Rajah & Tann Regional Round-Up
your snapshot of key legal developments in Asia
Issue 3 - Jul/Aug/Sep 2023
 

Updates on the Upcoming Draft Cybersecurity Bill

The Malaysian Government has recently reaffirmed its commitment to present a draft Cybersecurity Bill ("Bill") – to address existing gaps in Malaysia's cybersecurity legal framework – to Parliament by 2024.


The key components that will be addressed by the Cybersecurity Bill include:


  1. the establishment of the National Cyber Security Agency ("NACSA") as the national cybersecurity regulator entrusted with the necessary enforcement powers to oversee cybersecurity matters in the country;
  2. the designation of Critical National Infrastructure Information ("CNII") sectors, together with CNII sector leads to act as intermediaries between NACSA and CNII owners;
  3. the identification of computers and computer systems that will be designated as CNIIs;
  4. the issuance of specific directions or codes of practice to define minimum cybersecurity standards for CNII owners;
  5. the introduction of baseline audit and risk assessment requirements for CNII owners, wherein CNII owners will be required to conduct audits and risk assessments and submit reports to NACSA;
  6. the introduction of mandatory cybersecurity incident notification requirements; and
  7. the introduction of licensing requirements for service providers offering certain cybersecurity services identified in the Bill.


Once the Bill is enacted, it will introduce new compliance obligations for CNII owners and cybersecurity service providers. Additionally, organisations providing services or engaging with CNII owners may also be indirectly impacted by the requirements outlined by the Bill.


While there has been no official confirmation by the Government regarding the types of organisations that will be designated as CNII owners under the Bill, it is likely that the Bill will align with the 11 CNII sectors currently identified in the Malaysia Cyber Security Strategy 2020-2024 policy document, which include companies operating within the sectors of banking and finance, information and communication, energy, transportation, water, health services, emergency services, agriculture and plantation, etc.


As such, all organisations must update themselves on the status and developments of the Bill, and in the interim implement measures to ensure compliance with the possible obligations to be imposed by the Government once the Bill is passed by Parliament. 



Please note that whilst the information in this Update is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as a substitute for specific professional advice.

 

Christopher & Lee Ong
Level 22, Axiata Tower ,
No. 9 Jalan Stesen Sentral 5
Kuala Lumpur Sentral,
50470 Kuala Lumpur, Malaysia
www.christopherleeong.com


Contacts:

Kuok Yew Chen
Partner
D +603 7958 8310
F +603 7958 8311
yew.chen.kuok@christopherleeong.com

John Mathew
Partner
D +603 2267 2626
F +603 2273 8310
john.mathew@christopherleeong.com

Yon See Ting
Partner
D +603 2278 8311
F +603 2278 8322
see.ting.yon@christopherleeong.com

Yau Yee Ming
Partner
D +603 2278 8311
F +603 2273 8322
yee.ming.yau@christopherleeong.com

Deepak Pillai
Partner
D +603 2267 2675
F +603 2273 8310
deepak.pillai@christopherleeong.com

Sri Sarguna Raj
Partner
D +603 2267 2737
F +603 2273 8310
sri.sarguna.raj@christopherleeong.com

Chor Jack
Partner
D +603 2267 2729
F +603 2273 8310
jack.chor@christopherleeong.com

Rubini Murugesan
Partner
D +603 2267 2616
F +603 2273 8310
rubini.murugesan@christopherleeong.com

Lim Siaw Wan
Partner
D +603 2267 2731
F +603 2273 8310
siawwan.lim@christopherleeong.com

Rajah & Tann Asia is a network of legal practices based in Asia.

Member firms are independently constituted and regulated in accordance with relevant local legal requirements. Services provided by a member firm are governed by the terms of engagement between the member firm and the client.

This update is solely intended to provide general information and does not provide any advice or create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on this update.