Hakobi

Cybersecurity in Sabah

Last reviewed: 31 August 2026

Cybersecurity services cover the technical controls that keep a network defensible — firewalls, endpoint protection, access control, and monitoring — scoped against real obligations like PDPA and the Cyber Security Act 2024, not generic best-practice checklists.

The problem

Security spend is easy to under-prioritize until an incident or an audit forces the question. For regulated sectors — maritime, finance, and client-facing SMEs — the exposure isn’t hypothetical: PDPA and Act 854 carry real obligations, and “we’ll get to it” isn’t a defensible position during a review.

What’s included

  • Firewall deployment (ongoing configuration and monitoring is handled under Managed IT Services)
  • Endpoint protection and patching
  • Network access control and segmentation
  • Security monitoring and alerting
  • PDPA-aligned technical controls (access logging, data protection measures)
  • Security posture assessment
  • Incident response subscription via our Black Panda partnership (IR-1) — rapid response, continuous vulnerability and dark web monitoring, and insurance-backed recovery

How we deliver

Engagements typically start with a security assessment against the client’s current environment and applicable compliance obligations, followed by a prioritized remediation plan rather than a one-size-fits-all bundle.

Who this is for

Businesses in regulated or high-exposure sectors — maritime, logistics, finance and other client-facing SMEs — plus any business handling customer personal data under PDPA.

What it costs

Every security engagement is scoped against your actual environment and compliance obligations, so pricing depends on what’s already in place and what needs building. Request a quote and we’ll assess your posture before quoting a number.

Technology we use

Proof

Case study

FortiGate firewall migration for a Sabah port operator

FortiGate 61E-to-71G firewall migration across every site for a Sabah port operator, completed with under a minute of downtime per site to protect mission-critical port operations.

Frequently asked questions

Is this the same as firewall management?

Firewall management is one part of it — day-to-day FortiGate configuration and monitoring is handled under Managed IT Services. Cybersecurity as a whole also covers endpoint protection, access control, and compliance posture.

Do you handle PDPA compliance directly?

We design and implement the technical controls PDPA compliance depends on — access logging, data protection, breach detection. Legal compliance sign-off should still involve counsel.

What is Act 854 and does it apply to us?

The Cyber Security Act 2024 primarily targets National Critical Information Infrastructure (NCII) sectors — ports, utilities, government. See the Maritime industry page for the specific obligations.

Do you offer penetration testing?

Confirm current scope — if not offered directly, we can coordinate with a partner testing firm as part of a security engagement.

How do you handle incident response?

Through our partnership with Black Panda, clients can subscribe to IR-1 — a fixed-fee annual incident response plan rather than a traditional per-incident retainer. It bundles one incident response credit backed by Black Panda's cyber emergency team, continuous vulnerability scanning and dark web monitoring for leaked credentials, and insurance-backed recovery support. Activation is self-service through Black Panda's platform, with response inside 4 hours.

Ready to talk to an engineer?

Tell us about your site, your network, or your compliance deadline. We'll respond within one business hour.