Rajah & Tann Regional Round-Up
your snapshot of key legal developments in Asia
Issue 2 - Apr/May/Jun 2024
 

The New Cyber Security Act 2024: Update on its Gazettement and Expected Developments

The Cyber Security Bill 2024 ("Bill"), aimed at enhancing the country's cybersecurity and strengthening the protection of the National Critical Information Infrastructure ("NCII") from cyber threats and incidents, was passed by the Malaysian Parliament in April 2024.


The Bill has since received royal assent and was gazetted as the Cyber Security Act 2024 (Act 854) ("CSA") on 26 June 2024, although it has yet to come into force, and will only take effect on a future date to be gazetted by the Malaysian Government. This is expected to occur by the third quarter of 2024.


Now that the CSA has been gazetted, businesses can expect the following to happen next:


  1. Publication of the Names of NCII Sector Leads

  2. The Minister will designate one or more NCII Sector Leads for each of the identified 11 NCII Sectors, by publishing the names of the appointed NCII Sector Leads on the National Cyber Security Agency ("NACSA") website.

  3. Issuance of Subsidiary Regulations

  4. The Malaysian Government and NACSA are currently developing subsidiary regulations to supplement the CSA including:
  • the Cyber Security (Licensing of Cyber Security Service Providers) Regulations 2024, which will clarify the licensing requirements for cybersecurity service providers;
  • the Cyber Security (Compounding of Offences) Regulations 2024, which will identify the relevant offences under the CSA which are compoundable, and other ancillary procedural requirements;
  • the Cyber Security (Risk Assessment and Audit) Regulations 2024, which will clarify the requirements of cybersecurity risk assessment and audit that NCII Entities will be required to carry out under section 22 of the CSA; and
  • the Cyber Security (Cyber Security Incident Notification) Regulations 2024, which will set out further details regarding the cybersecurity incident notification obligation to the Chief Executive of NACSA and NCII Sector Leads imposed on NCII Entities.

   c. Preparation of Codes of Practice


Once the NCII Sector Leads for the identified 11 NCII Sectors are appointed, they will develop sector-specific codes of practice for their respective sectors that set out the minimum cybersecurity measures, standards and processes that NCII Entities must implement and comply with to protect their NCII.


All relevant businesses and stakeholders should stay abreast of developments relating to the implementation of the CSA, and initiate steps and allocate resources in preparation for compliance with the CSA.


For more information on the regulatory structure and key requirements introduced by the CSA, click here for our previous Legal Update and here for our Snapshot Deck.



Please note that whilst the information in this Update is correct to the best of our knowledge and belief at the time of writing, it is only intended to provide a general guide to the subject matter and should not be treated as a substitute for specific professional advice.

 

Christopher & Lee Ong
Level 22, Axiata Tower ,
No. 9 Jalan Stesen Sentral 5
Kuala Lumpur Sentral,
50470 Kuala Lumpur, Malaysia
www.christopherleeong.com


Contacts:

Kuok Yew Chen
Partner
D +603 7958 8310
F +603 7958 8311
yew.chen.kuok@christopherleeong.com

John Mathew
Partner
D +603 2267 2626
F +603 2273 8310
john.mathew@christopherleeong.com

Yon See Ting
Partner
D +603 2278 8311
F +603 2278 8322
see.ting.yon@christopherleeong.com

Yau Yee Ming
Partner
D +603 2278 8311
F +603 2273 8322
yee.ming.yau@christopherleeong.com

Deepak Pillai
Partner
D +603 2267 2675
F +603 2273 8310
deepak.pillai@christopherleeong.com

Celia Cheah
Partner
D +603 2267 2732
F +603 2273 8310
celia.cheah@christopherleeong.com

Chor Jack
Partner
D +603 2267 2729
F +603 2273 8310
jack.chor@christopherleeong.com

Rubini Murugesan
Partner
D +603 2267 2616
F +603 2273 8310
rubini.murugesan@christopherleeong.com

Lim Siaw Wan
Partner
D +603 2267 2731
F +603 2273 8310
siawwan.lim@christopherleeong.com

Rajah & Tann Asia is a network of legal practices based in Asia.

Member firms are independently constituted and regulated in accordance with relevant local legal requirements. Services provided by a member firm are governed by the terms of engagement between the member firm and the client.

This update is solely intended to provide general information and does not provide any advice or create any relationship, whether legally binding or otherwise. Rajah & Tann Asia and its member firms do not accept, and fully disclaim, responsibility for any loss or damage which may result from accessing or relying on this update.