Cyber Security Act 2024 (Act 854): Does It Apply to Your Business?
Last updated: 31 August 2026
Malaysia's Cyber Security Act 2024 (Act 854) came into force on 26 August 2024, and it's a common source of confusion for businesses trying to work out whether it actually applies to them. The short answer: it depends on whether you're designated as National Critical Information Infrastructure, or whether you supply one.
What Act 854 actually is
The Act introduces the concept of National Critical Information Infrastructure (NCII) — a computer or system that, if disrupted, would harm key national or government functions, public safety, or public order. It applies across 11 defined sectors: Government, Banking and Finance, Transportation, Defence, Healthcare, Energy, Water, Agriculture, Trade, Science & Technology, and Information/Communication.
Who counts as NCII
Not every business in those 11 sectors is automatically designated — NCII status is a specific designation, not a blanket industry rule. Port and terminal operators are a clear example within the Transportation sector where designation is common given the operational stakes involved; the same logic extends to banks, utilities, and healthcare providers running systems that genuinely underpin critical services.
The part most businesses miss: third-party vendors
This is where scope catches businesses off guard. Act 854 obligations can extend to a company that isn't itself NCII-designated but supplies or services an entity that is — a vendor, contractor, or service provider connected into a critical system can inherit compliance expectations by association.
What NCII status requires in practice
Designated entities carry obligations around regular risk assessment, defined security measures, and formal incident reporting. This isn't a paperwork exercise — it changes how network architecture gets designed, particularly around separating operational technology (the systems actually running physical operations) from standard office IT, so a compromise in one doesn't cascade into the other.
What happens if you don't report an incident
Failing to report a cybersecurity incident under the Act carries real consequences — a fine of up to RM500,000, imprisonment of up to 10 years, or both. That's a materially higher bar than most businesses' existing incident response processes were built around.
How to find out if you're in scope
NCII designation is confirmed by the relevant sector authority, not self-assessed. If you operate in one of the 11 sectors, or supply into one, it's worth confirming your actual status rather than assuming either way — and building network segmentation and incident reporting capability that would hold up under the Act regardless of formal designation, since the underlying risk doesn't disappear just because the paperwork hasn't caught up.
Source: Cyber Security Act 2024 (Act 854), National Cyber Security Agency (NACSA).
