Cyber Security Act 2024 (Malaysia): What It Actually Means for Your Business
A plain-language guide for Malaysian businesses. Written from the primary sources — the Act, the four regulations, and all ten of the Chief Executive’s Directives.
Start here: the 30-second answer
Most Malaysian businesses are not regulated by the Cyber Security Act 2024.
The Act applies to a National Critical Information Infrastructure entity — an “NCII entity.” You do not become one by being large, by being in an important industry, or by handling sensitive data. You become one because a sector lead formally designates you, and sends you a letter.
There is no register you can look yourself up in. The register exists, but it is classified. There is no self-assessment that makes you one. There is no threshold you cross.
If no letter has arrived, you are not an NCII entity.
But that does not mean the Act cannot affect you. It reaches most businesses through a different route, and usually without anyone mentioning the Cyber Security Act at all.
Work out which of these three you are:
| Your situation | Go to | |
|---|---|---|
| 1 | A designation letter arrived. You are an NCII entity. | Door 1 |
| 2 | No letter — but you supply, or want to supply, an organisation that received a designation letter. | Door 2 |
| 3 | Neither. | Door 3 |
Door 2 is where most readers belong, and few realise it. Door 3 gets a straight answer, not a sales pitch.
A note on data protection (the PDPA) — separate from the rest of this guide.
One law cuts across all three doors. The Personal Data Protection Act (PDPA) applies to almost any business that handles people’s personal data in the course of commercial dealings — whichever door you are in, and whether or not any Cyber Security Act letter ever arrives. It is a different regime, with a different regulator (the Personal Data Protection Commissioner), and it is a separate specialism — the province of data-protection consultants and specialised law firms, not this guide.
The distinction in one line. The Cyber Security Act asks whether your critical systems are resilient and your NCII duties are met — and it applies only once you are designated. The PDPA asks whether you handle people’s data lawfully — and it applies automatically, the moment you hold personal data. Different question, different regulator, different adviser.
Everything else in this guide is about the Cyber Security Act.
First, the thing many people get wrong
You have probably seen this list, described as “the 11 industries covered by the Act”:
Government · Banking and finance · Transportation · Defence and national security · Information, communication and digital · Healthcare services · Water, sewerage and waste management · Energy · Agriculture and plantation · Trade, industry and economy · Science, technology and innovation
That list is real. It is in the Schedule to the Act. But it is a list of sectors, not a list of who is regulated.
Being in a listed sector does not make you an NCII entity. It identifies the sector in which a sector lead has the power to designate certain entities in that sector. Most businesses in every one of those eleven sectors are not designated and never will be.
Look at one of the sectors on that list: “Trade, industry and economy.” Almost every company in Malaysia is involved in trade or industry in some way. So if simply being in a listed sector made you regulated, nearly every company in the country would be regulated. That is obviously not what the Act was meant to do. The sector list tells you where a sector lead may designate. It does not tell you who has been designated.
If someone tells you that you are “covered by the Act because you are in healthcare,” they are either mistaken or selling you something. Ask them to point you to your designation letter.
Door 2 — Your customer got the letter. The obligations arrive in your contract.
Read this door even if you think you are in Door 3.
How the Act reaches an ordinary business
Every NCII entity must implement its sector’s Code of Practice. That Code requires the entity to manage the security of its supply chain. An NCII entity must:
- Keep a register of every external service provider. The Code of Practice Template records six things per provider: provider details (name, contact, role); the services they provide; what sensitive data they can access, process or store; an assessed risk level; their compliance status (e.g. certification and contractual obligations); and the contract details (agreement references and the data-protection, security and breach-notification clauses).
- Require suppliers to show compliance with a recognised security standard — ISO/IEC 27001 certification “or an equivalent framework.”
- Put security requirements into supplier contracts — data protection measures, rights to conduct security assessments, breach notification, and compliance with applicable law.
- Monitor supplier compliance on an ongoing basis, and review the register at least once a year.
- Have NDAs signed by vendors, contractors and partners before giving them access to anything sensitive.
Read that from your side of the table. Your customer now has a legal duty — carrying a maximum penalty of RM500,000 and 10 years, which cannot be settled out of court, and with personal liability for their directors — to assess you, score you, document you, and bind you by contract.
They will not be relaxed about it.
The part that catches people out
Most guidance assumes this arrives as a security questionnaire: a spreadsheet with 200 questions and a deadline. That does happen, and if it has happened to you, you already know you have a problem.
But there is a second way these obligations reach you, and it is easier to miss.
The obligations arrive as clauses in your contract. A large organisation with a good legal team does not always send a form. It updates its standard contract terms instead. So at your next renewal, the agreement picks up a new data protection schedule, a security addendum, an audit rights clause, a warranty that you hold certain certifications, a breach notification deadline — and an indemnity that makes you pay if any of it turns out to be untrue.
Nobody attaches a note to highlight and say to you: “these are our Cyber Security Act supply chain obligations, now passed on to you.” It reads like standard wording. Your lawyer notes “some new security clauses,” you sign, and the file closes.
You now have ongoing obligations that you have never assessed, cannot prove you meet, and did not know you had taken on.
That is the real risk for most suppliers. Not failing a questionnaire — failing a clause you already signed.
One important distinction, stated honestly
If you are a supplier, the Cyber Security Act 2024 does not make you legally answerable to NACSA. The Act’s duties sit on the designated entity. Nothing in it turns a supplier into a regulated party.
Your exposure is contractual, not statutory. You owe these obligations to your customer, under the agreement you signed. They are enforced through the contract: indemnities, termination, non-renewal, and losing the account. If your revenue depends on that customer, contractual exposure is not a smaller risk. It is a different kind of risk — commercial and contractual, owed to your customer — and it should be named as that, not dressed up as a regulator at your door.
What to do this week
Three things you can do yourself, at no cost:
- Find your most recent contract or renewal with an important customer — start with the relationship you would least want to lose. (You cannot tell from the outside which organisations have been designated as NCII entities; that register is not public. So this is about where the consequences to you would be greatest, not about guessing who is designated.) Look for sections headed Confidentiality, Personal Data Protection, Data Security, IT, Service Levels, Audit, or Compliance.
- Read what you have promised. Look for phrases such as “appropriate technical and organisational measures,” “shall comply with,” “warrants that,” “shall permit audit,” and any notification deadline.
- For each promise, ask the question that matters: if my customer audited me next month, could I prove it?
That last question is the whole exercise. A claim is “we keep data secure.” Evidence is a written policy, dated and reviewed; a record of who can access what; proof that sensitive files are protected when sent. Auditors do not accept claims. They ask for proof.
If you can answer “yes, and here is the document” for every clause, you are in reasonable shape, and this guide has cost you twenty minutes.
If you cannot, you now know where you stand.
One specific thing to check now
If you provide, or buy, either managed security operations centre (SOC) monitoring or penetration testing, the provider must hold a licence issued by NACSA. This is a real licensing requirement, with a maximum penalty of RM500,000 and 10 years for providing or advertising those services without a licence, and it has been fully in force since 1 March 2025. If your customer asks whether your security vendors are licensed, they are asking a question they are required to ask.
Note what is not on that list. Risk assessments, gap analyses, policy work, compliance advice, security awareness training, and answering questionnaires are not licensable services. Only monitoring and penetration testing are.
Door 1 — A designation letter arrived
You are an NCII entity. A clock is running, and several of its deadlines are not in the Act itself.
This is the most important thing to understand: reading the Act by itself will not tell you what you have to do. The Act sets out the structure — who can be designated, who enforces it, what the penalties are — but it deliberately leaves the operational detail to instruments made under it. Your actual duties are spread across three layers: the Act, four sets of regulations made under it, and ten Chief Executive’s Directives (Arahan Ketua Eksekutif). The Directives are not gazetted legislation, but they are binding, and an auditor will check you against them. Several of your concrete duties — including the deadline to register your authorised persons, and exactly what a risk assessment must contain — appear only in the Directives, nowhere in the Act. So an organisation that reads only the Act, however carefully, will miss obligations it is nonetheless bound by.
Your clock, from the date of designation
The designation takes effect from the date stated in your letter (Directive No. 3). Everything below runs from that date.
| When | What | Where it’s set |
|---|---|---|
| Within 2 weeks | Complete the National Cyber Security Baseline self-assessment | Directive No. 4 |
| Within 21 days | Register three authorised persons with NC4 — one at management level, two at working level — by email to ncii@nc4.gov.my | Directive No. 1 |
| Whenever an authorised person changes | Report the change to NC4 within 7 days of it happening | Directive No. 1 |
| At least once a year | Conduct a cyber security risk assessment | s.22(1)(a) + P.U.(A) 219 reg 3(a); method set by Directive No. 5 |
| At least once every 2 years | Undergo an audit by an auditor approved by the Chief Executive (approval sought at least 30 days before it begins) | s.22(1)(b) + P.U.(A) 219 reg 3(b); method set by Directive No. 8 |
| Within 30 days of finishing a risk assessment or audit | Submit the report to the Chief Executive, copied to your sector lead | s.22(2) sets the report-to-CE duty; the sector-lead copy is required by Directive No. 5 (risk assessment) and Directive No. 8 (audit) |
| Within 30 days of a material change to your NCII | Notify your sector lead | s.20 |
| Ongoing | Implement your sector’s Code of Practice | s.21 |
On “once a year” and “once every two years.” The regulations set a frequency, not a fixed calendar date. “At least once every two years” runs from your date of designation — so if you were designated in March, your first audit cycle is the two years from that March, and the audit must be completed within it. The report is then due within 30 days of the audit finishing. The safe reading is: don’t treat these as “sometime in year two” — plan the engagement so it finishes, and the report is submitted, before the period ends.
On the authorised persons. Within 21 days of designation you email ncii@nc4.gov.my with the details of your three nominated people (one management, two working level). After that, if you ever change one of them — someone leaves, or you swap who holds the role — you notify the same address within 7 days of that change. The reason this deadline matters more than it looks: only a registered authorised person can lawfully file an incident notification. If you haven’t registered anyone, you have nobody who can report an incident when one happens.
What counts as a “material change.” The Act defines it as a change that affects, or may affect, the cyber security of your NCII or your ability to respond to a threat or incident (s.20(4)). In practice that includes things like a significant change to the design, configuration, security or operation of the system, or — at the extreme — losing ownership or control of the computer or system that performs the nationally-important function. If in doubt, the 30-day clock is short, so err towards notifying.
If you have an incident
This is where published advice is most often wrong.
There is no 72-hour rule. Several widely circulated Malaysian “compliance guides” state one. It appears to have been copied from the GDPR. It is not in the Act, the regulations, or any Directive.
The actual sequence is much tighter.
Your clock, from the moment an incident comes to your knowledge
| When | What | Where it’s set |
|---|---|---|
| Immediately | Notify by email to cert@nc4.gov.my — not “promptly,” immediately | P.U.(A) 220 reg 2(1); Directive No. 1 |
| Within 6 hours | Submit the required particulars — incident type, description, severity, when it became known, how it was discovered — through the NC4 portal at nc4.gov.my | P.U.(A) 220 reg 2(2) |
| Within 14 days | Submit supplementary information — what was affected, hosts involved, threat actor details, artefacts, tactics, impact, action taken | P.U.(A) 220 reg 2(3) |
| After that | Further updates as the Chief Executive requires | P.U.(A) 220 reg 2(4) |
If the NC4 system is unavailable, the fallback is by telephone (03-8064 4853 / 03-8064 4854) or email to the same address.
Only a registered authorised person may notify. If you have not registered your three people, nobody in your organisation can lawfully make the notification. That is why the 21-day registration deadline matters more than it appears to.
The trigger is also wider than people assume: notification is required for an incident that has occurred or might have occurred.
What it costs to get this wrong
Maximum penalties, from the Act:
| Provision | Failure | Maximum |
|---|---|---|
| s.21(5) | Failing to implement the code of practice | RM500,000 and/or 10 years |
| s.23(2) | Failing to notify a cyber security incident | RM500,000 and/or 10 years |
| s.27(5) | Providing or advertising an unlicensed cyber security service | RM500,000 and/or 10 years |
| s.22(7) | Failing to conduct a risk assessment or audit, or submit the report | RM200,000 and/or 3 years |
| s.20(6) | Failing to provide required information about your NCII | RM100,000 and/or 2 years |
Some offences can be compounded — settled by payment, without prosecution, for up to half the maximum fine. Under the Compounding of Offences Regulations 2024, six offences may be compounded:
| Provision | Offence |
|---|---|
| s.20(6) | NCII entity failing to provide NCII information |
| s.20(7) | Sector lead failing to notify the Chief Executive |
| s.22(7) | Failing to conduct a risk assessment or audit, or submit the report |
| s.22(8) | Failing to comply with the Chief Executive’s directions on a risk assessment or audit |
| s.24(4) | Failing to comply with directions on cyber security exercises |
| s.32(3) | Licensee record-keeping failure |
The three heaviest offences are not on that list. Failing to implement the code of practice (s.21(5)), failing to notify an incident (s.23(2)), and providing an unlicensed service (s.27(5)) cannot be settled by payment. They must go to court.
What “compounding” means in plain terms. Compounding is settling an offence by paying a sum of money instead of being prosecuted in court. For the six offences on the list, the Chief Executive may offer the offender the chance to pay a compound — up to half the maximum fine — and if the offender pays, no prosecution follows and there is no criminal conviction. The offer must be made before prosecution begins, requires the written consent of the Public Prosecutor, and lapses 30 days after it is received unless the time is extended. It is a way out for the lesser offences — but note again that the three heaviest offences are not eligible, so for those there is no paying your way out.
Section 58 — personal liability
Directors should read this twice:
Where the offence is committed by a body corporate, a director, compliance officer, partner, manager or anyone concerned in its management is deemed to have committed the offence — unless they can show it was committed without their knowledge, or that they took all reasonable precautions and exercised due diligence to prevent it.
You are not only exposed to a company fine. You are personally deemed guilty, and the way out is a due diligence defence, which means evidence: documented decisions, dated assessments, minuted approvals. You cannot create that evidence after the incident. It has to already exist.
Door 3 — Neither. You are not in scope.
Then you are not in scope, and I am not going to suggest otherwise.
You have no duties under the Cyber Security Act 2024. No risk assessment, no audit, no incident notification, no code of practice, no baseline. Nothing on the Door 1 clock applies to you. If a consultant tells you otherwise, ask them to point you to your designation letter.
Two honest notes, and then you can get on with your day:
1. Door 2 can arrive without warning. You are one large customer, or one contract renewal, away from picking up security obligations. Nothing urgent today, but it is worth knowing roughly what that involves before it happens.
2. None of this means your security does not matter. It just means it isn’t a compliance problem — but you still have to watch out for attacks; ransomware doesn’t check whether you were designated.
Three things worth knowing, from working through the actual files
Everything above comes from primary sources. These three points come from working through the tools themselves, and they may save someone a difficult week.
Choosing the right approach in the risk assessment toolkit
Risk assessment is one of the recurring Door 1 duties — a designated entity must run one at least once a year — and its point is to surface the weaknesses an attacker could exploit, before they do. NACSA publishes a free Excel toolkit for conducting it. On the first screen it asks you to choose one of three approaches — Asset-Based, Event-Based, or both — and notes that the choice cannot be undone.
Choose “Asset Based and Event Based.”
Here is why the selection matters. The Directive governing risk assessments requires you to identify your assets, the threats to them, and the vulnerabilities those threats could exploit. The Event-Based sheets are built around scenarios and do not capture asset, threat and vulnerability fields, so an Event-Based-only workbook will not produce three of the columns that NACSA’s own risk assessment report template asks for. The Event-Based view is genuinely useful — ransomware and insider scenarios sit naturally there — but on its own it will not give you what the Directive requires.
Selecting both gives you the compliance record and the scenario view together.
If you have already selected Event-Based only, your work is not lost. The confirmation prompt says the choice cannot be undone, and the buttons lock — but the workbook includes an administrator reset macro (AdminResetChoice, reachable through Alt+F8 → select → Run) that clears the stored choice and re-enables the buttons so you can select again. The rows you have already entered are retained in the workbook; which sheets are then displayed simply follows your new selection (so choose “Asset Based and Event Based” and everything reappears). This reset is not mentioned anywhere in the user manual, which is probably why it is not widely known.
Read the Baseline element scores, not just the headline rating
The National Cyber Security Baseline self-assessment tool produces a headline maturity rating — Initial, Basic, Intermediate or Advanced — across 33 elements.
That headline figure reflects how many of the 33 elements you have scored on, rather than how mature you are on each. So an organisation sitting at the lowest non-zero level across most elements can land in a high band, while an organisation that is genuinely strong on a few elements and has not addressed the rest can read as low.
The practical advice is simple: read the 33 element ratings individually and work on the weakest ones. That is better management information, and it is closer to what an auditor will look at.
The self-assessment is self-declared. The audit is not.
The Baseline is something you complete about yourself. The two-yearly audit is carried out by an auditor approved by the Chief Executive, against the Act, the regulations, the Directives, the code of practice and your sector lead’s guidelines, and every finding must be supported by audit evidence.
An organisation that ticks its way to a flattering self-assessment has written down a set of claims it cannot support. That is not compliance.
The gap between “we said yes” and “we can prove yes” is the real work — and it is the same gap a supplier faces on a contract clause.
How much evidence is enough? The instruments tell you that findings must be supported by audit evidence, and the Code of Practice and Baseline tell you which documents must exist. What they do not tell you is exactly how strictly each approved auditor will read a phrase like “appropriate and sufficient measures.” That will vary between auditors and will settle over the first few audit cycles. What is safe to say now is that documentation which is written, dated, approved, reviewed and actually followed is what any auditor will expect. Anyone who claims to know the precise bar today is guessing.
One thing I cannot do for you
Directive No. 10 requires NCII entities to comply with the National Cyber Security Crisis Management Plan. That Plan is classified TERHAD (Restricted). It is watermarked, may not be printed or copied, and is distributed only to the three authorised persons registered with NC4, who sign an undertaking not to share it.
An external consultant therefore cannot lawfully be given it — including me. If a firm offers to advise you on the contents of the Crisis Management Plan, ask how they obtained a copy.
What an adviser can properly do is help build the internal capability, roles and procedures that your own people then map to the Plan themselves.
If you want help: what that looks like
Three levels, so you can see where the free work ends and paid work begins.
Tier 1 — Do it yourself, free
The three steps in Door 2 above, plus a self-assessment checklist you can download and work through on your own contracts. No payment, no obligation. Many businesses will find they are in reasonable shape and need nothing more.
A self-assessment has one real limit, worth stating: it can tell you whether you have a written policy. It cannot tell you whether your “yes” would hold up when an auditor asks for proof, because you cannot objectively test your own evidence. That is where the paid work starts.
Tier 2 — Contract and obligations assessment
A fixed-scope, fixed-fee engagement:
- You send the contract (or the relevant clauses) and a short description of your setup.
- I map every security, data protection, confidentiality, audit and licensing obligation it places on you.
- Each one is classified: met / partly met / not met / cannot evidence.
- Each is then evidence-tested: could you prove it to an auditor next month?
- You receive a prioritised gap report and a call to go through it.
That is the entire engagement, and it has a defined end.
Tier 3 — Closing the gaps
A separate, separately priced engagement to fix what the report found: drafting the data security policy, the access-control policy, the incident procedure, the supplier register — the documentation an auditor will ask for.
And a boundary I will state plainly: if closing a gap requires penetration testing or managed SOC monitoring, those are licensed services under the regulations and I do not hold that licence. I will tell you what is needed and refer you to a licensed provider. I will not pretend those are things I can do.
Where this comes from
Every factual claim above traces to a primary source: the Cyber Security Act 2024 (Act 854); the four 2024 regulations on risk assessment and audit periods (P.U. (A) 219), incident notification (P.U. (A) 220), licensing of cyber security service providers (P.U. (A) 221) and compounding of offences (P.U. (A) 222); the ten Chief Executive’s Directives issued under section 13; the National Cyber Security Baseline; and NACSA’s Code of Practice Template. All are published at nacsa.gov.my. I link to them rather than republish them — go and read them.
Where the law is genuinely unsettled, I have said so rather than guessed.
This is an educational guide, not legal advice. It describes the law as I read it from the primary sources. It is not a substitute for advice on your specific circumstances, and it does not create a professional relationship. Where a decision carries real consequences — and under this Act, several carry personal liability for directors — take proper advice.
Kenneth Wong kenneth@chuinwei.com 23 July 2026