Cyber Security Act 2024 (Act 854) NACSA Readiness Training

A one-day readiness programme for organisations that fall within, or supply into, Malaysia's National Critical Information Infrastructure (NCII) sectors under the Cyber Security Act 2024 (Act 854). The Act places statutory duties on designated NCII entities: appointing an internal point of contact, adopting the applicable code of practice, running risk assessments and independent audits on the prescribed cycle, and notifying cyber security incidents to the National Cyber Security Agency (NACSA) and the relevant sector lead. It also introduces a licensing regime for providers of specified cyber security services.

The programme translates those duties into an internal work plan rather than a reading of the statute: who owns what, what evidence has to exist before an audit asks for it, and what has to happen in the first hours of an incident. Content can be tailored to the participants' sector and to whether the organisation is a designated entity, a supplier to one, or still working out which.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:15 AM

The Cyber Security Act 2024 in Context

Why the Act was introduced and how it sits alongside the Personal Data Protection Act 2010 and its 2024 amendments, the Communications and Multimedia Act 1998, and sector regulator requirements such as BNM RMiT and Securities Commission guidelines. The role of NACSA and the National Cyber Security Committee, and what changed for organisations when the Act came into force.

03

10:15 AM - 10:30 AM

Break

04

10:30 AM - 11:30 AM

NCII Sectors, Designation and Scope

The NCII sectors named in the Act, how sector leads designate NCII entities, and how to work out whether your organisation is designated, is a supplier into a designated entity, or is out of scope. Practical scoping of which systems, data and third-party connections sit inside the NCII perimeter, and why that boundary needs to be documented before anyone else draws it for you.

05

11:30 AM - 12:30 PM

Statutory Duties of an NCII Entity

The duty to implement the applicable code of practice, to conduct cyber security risk assessments on the prescribed cycle, to commission independent audits, and to submit the resulting reports. What adequate looks like in evidence terms: asset registers, risk registers, policy sets, remediation tracking, audit trails and management sign-off.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:30 PM

Incident Notification and the First Hours

The statutory obligation to notify NACSA and the sector lead, the notification chain, and the prescribed reporting windows. What information must be captured at the point of detection, how to keep an initial submission accurate while the facts are still moving, and how the notification duty interacts with PDPA breach notification where personal data is involved. Escalation triggers, internal decision rights, and holding statements.

08

2:30 PM - 3:15 PM

Governance, Roles and Accountability

Appointing and empowering the internal point of contact, board and senior management oversight, and how NCII duties are split between IT, risk, legal, procurement and the business. The offence and penalty provisions that attach to the entity and to individuals, and what a defensible compliance record looks like.

09

3:15 PM - 3:30 PM

Break

10

3:30 PM - 4:15 PM

Licensing of Cyber Security Service Providers

Which services fall inside the licensing regime, what it means when you buy managed detection, security operations or penetration testing services, and the due diligence questions to put to vendors. Contract clauses worth having, and the risk of relying on an unlicensed provider for a regulated service.

11

4:15 PM - 4:45 PM

Readiness Gap Workshop

Participants map their own organisation against the duties covered during the day and produce a prioritised gap list with named owners and target dates.

12

4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate, suitable for IT, risk, compliance, legal and operations leads, and for board members with oversight responsibility

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   10 to 15 question knowledge assessment covering all modules

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling