Safeware Glasswall APAC Partner Book a demo

Explore

What is CDRZero TrustThe detection gapCapabilitiesUse cases

Products

ProductsIntegrationFile support

Compliance

Compliance hub
Country guidesSingaporeAustraliaJapanSouth KoreaIndiaIndonesiaMalaysiaThailandVietnamPhilippinesTaiwanNew ZealandMongoliaAPAC overview

More

Trust & certificationsAboutDocumentation Book a demo

Regulatory landscape ยท Southeast Asia

Malaysia: file security and audit obligations

Malaysia's Cyber Security Act 2024 created a licensed NCII regime under NACSA, and PDPA amendments effective June 2025 added mandatory breach notification and data protection officers.

At a glance

How Malaysia regulates file security

  • 01

    Regime

    Licensed NCII regime under the Cyber Security Act 2024

  • 02

    File security

    NACSA-directed codes of practice and risk assessment for NCII entities

  • 03

    Audit and evidence

    Mandatory incident reporting; PDPA breach notification since June 2025

Overview

The regulatory picture

The Cyber Security Act 2024 (Act 854) was gazetted on 26 June 2024 and came into effect on 26 August 2024, and it changed Malaysia from a guidance market to a regulated one. It establishes the National Cyber Security Committee, gives expanded powers to the National Cyber Security Agency (NACSA), and imposes obligations on entities designated as National Critical Information Infrastructure (NCII)- computers or systems whose disruption would be detrimental to national functions, public safety or public order. In-scope entities face mandatory risk assessments, incident reporting and adherence to codes of practice, and cybersecurity service providers now require licensing.

In parallel, amendments to the Personal Data Protection Act 2010 took effect from 1 June 2025, introducing mandatory data protection officer appointments for certain processing, mandatory data breach notification, and data portability rights.

The landscape

Instruments that reach file security and audit

InstrumentAuthorityStatusRelevance
Cyber Security Act 2024 (Act 854)NACSAIn forceDirect
Personal Data Protection Act 2010 (as amended 2024)JPDPIn forceDirect

NACSA

Cyber Security Act 2024 (Act 854)

In force 26 August 2024. Establishes the NCII regime, mandatory risk assessments and incident reporting for designated entities, and licensing for cybersecurity service providers.

Why it matters for file security. NCII entities must conduct risk assessments and follow sector codes of practice. File-borne compromise of an NCII system is a material risk that has to be assessed and mitigated in a documented way.

How Glasswall addresses it. Deterministic rebuild of untrusted files entering an NCII environment is straightforward to document in a mandatory risk assessment, and the per-file verdict record supports the incident reporting obligation when a file-borne event has to be characterised.

Content Disarm and ReconstructionPer-file verdict recordICAP ClientGlasswall Halo / Glasswall Meteor

Source: NACSA

JPDP

Personal Data Protection Act 2010 (as amended 2024)

Amendments effective 1 June 2025 introduced mandatory data protection officers for certain processing, mandatory data breach notification and data portability rights.

Why it matters for file security. Mandatory breach notification means personal data sitting unmanaged in documents now carries a disclosure consequence rather than only an internal one.

How Glasswall addresses it. Find & Redact removes named data patterns from documents before storage or sharing, and Storage Monitor covers the existing Microsoft 365 estate, reducing the file population capable of triggering a notification.

Find & RedactStorage Monitor + SM AuditGlasswall Halo

Source: JPDP

Latest developments

What has changed in Malaysia

Most recent first.

  1. In forceMedium impact

    PDPA amendments take effect: mandatory breach notification and DPOs

    Amendments to Malaysia's Personal Data Protection Act took effect, introducing mandatory data protection officer appointments for certain processing activities, mandatory data breach notification, and data portability rights.

    Why it matters for file security. Breach notification creates an external consequence for personal data lost through documents, which raises the value of reducing what those documents carry.

    • banking
    • healthcare
    • telco
    • education

    Source: JPDP

  2. In forceHigh impact

    Cyber Security Act 2024 comes into force

    Malaysia's Cyber Security Act 2024 came into effect, establishing the NCII regime, NACSA's expanded powers, mandatory risk assessment and incident reporting duties, and licensing for cybersecurity service providers.

    Why it matters for file security. Moved Malaysia from advisory guidance to a statutory regime with designated entities and documented control obligations, including for content entering critical systems.

    • cii
    • government
    • banking
    • telco
    • energy

    Source: NACSA

Scope

About this page

This page is a working reference for organisations operating in Malaysia.

It is not legal advice. Regulatory obligations depend on how an organisation is designated, which sector it operates in and how its systems are architected, take local advice before relying on any of this for a compliance decision. Where we describe how Glasswall relates to an obligation, we are describing a control, not certifying an outcome.

Planning a deployment in Malaysia?