World Watch/Brunei/Cybersecurity

Cybersecurity · Brunei

Cybersecurity - Brunei

Comprehensive lawCybersecurity Act, Chapter 272 (S 20/2023, Revised Edition 2024), administered by Cyber Security Brunei (CSB); complemented by the Computer Misuse Act (Chapter 194, 2007) and Personal Data Protection Order (PDPO) 2025

Brunei enacted its standalone Cybersecurity Act via Cybersecurity Order (S 20/2023) on 20 May 2023, consolidated as Chapter 272 in the 2024 Revised Edition. The Act establishes a national cybersecurity oversight regime centred on protecting Critical Information Infrastructure (CII) across ten essential-service sectors, with mandatory incident-reporting duties for CII owners under Section 16. The PDPO 2025 adds a 3-calendar-day data-breach notification requirement for private-sector organizations.

Cybersecurity Act (Chapter 272)

Passed as a Legislative Order on 20 May 2023 and revised in 2024, the Act creates a comprehensive legal framework for national cybersecurity oversight, designates Cyber Security Brunei (CSB) as the competent authority, and imposes binding duties on Critical Information Infrastructure (CII) owners across ten sectors including energy, banking and finance, healthcare, and defence.

CII Obligations & Code of Practice

CII owners must implement detection systems, conduct risk assessments, and follow the Code of Practice for CII issued by CSB. Non-compliance carries fines up to BND 100,000 and/or imprisonment up to 2 years, plus BND 5,000 per day for continuing offences.

Incident Reporting (CII — Section 16)

Section 16 of the Cybersecurity Act requires CII owners to notify the Commissioner of Cybersecurity of prescribed cybersecurity incidents. As of 2025, the specific incident categories and reporting timelines are pending subordinate regulation, but the notification duty is in force.

PDPO 2025 — Breach Notification

The Personal Data Protection Order, gazetted 8 January 2025 and enforced by AITI, requires private-sector organisations to notify the Responsible Authority within 3 calendar days of assessing a data breach likely to cause significant harm to affected individuals.

Financial Sector — BDCB Sectoral Notices

The Brunei Darussalam Central Bank (BDCB) supplements the Act with sector-specific cybersecurity notices for banks: a January 2024 Notice on Early Detection of Cyber Intrusion and Incident Reporting, a June 2023 Technology Risk Management Notice, and a 2025 Compliance and Security by Design Notice (TRS/N-2/2025/1).

BruCERT & National Framework

The Brunei Computer Emergency Response Team (BruCERT), established in 2004 and operating under CSB, serves as the national CERT coordinating incident response with international CERTs, ISPs, and government agencies. CSB also maintains the voluntary Brunei National Cyber Security Framework as a risk-reduction guide for all organisations.

Machine-assisted translation · verified 5/24/2026 · orientation, not legal advice. English version →