KUALA LUMPUR: The National Cyber Security Agency has strengthened the country's readiness against cyber threats through the National Cyber Crisis Management Plan, which sets out how critical organisations should respond when their systems are compromised. The agency, known as Nacsa, said the plan identifies the necessary response measures for entities designated as National Critical Information Infrastructure, covering public and private organisations. It is built on a risk management framework.

Nacsa chief executive Dr Megat Zuhairy Megat Tajuddin said the plan gives affected organisations a clear sequence of actions once a serious incident is confirmed. It covers entities designated as NCII, the term used for operators whose services underpin essential national functions. The approach is intended to shorten the time between detection and containment, and to remove guesswork from the early hours of a crisis.

Monitoring and intelligence work is carried out through the National Cyber Coordination and Command Centre, known as NC4, which issues advance warnings to entities that may be targeted by potential cyber threats. The centre also performs the functions of the Malaysia Computer Emergency Response Team, or MyCERT, which handles incident reports and coordinates technical assistance. Nacsa said NC4 is currently being upgraded.

Immediate reporting duties for critical entities

Entities infected by malicious code must report immediately to the Nacsa chief executive and to the head of their NCII sector. The duty is not optional and applies to organisations in both the public and private sectors that have been designated as critical. Nacsa said the requirement is anchored in the Cyber Security Act 2024 and the regulations issued under it, alongside the crisis management plan itself.

He said that this aligns with Section 23(1) of the Cyber Security Act 2024 (Act 854), and the Cyber Security (Notification of Cyber Security Incident) Regulations 2024, as outlined in the Nacsa Chief Executive's Directive Number 1 on cyber security incident notification, and the NCCMP.

The legislation is formally titled the Cyber Security Act 2024 and is also cited as Act 854. Section 23(1) deals with the duty to notify the authorities of a cyber security incident, while the accompanying regulations set out how notifications are to be made. Nacsa also issued Directive Number 1 on cyber security incident notification to guide entities on what to report and when.

Containment, recovery and forensic follow-up

Once an infection is confirmed, response measures can include isolating the affected servers, ensuring that all security patches are up to date, and clearing all data and settings from a server before restoring it from backups. Those steps are meant to stop a compromised machine from reintroducing malicious code into a restored environment. Digital forensics is then carried out to identify the attackers, and Nacsa will work with the police on the action that follows.

  • Isolate infected servers to stop the spread of malicious code
  • Make sure all security patches are up to date before systems return to service
  • Clear all data and settings from a server before restoring it from backup
  • Carry out digital forensics to identify the attackers
  • Work with the police on follow-up action

The emphasis on forensics shows that recovery is no longer the only objective once a critical system has been hit. Identifying who was behind an intrusion, and preserving evidence that can support action against them, now form part of the response. For operators, incident handling is therefore not purely a technical exercise but also a legal and regulatory one.

Malaysia in the global threat landscape

The strengthened framework comes as Malaysia remains an attractive target for attackers. According to the Microsoft Digital Defence report, Malaysia ranked 6th among countries targeted by cyberattacks in 2023, compared with 12th in 2024. The figures underline why national coordination matters for organisations that hold sensitive data and run essential services.

According to the Microsoft Digital Defence report, Malaysia ranked 6th among countries targeted by cyberattacks in 2023, compared with 12th in 2024.

Nacsa also announced institutional development on the cryptographic side. The National Cyber Security Council has approved the establishment of the Malaysian Cryptology Technology and Management Centre. Experts from Universiti Putra Malaysia, USM, UTeM, UiTM and UMS, as well as CyberSecurity Malaysia, will be placed at the centre. The aim is to deepen national expertise in cryptology.

What it means for Malaysia's cloud and data centre market

For cloud providers and data centre operators in Malaysia, the plan makes clear that serious security incidents are now handled as a matter of national coordination. Facilities that host data for critical sectors sit inside the scope of the NCII framework, and their customers will increasingly ask how incidents are detected, reported and contained. Advance warnings from NC4 give operators time to harden systems before an attack spreads.

  • Faster reporting means incident logs and timelines must be kept in order
  • Containment planning should cover server isolation and clean restoration
  • Patch management becomes an auditable commitment rather than routine housekeeping
  • Forensic readiness helps operators support investigations after an incident
  • Compliance with Act 854 is becoming part of customer due diligence

The plan also signals that security credentials are becoming part of commercial evaluation in Malaysia. Enterprises choosing a cloud or colocation partner are likely to ask how quickly an operator can detect, report and contain an incident, and whether those processes have been tested. Providers that can demonstrate a rehearsed response are better placed to win regulated workloads in the financial, healthcare and utility sectors.

Nacsa said the goal is to make the national response faster and more orderly when a crisis occurs. For businesses, preparation and compliance are becoming basic conditions for operating in Malaysia rather than optional extras, and operators should plan for them accordingly.

Source: The Star