Read what you have promised. Look for phrases such as “appropriate technical and organisational measures,” “shall comply with,” “warrants that,” “shall permit audit,” and any notification deadline.
  3. For each promise, ask the question that matters: if my customer audited me next month, could I prove it?

That last question is the whole exercise. A claim is “we keep data secure.” Evidence is a written policy, dated and reviewed; a record of who can access what; proof that sensitive files are protected when sent. Auditors do not accept claims. They ask for proof.

If you can answer “yes, and here is the document” for every clause, you are in reasonable shape, and this guide has cost you twenty minutes.

If you cannot, you now know where you stand.

One specific thing to check now

If you provide, or buy, either managed security operations centre (SOC) monitoring or penetration testing, the provider must hold a licence issued by NACSA. This is a real licensing requirement, with a maximum penalty of RM500,000 and 10 years for providing or advertising those services without a licence, and it has been fully in force since 1 March 2025. If your customer asks whether your security vendors are licensed, they are asking a question they are required to ask.

Note what is not on that list. Risk assessments, gap analyses, policy work, compliance advice, security awareness training, and answering questionnaires are not licensable services. Only monitoring and penetration testing are.


Door 1 — A designation letter arrived

You are an NCII entity. A clock is running, and several of its deadlines are not in the Act itself.

This is the most important thing to understand: reading the Act is not a compliance programme. The Act sets out the structure. The detailed duties are spread across four sets of regulations and ten Chief Executive’s Directives (Arahan Ketua Eksekutif), which are not gazetted legislation but are binding, and which an auditor will check you against. Several of your duties appear only in the Directives.

Your clock, from the date of designation

WhenWhat
Within 2 weeksComplete the National Cyber Security Baseline self-assessment (Directive No. 4)
Within 21 daysRegister three authorised persons with NC4 — one at management level, two at working level — by email to ncii@nc4.gov.my. Report any change within 7 days (Directive No. 1)
Every yearConduct a cyber security risk assessment
Every 2 yearsUndergo an audit by an auditor approved by the Chief Executive — approval sought at least 30 days before the audit
Within 30 days of completing eitherSubmit the risk assessment report or audit report to the Chief Executive, copied to your sector lead
Within 30 days of any material change to your NCIINotify your sector lead
OngoingImplement your sector’s Code of Practice

If you have an incident

This is where published advice is most often wrong.

There is no 72-hour rule. Several widely circulated Malaysian “compliance guides” state one. It appears to have been copied from the GDPR. It is not in the Act, the regulations, or any Directive.

The actual sequence is much tighter:

  1. Immediately, once the incident comes to your knowledge — notify by email to cert@nc4.gov.my. Not “promptly.” Immediately.
  2. Within 6 hours — submit the required particulars (incident type, description, severity, when it became known, how it was discovered) through the NC4 portal at nc4.gov.my.
  3. Within 14 days — submit supplementary information: what was affected, hosts involved, threat actor details, artefacts, tactics, impact, and action taken.
  4. After that — further updates as the Chief Executive requires.

If the NC4 system is unavailable, the fallback is by telephone (03-8064 4853 / 03-8064 4854) or email to the same address.

Only a registered authorised person may notify. If you have not registered your three people, nobody in your organisation can lawfully make the notification. That is why the 21-day registration deadline matters more than it appears to.

The trigger is also wider than people assume: notification is required for an incident that has occurred or might have occurred.

What it costs to get this wrong

Maximum penalties, from the Act:

ProvisionFailureMaximum
s.21(5)Failing to implement the code of practiceRM500,000 and/or 10 years
s.23(2)Failing to notify a cyber security incidentRM500,000 and/or 10 years
s.27(5)Providing or advertising an unlicensed cyber security serviceRM500,000 and/or 10 years
s.22(7)Failing to conduct a risk assessment or audit, or submit the reportRM200,000 and/or 3 years
s.20(6)Failing to provide required information about your NCIIRM100,000 and/or 2 years

Some offences can be compounded — settled by payment, without prosecution, for up to half the maximum fine. Under the Compounding of Offences Regulations 2024, six offences may be compounded:

ProvisionOffence
s.20(6)NCII entity failing to provide NCII information
s.20(7)Sector lead failing to notify the Chief Executive
s.22(7)Failing to conduct a risk assessment or audit, or submit the report
s.22(8)Failing to comply with the Chief Executive’s directions on a risk assessment or audit
s.24(4)Failing to comply with directions on cyber security exercises
s.32(3)Licensee record-keeping failure

The three heaviest offences are not on that list. Failing to implement the code of practice (s.21(5)), failing to notify an incident (s.23(2)), and providing an unlicensed service (s.27(5)) cannot be settled by payment. They must go to court.

A compounding offer must be made before prosecution starts, requires the written consent of the Public Prosecutor, and lapses 30 days after receipt unless extended.

Section 58 — personal liability

Directors should read this twice:

Where the offence is committed by a body corporate, a director, compliance officer, partner, manager or anyone concerned in its management is deemed to have committed the offence — unless they can show it was committed without their knowledge, or that they took all reasonable precautions and exercised due diligence to prevent it.

You are not only exposed to a company fine. You are personally deemed guilty, and the way out is a due diligence defence, which means evidence: documented decisions, dated assessments, minuted approvals. You cannot create that evidence after the incident. It has to already exist.


Door 3 — Neither. You are not in scope.

Then you are not in scope, and I am not going to suggest otherwise.

You have no duties under the Cyber Security Act 2024. No risk assessment, no audit, no incident notification, no code of practice, no baseline. Nothing on the Door 1 clock applies to you. If a consultant tells you otherwise, ask them to point to the designation letter.

Three honest notes, and then you can get on with your day:

1. The Personal Data Protection Act still applies to you. The PDPA is a separate law with much wider reach. It applies to almost anyone processing personal data commercially, and it has recently been amended. For most SMEs, that is where the real regulatory exposure sits, not the Cyber Security Act.

2. Door 2 can arrive without warning. You are one large customer, or one contract renewal, away from picking up security obligations. Nothing urgent today, but it is worth knowing roughly what that involves before it happens.

3. None of this means your security does not matter. It means it is not a compliance problem. Ransomware does not check whether you were designated.


Three things worth knowing, from working through the actual files

Everything above comes from primary sources. These three points come from working through the tools themselves, and they may save someone a difficult week.

Choosing the right approach in the risk assessment toolkit

NACSA publishes a free Excel toolkit for conducting the risk assessment. On the first screen it asks you to choose one of three approaches — Asset-Based, Event-Based, or both — and notes that the choice cannot be undone.

Choose “Asset Based and Event Based.”

Here is why the selection matters. The Directive governing risk assessments requires you to identify your assets, the threats to them, and the vulnerabilities those threats could exploit. The Event-Based sheets are built around scenarios and do not capture asset, threat and vulnerability fields, so an Event-Based-only workbook will not produce three of the columns that NACSA’s own risk assessment report template asks for. The Event-Based view is genuinely useful — ransomware and insider scenarios sit naturally there — but on its own it will not give you what the Directive requires.

Selecting both gives you the compliance record and the scenario view together.

If you have already selected Event-Based only, your work is not lost. The workbook includes an administrator reset function (AdminResetChoice, reachable through Alt+F8 → select → Run). Running it lets you make the selection again; the rows you have already entered remain in place. This is not covered in the user manual, which is probably why it is not widely known.

Read the Baseline element scores, not just the headline rating

The National Cyber Security Baseline self-assessment tool produces a headline maturity rating — Initial, Basic, Intermediate or Advanced — across 33 elements.

That headline figure reflects how many of the 33 elements you have scored on, rather than how mature you are on each. So an organisation sitting at the lowest non-zero level across most elements can land in a high band, while an organisation that is genuinely strong on a few elements and has not addressed the rest can read as low.

The practical advice is simple: read the 33 element ratings individually and work on the weakest ones. That is better management information, and it is closer to what an auditor will look at.

The self-assessment is self-declared. The audit is not.

The Baseline is something you complete about yourself. The two-yearly audit is carried out by an auditor approved by the Chief Executive, against the Act, the regulations, the Directives, the code of practice and your sector lead’s guidelines, and every finding must be supported by audit evidence.

An organisation that ticks its way to a flattering self-assessment has written down a set of claims it cannot support. That is not compliance.

The gap between “we said yes” and “we can prove yes” is the real work — and it is the same gap a supplier faces on a contract clause.

How much evidence is enough? The instruments tell you that findings must be supported by audit evidence, and the Code of Practice and Baseline tell you which documents must exist. What they do not tell you is exactly how strictly each approved auditor will read a phrase like “appropriate and sufficient measures.” That will vary between auditors and will settle over the first few audit cycles. What is safe to say now is that documentation which is written, dated, approved, reviewed and actually followed is what any auditor will expect. Anyone who claims to know the precise bar today is guessing.


One thing I cannot do for you

Directive No. 10 requires NCII entities to comply with the National Cyber Security Crisis Management Plan. That Plan is classified TERHAD (Restricted). It is watermarked, may not be printed or copied, and is distributed only to the three authorised persons registered with NC4, who sign an undertaking not to share it.

An external consultant therefore cannot lawfully be given it — including me. If a firm offers to advise you on the contents of the Crisis Management Plan, ask how they obtained a copy.

What an adviser can properly do is help build the internal capability, roles and procedures that your own people then map to the Plan themselves.


If you want help: what that looks like

Three levels, so you can see where the free work ends and paid work begins.

Tier 1 — Do it yourself, free

The three steps in Door 2 above, plus a self-assessment checklist you can download and work through on your own contracts. No payment, no obligation. Many businesses will find they are in reasonable shape and need nothing more.

A self-assessment has one real limit, worth stating: it can tell you whether you have a written policy. It cannot tell you whether your “yes” would hold up when an auditor asks for proof, because you cannot objectively test your own evidence. That is where the paid work starts.

Tier 2 — Contract and obligations assessment

A fixed-scope, fixed-fee engagement:

  1. You send the contract (or the relevant clauses) and a short description of your setup.
  2. I map every security, data protection, confidentiality, audit and licensing obligation it places on you.
  3. Each one is classified: met / partly met / not met / cannot evidence.
  4. Each is then evidence-tested: could you prove it to an auditor next month?
  5. You receive a prioritised gap report and a call to go through it.

That is the entire engagement, and it has a defined end.

Tier 3 — Closing the gaps

A separate, separately priced engagement to fix what the report found: drafting the data security policy, the consent process, the incident procedure, the supplier register — the documentation an auditor will ask for.

And a boundary I will state plainly: if closing a gap requires penetration testing or managed SOC monitoring, those are licensed services under the regulations and I do not hold that licence. I will tell you what is needed and refer you to a licensed provider. I will not pretend those are things I can do.


Where this comes from

Every factual claim above traces to a primary source: the Cyber Security Act 2024 (Act 854); the four 2024 regulations on risk assessment and audit periods (P.U. (A) 219), incident notification (P.U. (A) 220), licensing of cyber security service providers (P.U. (A) 221) and compounding of offences (P.U. (A) 222); the ten Chief Executive’s Directives issued under section 13; the National Cyber Security Baseline; and NACSA’s Code of Practice Template. All are published at nacsa.gov.my. I link to them rather than republish them — go and read them.

Where the law is genuinely unsettled, I have said so rather than guessed.


This is an educational guide, not legal advice. It describes the law as I read it from the primary sources. It is not a substitute for advice on your specific circumstances, and it does not create a professional relationship. Where a decision carries real consequences — and under this Act, several carry personal liability for directors — take proper advice.


Kenneth Wong kenneth@chuinwei.com 23 July 2026