SC Cybersecurity and Technology Risk Guidelines for Capital Market Entities

A half-day boardroom programme for directors, senior management and compliance leads at capital market entities regulated by the Securities Commission Malaysia. The SC's technology risk management and cyber risk requirements place accountability at board and senior management level: the board is expected to understand the entity's technology and cyber risk exposure, approve the framework and the risk appetite behind it, and satisfy itself that incident response actually works rather than merely exists on paper.

The session is built around oversight and decision-making rather than technical implementation. No technical background is assumed. It closes with a short board-level tabletop scenario in which participants make the calls that would genuinely sit with them during an incident, including when to notify the regulator and what to tell clients.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:00 AM

The Regulatory Picture

The Securities Commission's technology risk management and cyber risk requirements for capital market entities, and how they sit alongside the Capital Markets and Services Act 2007, the SC's guidelines on conduct and on outsourcing, the Personal Data Protection Act 2010 and its 2024 amendments, and the Cyber Security Act 2024 where an entity is also designated as national critical information infrastructure.

03

10:00 AM - 10:45 AM

Board and Senior Management Accountability

What the board is expected to approve, review and challenge: the technology risk management framework, the risk appetite, the cyber risk register, budget and resourcing, and the assurance the board should be receiving and from whom. What a board pack on cyber risk should contain, and the questions directors should be asking management when it does not.

04

10:45 AM - 11:00 AM

Break

05

11:00 AM - 11:45 AM

Cyber Risk in a Capital Markets Setting

The threat scenarios that matter for intermediaries and market participants: client account takeover, business email compromise and payment fraud, ransomware affecting trade processing and settlement, third-party and vendor compromise, insider misuse of client and market-sensitive data, and outages that interrupt client access during market hours. Each framed by the obligation it puts at risk.

06

11:45 AM - 12:30 PM

Incident Response and Notification

The entity's obligation to notify the Securities Commission of cyber incidents, the internal decision chain in the first hours, client communication, evidence preservation, and how the notification duty interacts with PDPA breach notification where personal data is involved. Who has authority to decide, and what gets recorded.

07

12:30 PM - 12:50 PM

Board-Level Tabletop Scenario

A short simulation of an unfolding incident. Participants make the decisions that would sit with the board and senior management, including when to notify, what to disclose, and what to hold. Debrief against the obligations covered during the session.

08

12:50 PM - 1:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • State what the Securities Commission expects the board and senior management to own in technology and cyber risk
  • Read and challenge a cyber risk report rather than receive it passively
  • Recognise the cyber scenarios with the highest impact on a capital market entity's clients and regulatory obligations
  • Understand incident notification duties to the SC and how they interact with PDPA breach notification
  • Make and record board-level decisions while an incident is still unfolding
  • Identify the gaps in the entity's current board-level cyber oversight

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Board and senior management level, suitable for directors, senior management, compliance and risk leads. No technical background assumed

Duration   Half-Day (4 Hours)  |  9:00 AM to 1:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   Facilitated tabletop scenario and debrief; a written knowledge assessment is available on request

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling

Frequently Asked Questions

Yes. SC Cybersecurity and Technology Risk Guidelines for Capital Market Entities is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

SC Cybersecurity and Technology Risk Guidelines for Capital Market Entities runs for half-day (4 hours) | 9:00 AM to 1:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Board and senior management level, suitable for directors, senior management, compliance and risk leads. No technical background assumed. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.