Malaysia’s Cyber Security Act Starts a Six-Hour NCII Incident Clock

Malaysia’s Cyber Security Act 2024 turns critical-infrastructure security into a recurring governance process—and gives designated entities only six hours to submit the first prescribed details of a known cyber incident.

Malaysia’s Cyber Security Act 2024, Act 854, was gazetted on 26 June 2024 and came into operation on 26 August 2024. It created a national framework around the National Cyber Security Committee, the National Cyber Security Agency (NACSA), National Critical Information Infrastructure sector leads and designated NCII entities. It also introduced licensing for specified cybersecurity services.

The most operationally demanding part is easy to miss in a general summary of the Act. For a designated NCII entity, incident reporting is not measured in days. The implementing regulations require immediate electronic notification when an incident has or might have occurred and has come to the entity’s knowledge. Prescribed initial information must follow within six hours.

Sector membership is not the same as designation

Malaysia identifies eleven NCII sectors: government; banking and finance; transportation; defence and national security; information, communication and digital; healthcare services; water, sewerage and waste management; energy; agriculture and plantation; trade, industry and economy; and science, technology and innovation.

Operating in one of those fields does not, by itself, make every business a designated NCII entity. Sector leads identify entities that own or operate infrastructure meeting the statutory criteria. Legal, security and executive teams should therefore document the organisation’s designation status, the systems within scope and the relevant sector lead. A group with several Malaysian entities should not assume that one designation—or one response plan—answers the question for all of them.

Suppliers should perform the same mapping. A cloud, managed-service or technology provider may not itself be designated for a customer’s system, yet its telemetry and response speed may determine whether the customer can meet its duties.

The notification process has several stages

The Cyber Security (Notification of Cyber Security Incident) Regulations 2024 establish a layered process:

  • notify the incident immediately by electronic means once it is known;
  • within six hours, provide details of the authorised person, the entity and sector, plus the incident’s type, description, severity, known time and method of discovery;
  • within fourteen days, provide supplementary information to the fullest extent practicable, including affected infrastructure and hosts, threat-actor information, artefacts, related incidents, tactics, techniques and procedures, impact and actions taken; and
  • provide further updates when required by NACSA’s Chief Executive.

The first report is not a final forensic conclusion. The process expressly anticipates later information. That means an organisation should be able to distinguish confirmed facts, current assessment and open questions without delaying the initial notice in search of certainty.

The six-hour period should also be reflected in internal definitions. A playbook needs a defensible point at which the entity treats an incident as having come to its knowledge. If every business unit uses a different threshold, the reporting clock becomes impossible to govern.

Annual risk assessment and biennial audit create the evidence cycle

The incident clock sits inside a broader assurance regime. The risk-assessment and audit regulations require an NCII entity that owns or operates NCII to conduct a cybersecurity risk assessment at least once each year. It must carry out an audit at least once every two years, or more frequently if directed in a particular case.

These should not become isolated compliance exercises. The asset and dependency map used in the risk assessment should also support incident scoping. Audit findings should feed funded remediation plans, and unresolved findings should influence incident severity and executive escalation.

A practical evidence chain connects:

  • the legal record of designation and systems in scope;
  • an owned inventory of NCII assets and dependencies;
  • the annual risk assessment;
  • audit findings and remediation evidence;
  • incident records and notification timestamps; and
  • board or senior-management oversight.

When those records use different system names or ownership data, the mismatch is itself a resilience problem.

Supplier contracts must run faster than the legal clock

A six-hour regulatory deadline cannot be passed through to a supplier as a six-hour contractual deadline. The designated entity still needs time to validate, classify, escalate and submit. Contracts for hosting, monitoring, incident response and operational technology should require a much faster initial alert, continuous cooperation and evidence preservation.

The contract should also identify who can authorise regulatory communication, how communications continue if the primary portal or network is unavailable, and which telemetry the customer can obtain without waiting for a commercial dispute. Exercises should include weekends, public holidays and incidents originating inside a supplier.

Licensing affects two defined service categories

Act 854 also regulates cybersecurity service providers. The 2024 licensing regulations apply to managed security operations centre monitoring and penetration-testing services, subject to stated exclusions. Providers—and customers conducting due diligence—should check the current licensing rules, NACSA directives and any applicable exemption rather than treating “cybersecurity services” as one undifferentiated category.

Malaysia’s regime makes speed, evidence and accountability part of the same control system. For designated NCII entities, the best preparation for the six-hour clock is not a notification form kept in a legal folder. It is a rehearsed operating model that can identify the affected service, reach an authorised decision-maker and produce reliable facts while the investigation is still moving.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *