Cybersecurity / Regulatory Readiness

Cyber Security Act 2024 and NCII Readiness

Being designated a National Critical Information Infrastructure entity converts good security practice into a statutory duty with reporting timelines and audit obligations attached. We assess where you stand against those duties and give you a remediation plan ordered by regulatory exposure.

Assessment against NCII entity duties Risk assessment and audit obligation readiness Incident reporting workflow built to the statutory timeline
Overview

Cyber Security Act & NCII Readiness

What it is

A readiness assessment against the obligations that fall on National Critical Information Infrastructure entities under the Cyber Security Act 2024, with a prioritised remediation plan and the artefacts the Act requires you to hold.

Why organisations need it

Orbix already trains organisations on the Act. What the training cannot do is tell a specific entity where it currently stands. Designated entities carry duties around risk assessment, audit, incident notification and adherence to directions, and the penalties attach to the entity and its officers. Sectors that expect designation are better served finding their gaps before a regulator or an appointed auditor does.

Key features

What the engagement covers

Scoped to your designation status. Designated entities are assessed against the duties as they apply now; organisations in a likely sector are assessed against what designation would require of them.

Applicability and designation review

Whether the Act reaches you, through designation as an NCII entity or through your position in a designated entity's supply chain. What sector lead your obligations run through, and what a designation would change in practice.

Obligation mapping

Every duty the Act and its regulations place on an entity, mapped to your current position: the code of practice, risk assessment, audit, incident notification, and compliance with directions from the sector lead or the Chief Executive.

Cyber security risk assessment readiness

The Act requires a risk assessment on a defined cycle. We assess whether what you do today satisfies it in scope, method and documentation, and close the gap where it does not.

Audit readiness

The periodic audit obligation, what an appointed auditor examines, and where your evidence would not currently support the finding you would want. Run as a dry run rather than as a checklist review.

Incident notification workflow

A working notification process built to the statutory timeline: detection to assessment to decision to notification, with named roles and the template content. Tested rather than documented and filed.

Remediation plan and control uplift

Findings ordered by regulatory exposure rather than by technical severity, with effort estimates and owners, plus support implementing the controls that close them.

Business value

What the business gets out of it

You find the gaps before an auditor does

The audit obligation is periodic and the findings go upward. A dry run converts a regulatory finding into an internal action item.

The notification clock becomes achievable

Statutory notification timelines are short and start at detection. A workflow with named roles and pre-drafted content is the only thing that reliably meets them.

Officers understand their exposure

Duties under the Act attach to the entity and can reach its officers. Directors and senior management get a clear statement of what is owed and by whom.

Existing security work counts

Organisations running ISO 27001, BNM RMiT or a mature security programme already satisfy much of this. We map what exists rather than starting from a blank page.

Supply chain questions get answered

Suppliers to designated entities are increasingly asked to demonstrate equivalent controls. The same assessment answers those requests.

Training and assessment reinforce each other

Where the remediation needs your people to change how they work, the Cyber Security Act course is HRD Corp claimable and can be delivered alongside.

How it works

How the engagement runs

01

Applicability review

Determining how the Act reaches you, through designation or supply chain, and which sector lead your obligations run through.

02

Obligation mapping

Building the register of duties that apply, with the current position and evidence against each.

03

Assessment fieldwork

Reviewing your risk assessment, controls, documentation and incident processes against those duties, including interviews with the people who operate them.

04

Notification workflow design

Building and walking through the incident notification process against the statutory timeline, with a timed exercise.

05

Findings and remediation plan

Findings ranked by regulatory exposure, with effort, owners and sequence, presented to management and the board.

06

Remediation support and re-test

Support closing the findings, then re-testing the areas that mattered most so the closure is evidenced rather than asserted.

Deliverables

What you receive

Applicability determination

A documented position on how the Act applies to you and through which route, useful in itself when customers ask.

Obligation register

Every applicable duty with the current position, evidence held and gap, maintained as the regulations develop.

Readiness assessment report

Findings against each duty, ranked by regulatory exposure, with the basis for each conclusion.

Incident notification workflow

Roles, decision points, timeline and template content, exercised rather than only documented.

Remediation plan

Prioritised actions with effort estimates, owners and target dates, sequenced to close the highest exposure first.

Board briefing pack

A summary of duties, current standing and officer exposure, in language a board can act on.

Who it is for

Who this is built for

Industries

Government and public sectorBanking and financeHealthcareEnergy and utilitiesWaterTransportationTelecommunicationsDefence and national security suppliers

Company sizes

Designated NCII entitiesLarge enterpriseMid-market suppliers to NCII entitiesGovernment-linked companies

Departments

IT and securityRisk and complianceInternal auditLegalExecutive leadershipBoard
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

How do we know if we are an NCII entity?

Designation is made through the sector leads for the sectors the Act identifies, which cover government, banking and finance, transportation, defence, information and communications, healthcare, water and energy, among others. If you have not been notified, the applicability review establishes your likely position and what a designation would require.

What are the main duties?

In broad terms: adhering to the applicable code of practice, conducting cyber security risk assessments on a defined cycle, undergoing periodic audit, notifying cyber security incidents within statutory timelines, and complying with directions issued by the sector lead or the Chief Executive.

Is this the same as an ISO 27001 gap analysis?

No, although they overlap substantially. ISO 27001 assesses you against a voluntary standard you chose. This assesses you against statutory duties with penalties attached. Organisations holding ISO 27001 usually have a much shorter gap, and we map that across rather than duplicating it.

Can you perform the statutory audit?

The audit obligation must be satisfied in the manner the Act and its regulations require, which may specify who can perform it. We prepare you for that audit and run it as a dry run. Where an appointed or licensed auditor is required, that is a separate appointment and we will say so plainly.

We are a supplier to an NCII entity, not one ourselves. Does this apply?

Not directly, but the practical effect often is. Designated entities pass control expectations down their supply chain, and increasingly ask suppliers to evidence equivalent practices. The same assessment answers those requests and prepares you if designation later reaches your sector.

How long does the assessment take?

For a mid-sized entity, typically three to six weeks from kickoff to findings, depending on how many systems are in scope and how readily the evidence can be produced. Remediation timelines depend entirely on what the findings turn out to be.

Does the training count towards anything?

The Cyber Security Act course supports the awareness and competence side of your obligations and is HRD Corp SBL-Khas claimable. The assessment itself is advisory work and is not claimable, which is why the two are quoted separately.

Get started

Find the gaps before the auditor is appointed

Tell us your sector, whether you have been designated, and what your current security programme looks like. We will come back with scope, timeline and a fixed quotation, and we will tell you if your existing ISO or RMiT work already covers most of it.