Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

Cyber Security Act 2024 (Act 854) & NACSA Readiness

The Cyber Security Act 2024 came into operation on 26 August 2024 and changed the position for two very different groups. Organisations designated as National Critical Information Infrastructure entities picked up statutory duties on risk assessment, audit and incident reporting. Companies that sell cyber security services picked up a licensing requirement with criminal penalties attached to getting it wrong. This programme separates the two, works out which one describes you, and turns the obligations into a checklist you can act on.

Programme Agenda

What the Act Does and Who It Reaches

Structure of Act 854, the role of the Chief Executive of NACSA, and the distinction between sector leads, NCII entities and licensed service providers. Reading the Act to work out which category applies to your organisation.

NCII Designation and the Sectors

How designation works, the sectors covered by the national critical information infrastructure framework, and what changes on the day an entity is designated. What to do if you supply a designated entity without being one yourself.

Duties of an NCII Entity

Implementing the code of practice, conducting cyber security risk assessments, commissioning audits at the required frequency, and maintaining the records that evidence all three.

Incident Notification Mechanics

What counts as a reportable cyber security incident, the notification chain through the sector lead to NACSA, timing, and the information required in the initial and follow-up reports.

Licensing for Cyber Security Service Providers

Which services fall inside the licensing regime, how the application works, the one-year validity and renewal window, and the penalty for providing a licensable service without a licence: a fine of up to RM500,000, imprisonment of up to ten years, or both.

Where Act 854 Meets the PDPA

A single incident can trigger duties under both statutes on different clocks. Running the Act 854 notification and the PDPA 72-hour notification to the Commissioner in parallel without one delaying the other.

Building the Evidence Pack

Assembling the risk assessment, audit report, incident register, and code of practice conformance record into something that can be produced on request rather than reconstructed under pressure.

Readiness Workshop

Participants score their own organisation against the obligations that apply to it, identify the gaps, and leave with a prioritised remediation list and named owners.

Learning Outcomes:
Determine whether your organisation is an NCII entity, a service provider, both, or neither
State the statutory duties that follow from each category
Plan the risk assessment and audit cycle an NCII entity is required to maintain
Recognise a reportable incident and run the notification chain correctly
Assess whether a service you sell falls inside the licensing regime
Run Act 854 and PDPA notification duties in parallel after a single incident
Assemble an evidence pack that can be produced on request

Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Chief information security officers, IT and risk managers in the sectors covered by the NCII framework, compliance officers, legal counsel, and directors of companies that provide cyber security services in Malaysia.

Often, for two reasons. Designated entities push obligations down their supply chain contractually, so suppliers meet the requirements indirectly. And any company selling cyber security services in Malaysia is affected by the licensing regime regardless of designation.

No. The programme explains the statutory framework and what compliance involves in practice, and is not a substitute for advice from your own counsel on a specific designation or licensing question.

The content is reviewed before each delivery and the position stated in the session is the position at that date. Where a requirement is subject to pending subsidiary legislation, the session says so rather than presenting it as settled.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Cybersecurity