An Overview of Malaysia's Cyber Security Act 2024
- Muhammad Akhlil Ridza

- May 1, 2024
- 4 min read
In an era where cyber threats are increasingly sophisticated and relentless, Malaysia has taken a significant step forward with the introduction of the Cyber Security Act 2024 (“the Act”) which has come into force on 26th August 2024. For businesses operating in Malaysia, understanding and complying with the Act is not just a legal obligation but a strategic imperative. This article provides an in-depth overview of the Act and its implications for businesses.
This pivotal legislation forms a thorough legal structure aimed at protecting the National Critical Information Infrastructure (“NCII”) amidst a growing array of cyber threats. The Act establishes the National Cyber Security Committee and outlines the duties and powers of the Chief Executive of the National Cyber Security Agency (“NACSA”). Additionally, it defines particular roles for leads and entities within the NCII sectors.
Key Provisions of The Act
The Act encompasses several vital provisions that businesses need to be aware of:
Risk Assessment and Audit regulations
According to the Act, entities designated as NCII must adhere to rigorous risk assessment and audit protocols. These organizations are mandated to perform an exhaustive cybersecurity risk assessment at a minimum of once per year. This involves identifying potential vulnerabilities that could be exploited by cyber threats or incidents within the NCII. Furthermore, NCII entities must be audited biennially or more frequently if instructed by the Chief Executive of NACSA. The sectors that have been designated as NCII sectors by the government include 1) Government, 2) Healthcare, 3) Energy, 4) Agriculture, 5) Science, technology, and innovation, 6) Trade, industry, and economy, 7) Information, communication, and digital, 8) Banking and finance, 9) Defence, national security, and transportation and 10) Water, waste management, and sewage treatment.
Notification of Incidents
NCII entities must promptly notify the Chief Executive of NACSA and their NCII Sector Leads about any cybersecurity incidents, doing so electronically once identified. Within six hours, they must detail the incident via the National Cyber Coordination and Command Centre System (NC4S), including its nature, severity, and discovery. Additional details on the impact and response actions must be provided within 14 days of the first notification.
Licenses for Cyber Security Service Providers
The Act establishes a licensing system for Cyber Security Service Providers which are entities or individuals delivering cybersecurity services, including managing security operation centers, monitoring and penetration testing whereby they are required to secure a license from the authorities. However, the Act exempts specific services, such as those rendered by government bodies or within a company and its subsidiaries, from these licensing obligations.
Possible Offenses and Penalties
Violations under the Act cover a spectrum of issues, from neglecting required risk assessments and audits to failing to report cybersecurity incidents to relevant authorities. These infractions can lead to penalties including fines of up to RM200,000.00, imprisonment for up to three (3) years, or both.
More serious breaches, such as disregarding licensing requirements or not implementing mandated cybersecurity measures, can result in fines reaching RM500,000.00 and imprisonment for up to ten (10) years. The Act also extends accountability beyond organizations to their employees and agents, making individuals responsible for compliance within the entity liable as well.
The Importance of Compliance
Compliance with the Act 2024 is essential for businesses for several reasons:
Protecting Sensitive Data
With the increasing volume of data generated and stored by businesses, protecting sensitive information has become paramount. Compliance with the Act ensures that businesses implement robust security measures to safeguard customer data, intellectual property, and other critical information.
Mitigating Financial Loss
Cyber incidents can result in significant financial losses for businesses. Data breaches, ransomware attacks, and other cyber threats can disrupt operations, lead to legal liabilities, and damage an organization's reputation. By adhering to the Act's provisions, businesses can mitigate the financial impact of cyber incidents and minimize the risk of costly breaches.
Ensuring Business Continuity
A cyber incident can severely disrupt business operations and lead to extended downtime. Compliance with the Act helps businesses establish effective incident response and recovery plans, ensuring that they can quickly resume normal operations in the event of a breach. This is crucial for maintaining customer trust and minimizing the impact of disruptions.
Building Customer Trust
Customers are becoming increasingly concerned about the security of their personal information. Demonstrating compliance with the Act can enhance a business's reputation and build customer trust. Customers are more likely to engage with businesses that prioritize the protection of their data and have robust security measures in place.
Steps to Achieve Compliance
Achieving compliance with the Act requires a systematic approach. Businesses should consider the following steps:
Conduct a Cyber Security Audit
Begin by conducting a comprehensive cyber security audit to assess the current state of your organization's security posture. Identify vulnerabilities, evaluate existing policies and procedures, and determine areas that need improvement.
Develop and Implement Cyber Security Policies
Based on the findings of the audit, develop and implement cyber security policies that align with the requirements of the Act. Ensure that these policies address key areas such as data protection, incident response, and employee training.
Conduct Regular Risk Assessments
Regularly conduct risk assessments to identify emerging threats and vulnerabilities. Update your cyber security measures accordingly to stay ahead of potential risks.
Train Employees
Provide comprehensive cyber security training for your employees. Ensure that they are aware of best practices for protecting sensitive information and responding to cyber threats.
Establish an Incident Response Plan
Develop a well-defined incident response plan that outlines the steps to be taken in the event of a cyber incident. Ensure that all employees are familiar with the plan and know their roles and responsibilities.
Monitor and Review
Continuously monitor and review your cyber security measures to ensure ongoing compliance with the Act. Stay updated on the latest cyber threats and adjust your policies and procedures as needed.
Partnering with Cyber Security Experts
Given the complexity of the Act and the evolving nature of cyber threats, businesses may benefit from partnering with cyber security experts. These professionals can provide valuable insights, conduct thorough assessments, and help develop and implement effective security measures.
Conclusion
The Act marks a significant milestone in Malaysia's efforts to combat cyber threats and protect digital assets. For businesses, compliance with the Act is not just a legal requirement but a strategic necessity. By understanding the key provisions of the Act and taking proactive steps to achieve compliance, businesses can safeguard their sensitive information, mitigate financial risks, and build trust with their customers. As cyber threats continue to evolve, staying ahead of the curve and prioritizing cyber security will be crucial for the success and resilience of businesses in Malaysia.


