A half-day boardroom programme for directors, senior management and compliance leads at capital market entities regulated by the Securities Commission Malaysia. The SC's technology risk management and cyber risk requirements place accountability at board and senior management level: the board is expected to understand the entity's technology and cyber risk exposure, approve the framework and the risk appetite behind it, and satisfy itself that incident response actually works rather than merely exists on paper.
The session is built around oversight and decision-making rather than technical implementation. No technical background is assumed. It closes with a short board-level tabletop scenario in which participants make the calls that would genuinely sit with them during an incident, including when to notify the regulator and what to tell clients.
HRD Corp SBL-Khas Claimable
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:00 AM
The Regulatory Picture
The Securities Commission's technology risk management and cyber risk requirements for capital market entities, and how they sit alongside the Capital Markets and Services Act 2007, the SC's guidelines on conduct and on outsourcing, the Personal Data Protection Act 2010 and its 2024 amendments, and the Cyber Security Act 2024 where an entity is also designated as national critical information infrastructure.
10:00 AM - 10:45 AM
Board and Senior Management Accountability
What the board is expected to approve, review and challenge: the technology risk management framework, the risk appetite, the cyber risk register, budget and resourcing, and the assurance the board should be receiving and from whom. What a board pack on cyber risk should contain, and the questions directors should be asking management when it does not.
10:45 AM - 11:00 AM
Break
11:00 AM - 11:45 AM
Cyber Risk in a Capital Markets Setting
The threat scenarios that matter for intermediaries and market participants: client account takeover, business email compromise and payment fraud, ransomware affecting trade processing and settlement, third-party and vendor compromise, insider misuse of client and market-sensitive data, and outages that interrupt client access during market hours. Each framed by the obligation it puts at risk.
11:45 AM - 12:30 PM
Incident Response and Notification
The entity's obligation to notify the Securities Commission of cyber incidents, the internal decision chain in the first hours, client communication, evidence preservation, and how the notification duty interacts with PDPA breach notification where personal data is involved. Who has authority to decide, and what gets recorded.
12:30 PM - 12:50 PM
Board-Level Tabletop Scenario
A short simulation of an unfolding incident. Participants make the decisions that would sit with the board and senior management, including when to notify, what to disclose, and what to hold. Debrief against the obligations covered during the session.
12:50 PM - 1:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Board and senior management level, suitable for directors, senior management, compliance and risk leads. No technical background assumed
Duration Half-Day (4 Hours) | 9:00 AM to 1:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment Facilitated tabletop scenario and debrief; a written knowledge assessment is available on request
Certificate Certificate of Completion issued to all participants upon full attendance