Cyber Security Code of Practice for Banking and Finance NCII Entities (RMiT Appendix 12)

On 25 September 2026 Bank Negara Malaysia reissued its Risk Management in Technology policy document with a new Appendix 12, the Code of Practice for National Critical Information Infrastructure entities designated by BNM under the banking and finance sector. Read together with the cyber security requirements in the main body of RMiT, Appendix 12 is the code of practice required under section 25 of the Cyber Security Act 2024 for this sector, and BNM states the requirements have been endorsed by NACSA. It is legally binding on every financial institution BNM has designated as an NCII entity. Where it overlaps with or differs from the main body of RMiT, the appendix prevails for NCII entities, while requirements already in the main body keep their own effective dates. An entity may use alternative measures only if it proves to NACSA's Chief Executive that they give equal or higher protection.

The appendix turns the Act's broad duties into specific, checkable obligations: a cyber security policy aligned with ISO/IEC 27001 and 27002, NIST and OWASP and reviewed at least annually, a dedicated cyber security budget, an annual cyber security risk assessment and an audit at least every two years by a NACSA-approved auditor, each reported to NACSA within 30 days, notice to the sector lead within 30 days of material changes to the NCII, incident notification immediately and within 6 hours through NC4 with supplementary information within 14 days, data leakage prevention linked to the SIEM, annual scenario testing, and an annual review of code compliance. This two-day course is for CISOs, technology and cyber risk, IT security, compliance and internal audit teams at designated banks, insurers, takaful operators, DFIs and payment institutions. It works clause by clause, maps each one to the RMiT paragraph it builds on, and ends with a gap assessment. For the wider policy see BNM RMiT Compliance, and for the Act itself Cyber Security Act 2024 readiness.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

Appendix 12 and How It Fits With RMiT and Act 854

The 25 September 2026 reissue of RMiT, how Appendix 12 and the RMiT cyber requirements together form the section 25 code of practice, who is bound as a BNM-designated NCII entity, NACSA endorsement, precedence over the main body, preserved effective dates, and alternative measures under section 21(2).

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

Governance, Policy and Objectives

Board and senior management duties under RMiT sections 8, 9 and 11, formally assigned Act 854 roles, a cyber security policy aligned with ISO/IEC 27001 and 27002:2022, the NIST Cybersecurity Framework and OWASP Top 10, annual policy review, and SMART cyber security objectives reported annually to the governance committee.

05

Day 1, 11:30 AM - 12:30 PM

People, Budget, Awareness and Acceptable Use

The CISO and cyber team roles, a dedicated cyber security budget reviewed annually, contacts with NC4 and the police, awareness training that new staff complete before gaining access, and an IT acceptable use policy covering remote work and personal devices.

06

Day 1, 12:30 PM - 1:30 PM

Lunch

07

Day 1, 1:30 PM - 3:15 PM

Audits, Suppliers and Assets

The cyber security audit plan, audits at least once every two years from designation by a NACSA-approved auditor, audit reports to NACSA within 30 days, audits directed after material changes, supplier security, the asset inventory, notifying the sector lead within 30 days of material NCII changes, and quarterly preventive maintenance.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 4:45 PM

Cyber Security Risk Assessment and Treatment

Annual risk assessments from designation and after significant changes, what the report must contain, submission to NACSA and the sector lead within 30 days, prioritising high risks, and choosing between avoiding, modifying, sharing and retaining risk in a documented treatment plan.

10

Day 1, 4:45 PM - 5:00 PM

Day 1 Close

Recap and what to review before day two.

11

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

Recap of day one and the questions it left open.

12

Day 2, 9:15 AM - 10:15 AM

Data Security and Secure Engineering

Data leakage prevention integrated with the SIEM, the data lifecycle from acquisition and annual inventory to classification, encryption and disposal, application security, secure configuration, non-disclosure agreements, and physical security and perimeters.

13

Day 2, 10:15 AM - 10:30 AM

Break

14

Day 2, 10:30 AM - 12:30 PM

Network, Access and Vulnerability Management

Network security policies, diagrams and controls, malware protection, identity and access management, segregation of duties, password management, and a vulnerability assessment plan combining automated and manual testing with CVSS-based, threat-informed remediation.

15

Day 2, 12:30 PM - 1:30 PM

Lunch

16

Day 2, 1:30 PM - 3:15 PM

Incidents, Continuity and Testing

Event monitoring, the cyber security incident management procedure, notification immediately and within 6 hours through NC4, supplementary information within 14 days, three authorised persons, the CSIRT, business continuity planning, annual scenario-based testing, and the OT and e-commerce requirements including PCI-DSS.

17

Day 2, 3:15 PM - 3:30 PM

Break

18

Day 2, 3:30 PM - 4:45 PM

Workshop: Appendix 12 Gap Assessment

Teams assess a case bank against every section of the appendix, map each gap to its RMiT paragraph, decide which gaps need alternative measures justified to NACSA, and draft the annual code compliance report for the governance committee.

19

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Explain how RMiT Appendix 12 forms the Cyber Security Act code of practice for banking and finance
  • Identify which requirements bind your institution as a BNM-designated NCII entity and when
  • Meet the audit, risk assessment and material-change reporting duties and their 30-day deadlines
  • Run incident notification to NC4 immediately, within 6 hours and within 14 days
  • Map every Appendix 12 clause to existing RMiT controls and close the gaps
  • Produce the annual code of practice compliance review for the governance committee

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. For CISOs, technology and cyber risk, IT security, compliance and internal audit teams at BNM-designated NCII entities and institutions that may be designated. Working knowledge of RMiT assumed.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   An Appendix 12 gap assessment and draft compliance report for a case bank, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. Cyber Security Code of Practice for Banking and Finance NCII Entities (RMiT Appendix 12) is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Cyber Security Code of Practice for Banking and Finance NCII Entities (RMiT Appendix 12) runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. For CISOs, technology and cyber risk, IT security, compliance and internal audit teams at BNM-designated NCII entities and institutions that may be designated. Working knowledge of RMiT assumed. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.