New Act’s role in cybersecurity


MANY governments are passing national cybersecurity regulations and Malaysia recently joined the bandwagon when the Cyber Security Act 2024 (CSA) came into force three months ago.

The CSA requires affected companies to conduct risk assessments and audits periodically. Breaches or hacks must be reported. Non-compliance could result in heavy penalties of up to RM500,000 in fines or worse, a 10-year prison term.

While that sounds worrisome, the CSA only impacts certain sectors. It gives a lengthy description of these organisations – national critical information infrastructure (NCII) entities.

There are 11 such sectors, such as banking and finance, information and communications, healthcare, transport, energy and even the government itself.

Other unusual ones are agriculture and plantations, water, sewage and waste management, but with the increasing usage of digital technologies in these industries, it is clear why cybersecurity will be important.

The CSA has created yet another powerful government body – National Cyber Security Agency (Nacsa) – which has sweeping powers to enforce the law.

Nacsa will also appoint “sector leads”, typically the largest companies in those sectors, which will then come up with more detailed cybersecurity guidelines for each industry.

But before that, the CSA still requires all the companies in its stipulated sectors to do their regular audits and risk assessments.

Will all this require huge expenditure?

Not necessarily, points out Fong Choong Fook who heads local cybersecurity firm LGMS Bhd.

“Cybersecurity does not have to be costly. Smaller companies have less ‘attack surface’. They can apply simple practices like not using pirated software, changing passwords often and avoid using public Wi-Fi for transactions,” he says.

The work for larger companies is more elaborate and investments need to be made.

The CSA mandates that an NCII entity must immediately report cybersecurity incidents to Nacsa and sector leads.

An initial report must be submitted within six hours and should include details such as the description and severity of the incident, along with the method of discovery.

Subsequently, a full report will be due within 14 days.

While mandatory reporting is a new construct for many industries, LGMS’ Fong thinks that the six-hour and 14-day time frame is too lengthy.

For comparison, Singapore’s cybersecurity law requires companies to submit an initial report within two hours of discovering a breach.

KPMG Malaysia’s Muhammad Dawud Wilmot begs to differ, saying it can sometimes take days for a company to identify the source of the incident and that it is “really tough” to come up with a full report within two weeks.

“Imagine managing big infrastructure with thousands of servers. Trying to identify the source of the attack is like looking for a needle in a haystack,” he says.

Some reckon that the scope of the CSA should include sectors like hospitality and retail as some hotels and restaurants have been subject to cyber attacks.

However, Universiti Sains Malaysia associate professor Dr Selvakumar Manickam explains that their disruptions are unlikely to pose an immediate threat to national safety.

He notes, however, that a vast number of online service providers remain outside of the CSA’s purview.

“While the CSA stipulates that eCommerce platforms or supporting services (like payment gateways or logistics providers) could be designated as CII as they involve finance and transportation, the provisions outlining these requirements remain vague and require more detail,” he says.

Certifying cybersecurity experts

The CSA attempts to solve a long-standing problem of who really is certified to carry out cybersecurity-related services. Via the CSA, Nacsa will license such providers.

“It is a good initiative but I am sceptical as to how the government will manage the licensing. Many companies without the expertise, may apply for it and declare themselves as cybersecurity providers. So clear guidelines and specific criteria need to be outlined,” Fong says.

But KPMG’s Dawud says that at least now there will be a body that keeps track of cybersecurity providers’ registrations and certifications.

“Previously, there were no licensing requirements. So now if there are any complaints, you can report to the oversight body in the CSA,” he says.

While the CSA has come into effect, sources say that the government may be providing some lead time for companies to comply, with the intention of raising awareness first.

That said, the readiness for protection against cyber threats remains low. And more hacks and breaches may take place.

“This year was quite colourful as there have been numerous ransomware attacks, data breaches, and significant cybersecurity incidents. The majority of what happened was because of the lack of basic cybersecurity hygiene,” notes Dawud.

He adds that the country and government also face the risk of other nations stealing sensitive economic data like planned investments, contracts or defence strategies.

“As a smaller nation, we may be targeted by countries like the United States, Russia, or China, which have an economic interest in us and want to make money off us by knowing what our plans and tenders are,” Dawud notes.

Malaysia can learn from governments that have sought to build their cyber security defences. Singapore has initiatives to address skill gaps and helps pay for costs incurred by SMEs engaging cybersecurity consultants during the first year.

Britain and Thailand provide incentives for companies to invest in cybersecurity, including free cybersecurity insurance in Britain for those achieving Cyber Essentials certification and tax breaks for high-tech investments in Thailand.

As to how much impact the CSA will have on the country’s many SMEs, Ernst & Young Consulting Sdn Bhd’s Jason Yuen notes that these firms can look forward to improved security in relation to goods and services procured from critical infrastructure providers.

He also notes that while the CSA isn’t directly targeted at SMEs, “we do see that organisations operating within the 11 sectors are likely to have a spillover effect and have increased cybersecurity expectations placed upon them as the industry evolves”.

Get 20% OFF The Star Digital Access

Monthly Plan

RM 13.90/month

RM 11.12/month

Billed as RM 11.12 for the 1st month, RM 13.90 thereafter.

Best Value

Annual Plan

RM 12.33/month

RM 9.87/month

Billed as RM 118.40 for the 1st year, RM 148 thereafter.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Business News

AI to drive Asean+3 growth, 2026 forecast revised higher to 4.1% - AMRO
SkyWorld launches first overseas sales gallery in Ho Chi Minh City
Shein's Hong Kong IPO filing sidesteps Xinjiang cotton controversy
China's industrial profit growth moderates as exports cushion uneven recovery
Local retailers return to net buying with RM223.1mil inflow- MBSB IB
Ringgit opens higher vs US$ ahead of state poll
Indonesia central bank governor Perry Warjiyo steps down in surprise move
FBM KLCI picks up as oil prices subside on Gulf lull
How Singapore's unique monetary policy works
Shares, bonds bounce as oil skid offers inflation relief

Others Also Read