# Malaysia's Cybersecurity Posture: Threats, Strategy and Global Standing

> How Malaysia moved from a voluntary national strategy to a hard-law regime — the online-scam and incident trends driving it, the Cyber Security Act 2024 and its critical-infrastructure duties, and where the country sits on the ITU Global Cybersecurity Index.

- Category: technology
- Language: en
- Status: published
- Updated: 2026-08-01
- Canonical: https://negaraku.md/en/technology/malaysia-cybersecurity-landscape

---

For a decade, Malaysia asked its critical infrastructure to take cyber security
seriously. Since 26 August 2024, it tells them to — and attaches prison terms to
getting it wrong.

That shift, from a funded-but-voluntary national strategy to a criminal-law
regime, is the single most important thing to understand about where Malaysia's
cyber posture stands today. It happened while online-scam losses were climbing
into the billions, and while the country was still being marked as a global top
performer on the main international index. All three of those facts are true at
once, and together they describe the landscape.

## What are Malaysians actually losing to cyber threats?

The most visible harm to ordinary people is not state-grade hacking; it is fraud.
Reported online-fraud losses in Malaysia reached **RM1.57 billion in 2024** and
then rose to **RM2.97 billion in 2025**, according to figures the Home Ministry
gave Parliament. In the first five months of 2026 alone, a further RM830 million
was reported lost.

Recovery lags badly behind the losses. From 2022 to 2025 the authorities seized
**RM32.49 million** linked to scam syndicates and returned **RM10.9 million** to
victims through the courts — a fraction of a percent of what was taken. The gap
between money lost and money clawed back is why enforcement and prevention, not
just victim redress, dominate policy thinking.

Investment scams, impersonation and telecommunications fraud drive most of these
cases, and they increasingly ride on compromised systems, phishing and data
leaks rather than simple confidence tricks. That blurs the line between "scam"
and "cyber incident", and it is part of why Malaysia moved to regulate the
security of the systems underneath.

## Where did Malaysia's national strategy come from?

The modern posture starts with the **Malaysia Cyber Security Strategy (MCSS)
2020-2024**, launched in October 2020 with an allocation of **RM1.8 billion**.
It was a plan, not a law — a coordinated set of intentions with money behind it.

The MCSS was built on five pillars, expanded into 12 strategies, 35 action plans
and 113 programmes.

| # | MCSS pillar | Thrust |
| --- | --- | --- |
| 1 | National governance | Strengthen governance and critical ICT infrastructure |
| 2 | Legislation and enforcement | Review existing laws and formulate new cyber security law |
| 3 | Innovation and technology | Build world-standard cyber security capability |
| 4 | Capacity development | Grow a skilled cyber security workforce |
| 5 | International cooperation | Leverage regional and global partnerships |

Pillar 2 is the one that matured into hard law. The strategy explicitly set out to
"formulate new cyber security law" — and four years later, that is exactly what
arrived.

## What does the Cyber Security Act 2024 actually do?

The **Cyber Security Act 2024 (Act 854)** was gazetted on **26 June 2024** and
came into force on **26 August 2024**, together with four supporting regulations.
It does four things at once.

- It creates a **National Cyber Security Committee** to steer national policy.
- It gives statutory powers to the **Chief Executive of NACSA**, the National
  Cyber Security Agency.
- It defines **National Critical Information Infrastructure (NCII)** sectors, and
  the roles of sector leads and NCII entities within them.
- It sets up a **licensing regime** for certain cyber security service providers.

The Act did not arrive alone. Four subsidiary regulations came into force with it,
turning the framework into operational detail.

| Supporting regulation (2024) | What it governs |
| --- | --- |
| Period of Cyber Security Risk Assessment and Audit | How often NCII entities must assess and audit |
| Licensing of Cyber Security Service Provider | Who must be licensed, and how |
| Notification of Cyber Security Incident | Incident-reporting timelines and content |
| Compounding of Offences | Settling certain offences without full prosecution |

## Who counts as critical infrastructure?

The Act's heaviest duties fall on **NCII entities** — organisations whose systems,
if disrupted, would damage essential national services. The designated sectors
cover the backbone of the economy and the state:

- Government
- Banking and finance
- Defence, national security and transportation
- Information, communication and digital
- Healthcare
- Energy
- Water, sewerage and waste management
- Agriculture
- Trade, industry and economy
- Science, technology and innovation

If your organisation is designated within one of these sectors, three obligations
follow: conduct **cyber security risk assessments and audits** on the prescribed
cycle, report incidents on a tight clock, and follow any code of practice the
Chief Executive issues.

## How fast must an incident be reported?

Very fast. The reporting duty is staged, and the first stage is measured in hours,
not days.

| Stage | Deadline | What is required |
| --- | --- | --- |
| Notify | Immediately on discovery | Alert the Chief Executive of NACSA and the relevant sector lead |
| Initial report | Within **6 hours** | Description, severity, date and method of discovery |
| Supplementary report | Within **14 days** | Affected hosts, threat particulars and actions taken |

This "six-hour rule" is a demanding incident-notification window, and it is
penalty-backed rather than merely advisory. Failing to notify NACSA of an
incident can attract a fine of up to **RM500,000**, imprisonment of up to **10
years**, or both. Failing to carry out required risk assessments or audits
carries a lighter penalty — up to RM200,000 or three years — but is still a
criminal matter, not a paperwork lapse.

## Do cyber security firms now need a licence?

Some do. The Act creates a licensing requirement for providers of prescribed cyber
security services — notably **managed security operations centre (SOC) monitoring**
and **penetration testing**. Applicants must meet prerequisites set under the Act,
including not having been convicted of an offence involving fraud, dishonesty or
moral turpitude, and licensees must retain records of the services they provide
for at least six years. Operating such a service without a licence exposes a
provider to the same top-band penalty as incident non-reporting: up to RM500,000
or 10 years.

Internal security work an organisation does for itself, and government bodies, sit
outside the licensing net — the regime targets third-party service providers,
not every in-house engineer.

## How does Malaysia rank against the rest of the world?

Strongly, and consistently. The benchmark most often cited is the **ITU Global
Cybersecurity Index (GCI)**, which scores countries across five pillars — legal,
technical and organisational measures, capacity development, and cooperation.

In the 2020 edition (GCIv4), Malaysia scored **98.06** and ranked **joint fifth**
in the world, with perfect scores in the legal, capacity-development and
cooperation pillars and slightly lower marks on technical and organisational
measures. The 2024 edition moved to a five-tier model rather than a single league
table; Malaysia is placed in the top tier — the "role-modelling" group of
countries judged to demonstrate strong commitment across all five pillars.

The headline to hold onto: Malaysia is, by the main international yardstick, a
front-runner on cyber security *policy and institutions* — even as its citizens
lose record sums to fraud. High institutional maturity and high real-world harm
are not contradictory; they are the reason the law tightened.

## What's next

Act 854 is young, and the practical questions now shift from "what does the law
say" to "how is it enforced". Watch for which organisations are formally
designated as NCII entities, how NACSA applies the six-hour reporting rule in
practice, and how the licensing of SOC and penetration-testing providers is rolled
out. The scam-loss figures will be the real-world scorecard: whether the new
regime bends the curve, or whether losses keep climbing past the RM2.97 billion
seen in 2025.

The Act also sits alongside, not on top of, the
[Personal Data Protection Act 2010](/en/law/pdpa-2010). One protects the security
of critical systems; the other protects personal data in commercial transactions.
An organisation hit by a breach may owe duties under both — and those two regimes,
read together, define most of Malaysia's day-to-day cyber obligations.

## Sources

- Cyber Security Act 2024 [Act 854] — https://www.nacsa.gov.my/act854.php (National Cyber Security Agency (NACSA))
- Malaysia's New Cyber Security Act 2024 — A Summary and Brief Comparative Analysis — https://www.mayerbrown.com/en/insights/publications/2024/12/malaysias-new-cyber-security-act-2024-a-summary-and-brief-comparative-analysis (Mayer Brown)
- Malaysia's Cyber Security Act 2024: What Businesses Need to Know — https://www.aseanbriefing.com/news/malaysias-cyber-security-act-2024-what-businesses-need-to-know/ (ASEAN Briefing (Dezan Shira & Associates))
- Introduction of the new Cyber Security Act 2024 (CSA) and Supporting Regulations — https://dnh.com.my/introduction-of-the-new-cyber-security-act-2024-csa-and-supporting-regulations/ (Donovan & Ho)
- Malaysia pours RM1.8bn into national cyber security strategy — https://www.marketing-interactive.com/malaysia-pours-rm18bn-into-national-cyber-security-strategy (Marketing-Interactive)
- Global Cybersecurity Index 2024 — https://www.itu.int/epublications/ru/publication/global-cybersecurity-index-2024/en (International Telecommunication Union (ITU))
- Saifuddin: Malaysia ranked among top 10 countries with highest commitment to cybersecurity — https://www.malaymail.com/news/malaysia/2021/07/01/saifuddin-malaysia-ranked-among-top-10-countries-with-highest-commitment-to/1986235 (Malay Mail)
- Billions lost to scams since 2022 but only RM10.9mil returned, Dewan Rakyat told — https://www.thestar.com.my/news/nation/2026/06/24/billions-lost-to-scams-since-2022-but-only-rm109mil-returned-dewan-rakyat-told (The Star)

---
Source of truth: https://github.com/negaraku-md/NegaraKu.md
License: CC BY-SA 4.0
