
Until 2024, cyber risk in Malaysia was governed mostly by sector rules and good intentions. In eighteen months the picture changed: the Cyber Security Act 2024 came into force in August 2024, the Personal Data Protection (Amendment) Act 2024 phased in through 2025, and Bank Negara Malaysia reissued Risk Management in Technology in November 2025. For a board, the question is no longer whether cyber is a regulated matter but which of three regulators is asking, and whether the answers agree.
The threat picture the laws respond to
MyCERT's quarterly incident summaries tell a consistent story: fraud is by far the largest category of reported incident, and reported data-breach incidents rose through the second half of 2025 — 171 in the fourth quarter alone. Ransomware is smaller in count and larger in consequence; the incidents that reach the news involve exfiltration first and encryption second, with the stolen data used to pressure the victim, its customers and sometimes its regulator.
Two features of the Malaysian environment sharpen this. Leaked identity data — MyKad numbers, phone numbers, addresses — feeds the scam economy that MyCERT's fraud figures record, so a breach is rarely contained to the organisation that suffered it. And a large share of the economy runs on shared providers: cloud platforms, payment processors, managed security services. A single supplier incident can land in several regulated entities at once.
Three instruments, three regulators
The Cyber Security Act 2024 (Act 854) protects National Critical Information Infrastructure. NACSA designates NCII entities across eleven sectors — government, banking and finance, energy, water, healthcare, transport, communications and digital, defence, agriculture, trade and industry, science and technology — and each sector has a sector lead. Designated entities must run a cyber security risk assessment every year, be audited at least every two years, report incidents to NACSA, and complete the National Cyber Security Baseline self-assessment. Cyber security service providers need a NACSA licence.
The Personal Data Protection (Amendment) Act 2024 modernised the PDPA: mandatory breach notification to the Commissioner within 72 hours, a mandatory Data Protection Officer for qualifying controllers and processors, direct obligations on processors, a right to data portability, and higher penalties. The obligations came into force in three phases during 2025, with the breach-notification and DPO duties live from 1 June 2025.
Bank Negara Malaysia's Risk Management in Technology, reissued with effect from 28 November 2025, binds licensed banks, insurers and takaful operators, development financial institutions, e-money issuers and payment system operators, and for the first time large non-bank merchant acquirers and remittance intermediaries. It demanded a gap analysis within 90 days and an annual self-assessment thereafter.
Where they overlap — and where they do not
A Malaysian bank is an NCII entity, a data controller and an RMiT institution at once. Its incident-response plan has to satisfy NACSA's incident notification, the Commissioner's 72-hour breach clock and BNM's own reporting expectations — three clocks, three recipients, one incident. Its third-party register has to answer Act 854's supply-chain expectations, the PDPA's new processor obligations and RMiT's external-party assurance paragraphs.
The overlap is the opportunity. Governance, asset inventory, access control, logging, incident readiness and supplier oversight are demanded by all three; evidence collected once against a shared control model serves each regulator's questionnaire. The differences are the trap: NCSB is a maturity instrument with no mandatory floor, RMiT is a binding policy with Standard and Guidance paragraphs, and the PDPA is a law with a criminal penalty regime. Reporting them on the same scale misstates all three.
What a board should ask this quarter
Are we a designated NCII entity, and if so, when was our last annual risk assessment and our last audit? Who is our DPO, and has the 72-hour breach procedure been rehearsed? If we are BNM-regulated, has the RMiT gap analysis produced a plan with dates and owners, and what does the annual self-assessment show? And across all three: which suppliers would take us down, and which of them have we actually assessed?
None of these questions needs a new programme. They need the existing programme to be visible — control by control, with the evidence attached and the regulator's own scale applied. That is what GRCLens carries for Malaysia: the NCSB questionnaire scored NACSA's way, the RMiT catalogue with its 90-day clock as an indicator, and a shared evidence base underneath both.
Keep reading

The Cyber Security Act 2024, two years on: what an NCII entity actually has to do
Act 854 is short on prose and long on duties. A plain reading of the annual risk assessment, the biennial audit, incident notification, the NCSB self-assessment and the sector Codes of Practice.

Enhanced CIRMP Rules 2026: What to Do and When
The enhanced CIRMP Rules commenced on 10 June 2026. What nine high-risk asset classes must do, which frameworks now qualify, and the deadlines.

Saudi OTCC and CSCC: Which NCA Controls Apply?
OTCC-1:2022 covers critical OT and ICS. CSCC-1:2019 covers other critical systems. Scope, control counts, facility levels and the ECC link.