Regulatory landscape ยท Southeast Asia
Malaysia: file security and audit obligations
Malaysia's Cyber Security Act 2024 created a licensed NCII regime under NACSA, and PDPA amendments effective June 2025 added mandatory breach notification and data protection officers.
At a glance
How Malaysia regulates file security
- 01
Regime
Licensed NCII regime under the Cyber Security Act 2024
- 02
File security
NACSA-directed codes of practice and risk assessment for NCII entities
- 03
Audit and evidence
Mandatory incident reporting; PDPA breach notification since June 2025
Overview
The regulatory picture
The Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into effect on 26 August 2024, and it changed Malaysia from a guidance market to a regulated one. It establishes the National Cyber Security Committee, gives expanded powers to the National Cyber Security Agency (NACSA), and imposes obligations on entities designated as National Critical Information Infrastructure (NCII)- computers or systems whose disruption would be detrimental to national functions, public safety or public order. In-scope entities face mandatory risk assessments, incident reporting and adherence to codes of practice, and cybersecurity service providers now require licensing.
In parallel, amendments to the Personal Data Protection Act 2010 took effect from 1 June 2025, introducing mandatory data protection officer appointments for certain processing, mandatory data breach notification, and data portability rights.
The landscape
Instruments that reach file security and audit
| Instrument | Authority | Status | Relevance |
|---|---|---|---|
| Cyber Security Act 2024 (Act 854) | NACSA | In force | Direct |
| Personal Data Protection Act 2010 (as amended 2024) | JPDP | In force | Direct |
NACSA
Cyber Security Act 2024 (Act 854)
In force 26 August 2024. Establishes the NCII regime, mandatory risk assessments and incident reporting for designated entities, and licensing for cybersecurity service providers.
Why it matters for file security. NCII entities must conduct risk assessments and follow sector codes of practice. File-borne compromise of an NCII system is a material risk that has to be assessed and mitigated in a documented way.
How Glasswall addresses it. Deterministic rebuild of untrusted files entering an NCII environment is straightforward to document in a mandatory risk assessment, and the per-file verdict record supports the incident reporting obligation when a file-borne event has to be characterised.
Content Disarm and ReconstructionPer-file verdict recordICAP ClientGlasswall Halo / Glasswall Meteor
JPDP
Personal Data Protection Act 2010 (as amended 2024)
Amendments effective 1 June 2025 introduced mandatory data protection officers for certain processing, mandatory data breach notification and data portability rights.
Why it matters for file security. Mandatory breach notification means personal data sitting unmanaged in documents now carries a disclosure consequence rather than only an internal one.
How Glasswall addresses it. Find & Redact removes named data patterns from documents before storage or sharing, and Storage Monitor covers the existing Microsoft 365 estate, reducing the file population capable of triggering a notification.
Find & RedactStorage Monitor + SM AuditGlasswall Halo
Latest developments
What has changed in Malaysia
Most recent first.
-
PDPA amendments take effect: mandatory breach notification and DPOs
Amendments to Malaysia's Personal Data Protection Act took effect, introducing mandatory data protection officer appointments for certain processing activities, mandatory data breach notification, and data portability rights.
Why it matters for file security. Breach notification creates an external consequence for personal data lost through documents, which raises the value of reducing what those documents carry.
- banking
- healthcare
- telco
- education
-
Cyber Security Act 2024 comes into force
Malaysia's Cyber Security Act 2024 came into effect, establishing the NCII regime, NACSA's expanded powers, mandatory risk assessment and incident reporting duties, and licensing for cybersecurity service providers.
Why it matters for file security. Moved Malaysia from advisory guidance to a statutory regime with designated entities and documented control obligations, including for content entering critical systems.
- cii
- government
- banking
- telco
- energy
Elsewhere in the region
Other APAC territories
Scope
About this page
This page is a working reference for organisations operating in Malaysia.
It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.