This topic falls under a sensitive category and is presented descriptively and neutrally.
Malaysia's cybersecurity posture has hardened from the voluntary Malaysia Cyber Security Strategy 2020-2024 into binding law under the Cyber Security Act 2024 (Act 854), which came into force on 26 August 2024. The Act creates a National Cyber Security Committee, empowers the National Cyber Security Agency (NACSA), designates National Critical Information Infrastructure (NCII) sectors, and imposes risk-assessment, audit and rapid incident-reporting duties backed by criminal penalties. Against a backdrop of sharply rising online-scam losses, the country nonetheless sits in the top tier of the ITU Global Cybersecurity Index.
- The Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into force on 26 August 2024, together with four supporting regulations
- Act 854 establishes the National Cyber Security Committee and gives the Chief Executive of NACSA powers over designated National Critical Information Infrastructure (NCII) entities
- NCII entities must report a cyber security incident immediately, with an initial report within 6 hours and supplementary details within 14 days
- Failure to report an incident or operating without a required licence can attract a fine up to RM500,000 or up to 10 years' imprisonment
- The Malaysia Cyber Security Strategy 2020-2024 committed RM1.8 billion across five pillars, 12 strategies, 35 action plans and 113 programmes
- Malaysia scored 98.06 and ranked joint fifth globally in the ITU Global Cybersecurity Index 2020 (GCIv4), and is placed in the top tier of the 2024 edition
- Reported online-fraud losses reached RM1.57 billion in 2024 and RM2.97 billion in 2025
Who this applies to: Business owners, IT and compliance leads, students and general readers who want an accurate overview of Malaysia's cybersecurity law, strategy and international standing.
On this page
For a decade, Malaysia asked its critical infrastructure to take cyber security seriously. Since 26 August 2024, it tells them to — and attaches prison terms to getting it wrong.
That shift, from a funded-but-voluntary national strategy to a criminal-law regime, is the single most important thing to understand about where Malaysia’s cyber posture stands today. It happened while online-scam losses were climbing into the billions, and while the country was still being marked as a global top performer on the main international index. All three of those facts are true at once, and together they describe the landscape.
What are Malaysians actually losing to cyber threats?
The most visible harm to ordinary people is not state-grade hacking; it is fraud. Reported online-fraud losses in Malaysia reached RM1.57 billion in 2024 and then rose to RM2.97 billion in 2025, according to figures the Home Ministry gave Parliament. In the first five months of 2026 alone, a further RM830 million was reported lost.
Recovery lags badly behind the losses. From 2022 to 2025 the authorities seized RM32.49 million linked to scam syndicates and returned RM10.9 million to victims through the courts — a fraction of a percent of what was taken. The gap between money lost and money clawed back is why enforcement and prevention, not just victim redress, dominate policy thinking.
Investment scams, impersonation and telecommunications fraud drive most of these cases, and they increasingly ride on compromised systems, phishing and data leaks rather than simple confidence tricks. That blurs the line between “scam” and “cyber incident”, and it is part of why Malaysia moved to regulate the security of the systems underneath.
Where did Malaysia’s national strategy come from?
The modern posture starts with the Malaysia Cyber Security Strategy (MCSS) 2020-2024, launched in October 2020 with an allocation of RM1.8 billion. It was a plan, not a law — a coordinated set of intentions with money behind it.
The MCSS was built on five pillars, expanded into 12 strategies, 35 action plans and 113 programmes.
| # | MCSS pillar | Thrust |
|---|---|---|
| 1 | National governance | Strengthen governance and critical ICT infrastructure |
| 2 | Legislation and enforcement | Review existing laws and formulate new cyber security law |
| 3 | Innovation and technology | Build world-standard cyber security capability |
| 4 | Capacity development | Grow a skilled cyber security workforce |
| 5 | International cooperation | Leverage regional and global partnerships |
Pillar 2 is the one that matured into hard law. The strategy explicitly set out to “formulate new cyber security law” — and four years later, that is exactly what arrived.
What does the Cyber Security Act 2024 actually do?
The Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into force on 26 August 2024, together with four supporting regulations. It does four things at once.
- It creates a National Cyber Security Committee to steer national policy.
- It gives statutory powers to the Chief Executive of NACSA, the National Cyber Security Agency.
- It defines National Critical Information Infrastructure (NCII) sectors, and the roles of sector leads and NCII entities within them.
- It sets up a licensing regime for certain cyber security service providers.
The Act did not arrive alone. Four subsidiary regulations came into force with it, turning the framework into operational detail.
| Supporting regulation (2024) | What it governs |
|---|---|
| Period of Cyber Security Risk Assessment and Audit | How often NCII entities must assess and audit |
| Licensing of Cyber Security Service Provider | Who must be licensed, and how |
| Notification of Cyber Security Incident | Incident-reporting timelines and content |
| Compounding of Offences | Settling certain offences without full prosecution |
Who counts as critical infrastructure?
The Act’s heaviest duties fall on NCII entities — organisations whose systems, if disrupted, would damage essential national services. The designated sectors cover the backbone of the economy and the state:
- Government
- Banking and finance
- Defence, national security and transportation
- Information, communication and digital
- Healthcare
- Energy
- Water, sewerage and waste management
- Agriculture
- Trade, industry and economy
- Science, technology and innovation
If your organisation is designated within one of these sectors, three obligations follow: conduct cyber security risk assessments and audits on the prescribed cycle, report incidents on a tight clock, and follow any code of practice the Chief Executive issues.
How fast must an incident be reported?
Very fast. The reporting duty is staged, and the first stage is measured in hours, not days.
| Stage | Deadline | What is required |
|---|---|---|
| Notify | Immediately on discovery | Alert the Chief Executive of NACSA and the relevant sector lead |
| Initial report | Within 6 hours | Description, severity, date and method of discovery |
| Supplementary report | Within 14 days | Affected hosts, threat particulars and actions taken |
This “six-hour rule” is a demanding incident-notification window, and it is penalty-backed rather than merely advisory. Failing to notify NACSA of an incident can attract a fine of up to RM500,000, imprisonment of up to 10 years, or both. Failing to carry out required risk assessments or audits carries a lighter penalty — up to RM200,000 or three years — but is still a criminal matter, not a paperwork lapse.
Do cyber security firms now need a licence?
Some do. The Act creates a licensing requirement for providers of prescribed cyber security services — notably managed security operations centre (SOC) monitoring and penetration testing. Applicants must meet prerequisites set under the Act, including not having been convicted of an offence involving fraud, dishonesty or moral turpitude, and licensees must retain records of the services they provide for at least six years. Operating such a service without a licence exposes a provider to the same top-band penalty as incident non-reporting: up to RM500,000 or 10 years.
Internal security work an organisation does for itself, and government bodies, sit outside the licensing net — the regime targets third-party service providers, not every in-house engineer.
How does Malaysia rank against the rest of the world?
Strongly, and consistently. The benchmark most often cited is the ITU Global Cybersecurity Index (GCI), which scores countries across five pillars — legal, technical and organisational measures, capacity development, and cooperation.
In the 2020 edition (GCIv4), Malaysia scored 98.06 and ranked joint fifth in the world, with perfect scores in the legal, capacity-development and cooperation pillars and slightly lower marks on technical and organisational measures. The 2024 edition moved to a five-tier model rather than a single league table; Malaysia is placed in the top tier — the “role-modelling” group of countries judged to demonstrate strong commitment across all five pillars.
The headline to hold onto: Malaysia is, by the main international yardstick, a front-runner on cyber security policy and institutions — even as its citizens lose record sums to fraud. High institutional maturity and high real-world harm are not contradictory; they are the reason the law tightened.
What’s next
Act 854 is young, and the practical questions now shift from “what does the law say” to “how is it enforced”. Watch for which organisations are formally designated as NCII entities, how NACSA applies the six-hour reporting rule in practice, and how the licensing of SOC and penetration-testing providers is rolled out. The scam-loss figures will be the real-world scorecard: whether the new regime bends the curve, or whether losses keep climbing past the RM2.97 billion seen in 2025.
The Act also sits alongside, not on top of, the Personal Data Protection Act 2010. One protects the security of critical systems; the other protects personal data in commercial transactions. An organisation hit by a breach may owe duties under both — and those two regimes, read together, define most of Malaysia’s day-to-day cyber obligations.
Is the Cyber Security Act 2024 in force?
Yes. Act 854 was published in the Federal Gazette on 26 June 2024 and appointed to come into operation on 26 August 2024, alongside four supporting regulations covering risk assessment and audit, licensing, incident notification and the compounding of offences.
Does the Cyber Security Act 2024 apply to every business?
No. Its core duties fall on entities designated as National Critical Information Infrastructure (NCII) within essential-service sectors such as banking and finance, energy, healthcare and government. A separate licensing requirement, however, applies to anyone providing certain cyber security services, such as managed security operations centre monitoring or penetration testing, regardless of sector.
How quickly must a cyber incident be reported?
An NCII entity must notify the Chief Executive of NACSA and its sector lead immediately on discovering an incident, provide an initial report with the core details within 6 hours, and submit supplementary information within 14 days.
What is NACSA?
The National Cyber Security Agency is Malaysia's lead agency for national cyber security. Under the Cyber Security Act 2024 its Chief Executive designates NCII entities, receives incident reports, and administers the licensing of cyber security service providers.
How does Malaysia rank internationally?
In the ITU Global Cybersecurity Index 2020 (GCIv4) Malaysia scored 98.06 and ranked joint fifth in the world. In the 2024 edition, which uses a five-tier model, Malaysia is placed in the top 'role-modelling' tier.
The following are deliberately unstated or described only qualitatively until confirmed by a subject-matter expert:
- Exact statutory section numbers for the cyber security service licensing prerequisites and the six-year record-retention duty under Act 854 — the cited secondary sources confirm the substance but not reliable section references (the earlier draft's 'section 28' and 'section 33' were dropped as section 33 in fact governs licence revocation).
- Whether the six-hour incident-notification window is materially stricter than comparable ASEAN regimes — the earlier 'strictest in the region' comparison was removed pending a cited comparative source.
- The year-by-year split of reported scam losses (RM1.57 billion in 2024, RM2.97 billion in 2025, RM830 million in early 2026) against the primary Home Ministry / Dewan Rakyat record rather than press reporting.
- Malaysia's placement in the top 'role-modelling' tier of the ITU Global Cybersecurity Index 2024, confirmed against the published ITU report.
Sources
- Cyber Security Act 2024 [Act 854] — National Cyber Security Agency (NACSA)
- Malaysia's New Cyber Security Act 2024 — A Summary and Brief Comparative Analysis — Mayer Brown
- Malaysia's Cyber Security Act 2024: What Businesses Need to Know — ASEAN Briefing (Dezan Shira & Associates)
- Introduction of the new Cyber Security Act 2024 (CSA) and Supporting Regulations — Donovan & Ho
- Malaysia pours RM1.8bn into national cyber security strategy — Marketing-Interactive
- Global Cybersecurity Index 2024 — International Telecommunication Union (ITU)
- Saifuddin: Malaysia ranked among top 10 countries with highest commitment to cybersecurity — Malay Mail
- Billions lost to scams since 2022 but only RM10.9mil returned, Dewan Rakyat told — The Star
Change history
| Version | Date | Change | By |
|---|---|---|---|
| 01.00 | 1 Aug 2026 | Approved and published. | — |