Malaysia’s Cyber Security Act 2024 comes into force today, together with its subsidiary regulations, establishing a statutory framework for protecting National Critical Information Infrastructure (NCII).
Key points
- NCII entities must follow codes of practice.
- Risk assessments and audits are required.
- Incidents must be reported to the National Cyber Security Agency.
- Cyber security service providers must be licensed.
UK suppliers of technology and security services to Malaysian critical infrastructure should prepare for flow-down requirements and check whether the new licensing regime applies to their services.
Source: Cyber Security Act 2024 (Act 854) (NACSA)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.