Cyber Security Act 2024 (Act 854): Does It Affect Your SME?

Digital padlock with Act 854 text representing Malaysia's Cyber Security Act against a data-themed background.

Key Takeaways

  • You Might Be Regulated Indirectly: The Act governs 11 critical sectors (NCII), but it contractually impacts SMEs acting as their vendors or suppliers.
  • The “6-Hour” Rule: Failure to report a cyber incident within 6 hours can lead to fines up to RM500,000 or 10 years in prison.
  • Supply Chain Trap: Even if you aren’t an NCII entity, your enterprise customers (e.g., banks, government) will now force Act 854 standards onto you via new contracts.
  • Mandatory Audits: Designated NCII entities must conduct annual risk assessments and bi-annual audits.
  • License to Operate: IT companies offering Managed SOC or Penetration Testing services must now be licensed or face prison time.

Is your business ready for Malaysia’s new cyber laws?

Yes, Act 854 affects any SME that is either designated as a National Critical Information Infrastructure (NCII) entity OR serves as a third-party vendor to one. If you handle data for banks, government agencies, or healthcare providers, you are now part of a regulated supply chain.

Let’s be real—most Malaysian SME owners see “Cyber Security Act” and think it’s a problem for Maxis, Maybank, or TNB. But here’s the kicker: if you are a software vendor for a bank, or a logistics partner for a government agency, you are the “weak link” the government is looking at. With Act 854 officially in force as of August 26, 2024, the days of “we’ll fix the IT later” are legally over.

🧾 Act 854 Quick Compliance Summary

Feature

Details for SMEs

Impact Level

Primary Target

11 NCII Sectors (Banking, Gov, Energy, etc.)

High

Vendor Impact

Must meet client’s security “Code of Practice”

Critical

Incident Reporting

Must notify authorities within 6 hours of discovery

Mandatory

Audit Requirement

Annual Risk Assessment & Bi-annual Audit

Standard

Licensing

Required for SOC & Pentest providers

Legal Risk

Maximum Fine

Up to RM500,000 or 10 Years Jail

Severe

The 11 NCII Sectors: Are You on the List?

If you sell to these industries, you are in the splash zone.

The Act defines National Critical Information Infrastructure (NCII) as systems where disruption would damage the national economy, defence, or public safety. The 11 specific sectors are:

  1. Government (Ministries & Agencies)
  2. Banking & Finance (Banks, Insurance, E-wallets)
  3. Transportation (Airlines, Rail, Logistics/Ports)
  4. Defence & National Security
  5. Information, Communication & Digital (Telcos, Data Centers)
  6. Healthcare Services (Hospitals, Private Chains)
  7. Water, Sewerage & Waste Management
  8. Energy (TNB, Oil & Gas)
  9. Agriculture & Plantation
  10. Trade, Industry & Economy
  11. Science, Technology & Innovation

The Reality Check: You might run a small HR software company. But if your software is used by a Government Hospital (Sector 6) or a Regional Bank (Sector 2), disruption to your system could disrupt theirs. Under the Act, the Sector Lead (e.g., Bank Negara or MOH) can direct the NCII entity to ensure their vendors (you) are secure.

The “Vendor Trap”: Why SMEs Must Care

Your clients can no longer ignore your bad security.

Before Act 854, if a bank’s vendor got hacked, the bank just fired the vendor. Now, the bank can be fined for failing to secure its supply chain. This means big enterprise clients are rewriting their contracts.

What to expect in your new contracts:

  • Mandatory Incident Reporting: You must tell them if you are hacked immediately so they can report to NACSA within 6 hours.
  • Right to Audit: They will demand to see your Penetration Testing reports or ISO certification.
  • Liability Clauses: If your lack of security causes them to fail an audit, they may pass the fine onto you.

Scenario: You run a digital marketing agency handling customer data for a retail chain (Trade & Industry Sector). If your server is hit by Ransomware, and that data leaks, your client is liable under Act 854. They will sue you for negligence if you didn’t follow the “Code of Practice.”

New Rules for IT Companies (Licensing)

Are you an IT Service Provider? Read this carefully.

If your SME provides specific cybersecurity services, you are no longer allowed to operate freely. You must obtain a license from the National Cyber Security Agency (NACSA).

Services requiring a license:

  1. Managed Security Operations Centre (SOC) monitoring services.
  2. Penetration Testing services.

The Penalty: providing these services without a license carries a fine of up to RM500,000 or 10 years imprisonment. If you are a general IT support company, this is the time to partner with a Licensed MSP rather than trying to do it yourself illegally.

The Penalties: The Price of Ignorance

The government is not playing around.

The fines in Act 854 are designed to hurt. They apply primarily to NCII entities, but remember—contracts pass these costs down the chain.

  • Failure to Report an Incident:

    • Fine: Up to RM500,000
    • Jail: Up to 10 Years
    • Trigger: Not reporting a breach to NACSA within 6 hours.
  • Failure to Conduct Risk Assessments/Audits:

    • Fine: Up to RM200,000
    • Jail: Up to 3 Years
    • Trigger: Skipping your annual security review.
  • Failure to Comply with Directives:

    • Fine: Up to RM100,000
    • Trigger: Ignoring an order from the Sector Lead to patch a vulnerability.

What Should Malaysian SMEs Do Now?

Don’t panic, but don’t ignore it.

  1. Check Your Client List: Do you serve any of the 11 NCII sectors? If yes, expect an email from their compliance team soon.
  2. Review Your “Incident Response” Plan: If you were hacked at 2:00 AM, would you know who to call? You need a plan that works in under 6 hours.
  3. Get a “Gap Analysis”: You don’t need to be Fort Knox, but you need to know where your doors are open. A simple audit can save you a contract.
  4. Update Your Data Privacy: This Act often works in tandem with the PDPA Amendments 2025, which covers personal data protection.

Need trusted vendors for Act 854 compliance? Find verified cybersecurity experts and local suppliers on Listing.my—Malaysia’s leading Business Directory for SMEs.

FAQs: Act 854 for Business Owners

Does Act 854 apply to my coffee shop?

Likely no, unless your coffee shop is the exclusive caterer for a military base and integrates with their procurement system. It targets "Critical Infrastructure."

Who do I report a hack to?

NCII entities must report to NACSA (National Cyber Security Agency) and their specific Sector Lead (e.g., Bank Negara for banks).

Can I just buy Antivirus and be safe?

No. Act 854 requires "process" compliance (audits, risk assessments, reporting), not just software. You need EDR and a proper monitoring team.

When did this law start?

It came into force on 26 August 2024. It is active law right now.

What is the difference between Act 854 and PDPA?

PDPA protects personal data (names, IC numbers). Act 854 protects critical systems and national security. You usually need to comply with both.