SC Cybersecurity and Technology Risk Guidelines for Capital Market Entities

A half-day boardroom programme for directors, senior management and compliance leads at capital market entities regulated by the Securities Commission Malaysia. The SC's technology risk management and cyber risk requirements place accountability at board and senior management level: the board is expected to understand the entity's technology and cyber risk exposure, approve the framework and the risk appetite behind it, and satisfy itself that incident response actually works rather than merely exists on paper.

The session is built around oversight and decision-making rather than technical implementation. No technical background is assumed. It closes with a short board-level tabletop scenario in which participants make the calls that would genuinely sit with them during an incident, including when to notify the regulator and what to tell clients.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:00 AM

The Regulatory Picture

The Securities Commission's technology risk management and cyber risk requirements for capital market entities, and how they sit alongside the Capital Markets and Services Act 2007, the SC's guidelines on conduct and on outsourcing, the Personal Data Protection Act 2010 and its 2024 amendments, and the Cyber Security Act 2024 where an entity is also designated as national critical information infrastructure.

03

10:00 AM - 10:45 AM

Board and Senior Management Accountability

What the board is expected to approve, review and challenge: the technology risk management framework, the risk appetite, the cyber risk register, budget and resourcing, and the assurance the board should be receiving and from whom. What a board pack on cyber risk should contain, and the questions directors should be asking management when it does not.

04

10:45 AM - 11:00 AM

Break

05

11:00 AM - 11:45 AM

Cyber Risk in a Capital Markets Setting

The threat scenarios that matter for intermediaries and market participants: client account takeover, business email compromise and payment fraud, ransomware affecting trade processing and settlement, third-party and vendor compromise, insider misuse of client and market-sensitive data, and outages that interrupt client access during market hours. Each framed by the obligation it puts at risk.

06

11:45 AM - 12:30 PM

Incident Response and Notification

The entity's obligation to notify the Securities Commission of cyber incidents, the internal decision chain in the first hours, client communication, evidence preservation, and how the notification duty interacts with PDPA breach notification where personal data is involved. Who has authority to decide, and what gets recorded.

07

12:30 PM - 12:50 PM

Board-Level Tabletop Scenario

A short simulation of an unfolding incident. Participants make the decisions that would sit with the board and senior management, including when to notify, what to disclose, and what to hold. Debrief against the obligations covered during the session.

08

12:50 PM - 1:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Board and senior management level, suitable for directors, senior management, compliance and risk leads. No technical background assumed

Duration   Half-Day (4 Hours)  |  9:00 AM to 1:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   Facilitated tabletop scenario and debrief; a written knowledge assessment is available on request

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling