Baseline walkthrough
Each control explained.
A National Cyber Security Baseline self-assessment measures an organisation's controls against NACSA's minimum baseline, with the evidence behind each answer checked. NACSA's National Cyber Security Baseline sets minimum controls, and Directive No. 4 requires self-assessment against it. We facilitate the assessment, check the evidence behind each answer, and give you an honest score and a plan.
A facilitated self-assessment against the National Cyber Security Baseline, with evidence review and a remediation plan.
NACSA has published the National Cyber Security Baseline and a self-assessment tool, and Chief Executive Directive No. 4 addresses self-assessment against it. NCII entities are expected to use it, and increasingly ask their suppliers the same questions. A self-assessment without evidence gives a flattering score that will not survive an audit.
Each control explained.
Documents and settings behind each answer.
An honest baseline score.
Missing and weak controls.
Prioritised actions.
Using the result to answer customer questionnaires.
Backed by evidence.
Uses the national baseline.
Answer NCII customers confidently.
What to fix first.
No intrusive testing.
Scope and contacts.
Controls reviewed with your team.
Documents and settings checked.
Baseline score.
Gaps and plan.
Completed and evidenced.
By domain.
Missing and weak controls.
Prioritised.
For customer questionnaires.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
NACSA addresses self-assessment against the baseline in Chief Executive Directive No. 4 for NCII-related parties. Organisations outside that group use the baseline as a recognised national benchmark, and increasingly because their NCII customers ask about it.
Yes. NCII customers increasingly ask their suppliers the same baseline questions they must answer themselves. An evidenced self-assessment lets you answer those questionnaires quickly and honestly, and shows where to improve before a customer finds the gap.
We review evidence and settings behind each answer, such as configurations, records and policies, rather than accepting a yes at face value. We do not perform intrusive testing, so the assessment does not disrupt your systems.
Typically two to four weeks: a facilitated self-assessment session, an evidence review against each control, then a score and a remediation plan. The time depends mostly on how quickly evidence can be gathered.
The current version of the National Cyber Security Baseline that NACSA publishes, confirmed at kick-off. If NACSA updates the baseline during the engagement, we tell you what changed and how it affects your score.