Malaysia’s Cyber Security Act 2024 Comes Into Operation.
Introduction
We discussed the Cyber Security Bill 2024 in our April 2024 Legal Update. The Bill has since been presented for Royal Assent and has been officially gazetted. The Cyber Security Act 2024 (“CSA”) came into force on 26 August 2024 along with the following regulations:
- Cyber Security (Period for Cyber Security Risk Assessment and Audit) Regulations 2024 (“Risk Assessment Regulations”);
- ) Cyber Security (Notification of Cyber Security Incident) Regulations 2024 (“Notification Regulations”);
- ) Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024 (“Licensing Regulations”); and
- Cyber Security (Compounding of Offences) Regulations 2024 (“Compound Regulations”).
Will my business or organisation be subject to the new law and regulations?
Public and private entities (including private businesses) that are designated as national critical information infrastructure entities (“NCII Entities”) and cyber security service providers will be expected to comply with the regulatory requirements under the CSA and the abovementioned regulations.
By way of recapitulation, entities within the following sectors may potentially be designated as NCII Entities: (i) Government; (ii) Banking and Finance; (iii) Transportation; (iv) Defence and National Security; (v) Information, Communication and Digital; (vi) Healthcare Services; (vii) Water Sewerage and Waste Management; (viii) Energy; (ix) Agriculture and Plantation; (x) Trade, Industry and Economy; and (xi) Science, Technology and Innovation.