World Watch/Malaysia/Cybersecurity

Cybersecurity · Malaysia

Cybersecurity regulation in Malaysia (2026)

Comprehensive lawCyber Security Act 2024 (Act 854), administered by the National Cyber Security Agency (NACSA), supplemented by sector-specific rules and the Personal Data Protection Act (PDPA) for personal-data breaches.Country index 87 · A

Malaysia shaded by its cybersecurity status

Malaysia has a comprehensive, dedicated cybersecurity law: the Cyber Security Act 2024 (Act 854), which came into force on 26 August 2024 together with four subsidiary regulations. It establishes a National Cyber Security Committee, empowers the Chief Executive of NACSA, and imposes mandatory risk assessments, audits, incident reporting and service-provider licensing focused on National Critical Information Infrastructure (NCII). Separately, the amended PDPA introduced a mandatory personal-data breach-notification regime effective 1 June 2025.

Key points

Comprehensive law in force

The Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into operation on 26 August 2024, creating a National Cyber Security Committee (JKSN) and defining the powers of NACSA's Chief Executive and the roles of NCII sector leads and entities.

NCII focus across 11 sectors

The Act centres on protecting National Critical Information Infrastructure across 11 vital sectors (including government, banking/finance, defence, healthcare, energy and transport), imposing duties such as mandatory cyber security risk assessments and audits within prescribed periods.

Mandatory incident reporting (tiered)

Under the Cyber Security (Notification of Cyber Security Incident) Regulations 2024, NCII entities must give immediate electronic notification, an initial submission within 6 hours, and a supplemental report within 14 days; failure can lead to fines up to RM500,000 and/or imprisonment up to 10 years.

Four subsidiary regulations

The Act is operationalised by four regulations: Notification of Cyber Security Incident; Period for Cyber Security Risk Assessment and Audit; Compounding of Offences; and Licensing of Cyber Security Service Provider Regulations 2024.

Licensing of cyber security service providers

Providers of two prescribed services — managed security operation centre (SOC) monitoring and penetration testing — must hold a NACSA-issued licence; the regime applies to providers offering these services in Malaysia.

Personal-data breach notification (PDPA)

Separate from Act 854, the Personal Data Protection (Amendment) Act 2024 introduced mandatory breach notification effective 1 June 2025: notify the Commissioner within 72 hours and affected individuals within 7 days where there is risk of significant harm; max fines raised to RM1,000,000.

Timeline - major decisions & events

Jan 1, 2025lawofficial
Personal Data Protection (Amendment) Act 2024 Enters Force — Phased

The PDPA amendment rolled out in three phases (1 Jan, 1 Apr, 1 Jun 2025), introducing mandatory 72-hour breach notification to the Personal Data Protection Commissioner, compulsory appointment of Data Protection Officers, direct Security Principle obligations on processors, and penalties up to RM 1 million per offence. This is the most significant expansion of cybersecurity compliance duties on private-sector data handlers since the PDPA's 2013 commencement.

Personal Data Protection Department Malaysia
Aug 26, 2024lawofficial
Cyber Security Act 2024 (Act 854) and Four Subsidiary Regulations Enter Force

Malaysia's first standalone cybersecurity statute came into force alongside the Cyber Security (Notification of Cyber Security Incident) Regulations, the Risk Assessment and Audit Regulations, the Licensing of Cyber Security Service Provider Regulations, and the Compounding of Offences Regulations. NCII entities across 11 sectors must now conduct annual risk assessments, biennial audits, and report incidents to NACSA; cybersecurity service providers must hold a NACSA licence. Non-compliance attracts fines up to RM 500,000 and/or imprisonment.

National Cyber Security Agency (NACSA)
Aug 25, 2024incidentofficial
RansomHub Ransomware Attack on Prasarana Malaysia Berhad (316 GB Exfiltrated)

The RansomHub ransomware group exfiltrated 316 GB of operational and corporate data from Prasarana, operator of Klang Valley's LRT, MRT and Rapid Bus network. The Personal Data Protection Commissioner launched a formal investigation — a high-profile test of PDPA enforcement against a government-linked company — and the incident occurred just one day before the Cyber Security Act entered force.

Personal Data Protection Commissioner / Ministry of Digital Malaysia
Jan 26, 2024incidentofficial
R00tK1T ISC CyberTeam Launches Sustained Hacktivist Campaign Against Malaysia

Hacktivist group R00tK1T announced and executed a targeted campaign against Malaysian government agencies, national databases (including EPF and the Election Commission), and private firms, causing web defacements, data breaches, and unauthorised access before halting approximately one month later. The episode exposed gaps in pre-CSA 2024 incident-coordination frameworks and accelerated parliamentary passage of the Cyber Security Bill.

MyCERT / CyberSecurity Malaysia
Oct 12, 2020guidanceofficial
Malaysia Cyber Security Strategy 2020–2024 Launched with RM 1.8 Billion Allocation

The MCSS 2020–2024, built around five strategic pillars (governance, legislative reform, cyber resilience, capacity building, and international cooperation) and 113 programmes, was launched by the government with a RM 1.8 billion budget. Its Pillar 2 explicitly called for sector-specific cybersecurity legislation, providing the direct policy mandate that produced the Cyber Security Act 2024.

Majlis Keselamatan Negara (National Security Council)
Feb 1, 2017decisionofficial
National Cyber Security Agency (NACSA) Established Under National Security Council

NACSA was established in February 2017 as Malaysia's single national lead agency for cybersecurity policy, NCII protection, threat response, and international engagement, consolidating responsibilities that had been fragmented across MOSTI, CyberSecurity Malaysia, and the National Security Council. NACSA became the Chief Executive authority under the Cyber Security Act 2024.

National Cyber Security Agency (NACSA)
Nov 1, 2013lawofficial
Personal Data Protection Act 2010 Commences — Security Principle Binding on Private Sector

Three years after enactment, the PDPA 2010 commenced in November 2013, making the Security Principle — requiring data controllers to take practical steps to protect personal data from loss, misuse, modification, and unauthorised access — legally enforceable. This was the first time cybersecurity obligations under statute applied broadly to private commercial entities in Malaysia.

Personal Data Protection Department Malaysia
Jan 1, 2007decisionofficial
CyberSecurity Malaysia Formally Established (Rebranded from NISER)

The National ICT Security and Emergency Response Centre (NISER), founded in 1997, was restructured and rebranded as CyberSecurity Malaysia under the Ministry of Science, Technology and Innovation, becoming the national technical agency for cybersecurity operations, the MyCERT incident-response centre, digital forensics, and cryptography accreditation — functions it retains today.

CyberSecurity Malaysia
Jan 1, 2006guidanceofficial
National Cyber Security Policy (NCSP) Formulated — Malaysia's First National Cybersecurity Doctrine

Malaysia became one of the first Southeast Asian nations to adopt a comprehensive National Cyber Security Policy, defining ten Critical National Information Infrastructure (CNII) sectors and establishing a whole-of-government protection framework. The NCSP anchored subsequent institutional developments including NACSA, and its CNII sector model was directly codified in the Cyber Security Act 2024.

MyGOV — Government of Malaysia Official Portal
Apr 1, 1999lawofficial
Communications and Multimedia Act 1998 (Act 588) Enters Force

Act 588 entered force on 1 April 1999, creating a technology-neutral regulatory framework for converging ICT and broadcast industries. It imposed network-security obligations on licensees and established the MCMC as a regulator with enforcement powers over communications infrastructure — providing the first mandatory cybersecurity standards for network operators.

Malaysian Communications and Multimedia Commission (MCMC)
Jun 1, 1997lawofficial
Computer Crimes Act 1997 Enacted — Foundational Cybercrime Statute

Enacted as part of the Multimedia Super Corridor (MSC) cyber-law package alongside the Digital Signature Act 1997, the CCA 1997 criminalised unauthorised access to computer systems, data interception, data alteration, and misuse of computer programs. It established the foundational criminal liability framework for cybersecurity offences that remains in force today.

MSC Malaysia (Attorney General's Chambers Cyber Laws Portal)

Malaysia - other topics

Last verified 5/23/2026 · Orientation, not legal advice - verify against the primary sources linked above. Explore the full world map →