Cyber Security Act 2024 (Act 854) NACSA Readiness Training

A one-day readiness programme for organisations that fall within, or supply into, Malaysia's National Critical Information Infrastructure (NCII) sectors under the Cyber Security Act 2024 (Act 854). The Act places statutory duties on designated NCII entities: appointing an internal point of contact, adopting the applicable code of practice, running risk assessments and independent audits on the prescribed cycle, and notifying cyber security incidents to the National Cyber Security Agency (NACSA) and the relevant sector lead. It also introduces a licensing regime for providers of specified cyber security services.

The programme translates those duties into an internal work plan rather than a reading of the statute: who owns what, what evidence has to exist before an audit asks for it, and what has to happen in the first hours of an incident. Content can be tailored to the participants' sector and to whether the organisation is a designated entity, a supplier to one, or still working out which.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:15 AM

The Cyber Security Act 2024 in Context

Why the Act was introduced and how it sits alongside the Personal Data Protection Act 2010 and its 2024 amendments, the Communications and Multimedia Act 1998, and sector regulator requirements such as BNM RMiT and Securities Commission guidelines. The role of NACSA and the National Cyber Security Committee, and what changed for organisations when the Act came into force.

03

10:15 AM - 10:30 AM

Break

04

10:30 AM - 11:30 AM

NCII Sectors, Designation and Scope

The NCII sectors named in the Act, how sector leads designate NCII entities, and how to work out whether your organisation is designated, is a supplier into a designated entity, or is out of scope. Practical scoping of which systems, data and third-party connections sit inside the NCII perimeter, and why that boundary needs to be documented before anyone else draws it for you.

05

11:30 AM - 12:30 PM

Statutory Duties of an NCII Entity

The duty to implement the applicable code of practice, to conduct cyber security risk assessments on the prescribed cycle, to commission independent audits, and to submit the resulting reports. What adequate looks like in evidence terms: asset registers, risk registers, policy sets, remediation tracking, audit trails and management sign-off.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:30 PM

Incident Notification and the First Hours

The statutory obligation to notify NACSA and the sector lead, the notification chain, and the prescribed reporting windows. What information must be captured at the point of detection, how to keep an initial submission accurate while the facts are still moving, and how the notification duty interacts with PDPA breach notification where personal data is involved. Escalation triggers, internal decision rights, and holding statements.

08

2:30 PM - 3:15 PM

Governance, Roles and Accountability

Appointing and empowering the internal point of contact, board and senior management oversight, and how NCII duties are split between IT, risk, legal, procurement and the business. The offence and penalty provisions that attach to the entity and to individuals, and what a defensible compliance record looks like.

09

3:15 PM - 3:30 PM

Break

10

3:30 PM - 4:15 PM

Licensing of Cyber Security Service Providers

Which services fall inside the licensing regime, what it means when you buy managed detection, security operations or penetration testing services, and the due diligence questions to put to vendors. Contract clauses worth having, and the risk of relying on an unlicensed provider for a regulated service.

11

4:15 PM - 4:45 PM

Readiness Gap Workshop

Participants map their own organisation against the duties covered during the day and produce a prioritised gap list with named owners and target dates.

12

4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Determine whether the organisation is a designated NCII entity, a supplier into one, or out of scope
  • Explain the statutory duties that attach to an NCII entity and identify who inside the organisation owns each one
  • Run the incident notification process to NACSA and the sector lead without losing time to internal ambiguity
  • Identify the evidence a risk assessment or independent audit will ask for, and where it is currently missing
  • Assess whether cyber security services being purchased require a licensed provider
  • Leave with a prioritised readiness gap list for their own organisation

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate, suitable for IT, risk, compliance, legal and operations leads, and for board members with oversight responsibility

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   10 to 15 question knowledge assessment covering all modules

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling

Frequently Asked Questions

Yes. Cyber Security Act 2024 (Act 854) NACSA Readiness Training is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Cyber Security Act 2024 (Act 854) NACSA Readiness Training runs for 1 day (8 hours) | 9:00 AM to 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate, suitable for IT, risk, compliance, legal and operations leads, and for board members with oversight responsibility. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.