Cyber Security Act 2024 (Act 854) & NACSA Readiness
The Cyber Security Act 2024 came into operation on 26 August 2024 and changed the position for two very different groups. Organisations designated as National Critical Information Infrastructure entities picked up statutory duties on risk assessment, audit and incident reporting. Companies that sell cyber security services picked up a licensing requirement with criminal penalties attached to getting it wrong. This programme separates the two, works out which one describes you, and turns the obligations into a checklist you can act on.
Programme Agenda
What the Act Does and Who It Reaches
Structure of Act 854, the role of the Chief Executive of NACSA, and the distinction between sector leads, NCII entities and licensed service providers. Reading the Act to work out which category applies to your organisation.
NCII Designation and the Sectors
How designation works, the sectors covered by the national critical information infrastructure framework, and what changes on the day an entity is designated. What to do if you supply a designated entity without being one yourself.
Duties of an NCII Entity
Implementing the code of practice, conducting cyber security risk assessments, commissioning audits at the required frequency, and maintaining the records that evidence all three.
Incident Notification Mechanics
What counts as a reportable cyber security incident, the notification chain through the sector lead to NACSA, timing, and the information required in the initial and follow-up reports.
Licensing for Cyber Security Service Providers
Which services fall inside the licensing regime, how the application works, the one-year validity and renewal window, and the penalty for providing a licensable service without a licence: a fine of up to RM500,000, imprisonment of up to ten years, or both.
Where Act 854 Meets the PDPA
A single incident can trigger duties under both statutes on different clocks. Running the Act 854 notification and the PDPA 72-hour notification to the Commissioner in parallel without one delaying the other.
Building the Evidence Pack
Assembling the risk assessment, audit report, incident register, and code of practice conformance record into something that can be produced on request rather than reconstructed under pressure.
Readiness Workshop
Participants score their own organisation against the obligations that apply to it, identify the gaps, and leave with a prioritised remediation list and named owners.
Learning Outcomes:
Determine whether your organisation is an NCII entity, a service provider, both, or neither
State the statutory duties that follow from each category
Plan the risk assessment and audit cycle an NCII entity is required to maintain
Recognise a reportable incident and run the notification chain correctly
Assess whether a service you sell falls inside the licensing regime
Run Act 854 and PDPA notification duties in parallel after a single incident
Assemble an evidence pack that can be produced on request
Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Cybersecurity
- Data Breach Response and Incident Management · All levels, 1 day
- Incident Response and Digital Forensics · Intermediate, 2 days
- Cloud Security Fundamentals (AWS, Azure, GCP) · Intermediate, 2 days
- OT and ICS Security · All levels, 2 days
- CompTIA Security+ Certification · Intermediate, 5 days
- CompTIA CySA+ Certification · Intermediate to Advanced, 5 days
- ISC2 Certified in Cybersecurity (CC) · Beginner, 3 days
- CEH Certified Ethical Hacker · Intermediate, 5 days