THE EQUILIBRIUM JOURNAL / EXECUTIVE BRIEFING
Malaysia’s Cyber Security Act commences, alongside an adjustment to securities-market technology-risk guidance.
1–31 August 2024
Download this issue · PDF Subscribe free
What happened
26 August 2024 · Malaysia
Act 854 takes effect
Commencement
Malaysia’s Cyber Security Act 2024 commenced on 26 August. The framework addresses critical information infrastructure, incident management and licensing of specified cybersecurity services. Whether a particular organisation or service falls within it requires checking the statutory definitions and implementing instruments.
19 August 2024 · Malaysia
Recognised markets align technology-risk provisions
Guidelines amended
The SC amended its Guidelines on Recognized Markets to align relevant provisions with its revised technology-risk management guidelines. Operators should work from the updated instruments, rather than an old onboarding checklist.
Source: Securities Commission Malaysia · Amendment summary, 19 August 2024 ↗
The Malaysian lens
Our operational implication: a cyber incident can involve more than one reporting or supervisory relationship. A Malaysian market operator should map each applicable regime, its responsible officer and the evidence needed, without assuming that notifying one authority satisfies another.
QUESTION TO ASK
Who can classify an incident, preserve the records and initiate the correct escalation outside office hours?
Watch / next step
Review contracts with security providers and test the incident contact list. This briefing highlights commencement and alignment; it does not prescribe a universal reporting deadline for all organisations.
Sources checked on 20 September 2026. Official sources are preferred; news reports are identified as such. Maintained source pages may contain later updates. Check the enacted text, applicable jurisdiction and current position before acting. General information, not legal advice.
