Risk Consulting

Cyber Security Act 2024 (Act 854)

Readiness and compliance for Malaysia's Cyber Security Act 2024 (Act 854), for appointed NCII entities.

Malaysia's Cyber Security Act 2024 (Act 854) places new, time-sensitive obligations on appointed National Critical Information Infrastructure (NCII) entities. Nexagate helps you achieve and maintain compliance across one Act, four cyber security regulations and ten NACSA Chief Executive Directives.

As a NACSA-licensed and CREST-accredited provider, we take you from readiness consultation and gap assessment through to compliance. Our services cover the NCII Cyber Security Audit (once every two years), the annual Cyber Security Risk Assessment (CSRA), Post-Quantum Cryptography (PQC) migration within three months of a NACSA notice, cyber security incident obligations, the National Cyber Security Baseline Assessment (NCSB) and a Crisis Management Plan (CMP). We follow our 5'i' Compliance Journey, and your evidence, gaps and risk register are tracked in NSI.

Act 854 compliance services

NCII Cyber Security Audit

Independent cyber security audit for appointed NCII entities, required once every two years.

Cyber Security Risk Assessment (CSRA)

The annual cyber security risk assessment required under Act 854.

Post-Quantum Cryptography Migration (PQC)

Readiness for and migration to post-quantum cryptography, within three months of a NACSA notice.

Cyber Security Incidents

Incident notification, response and reporting aligned to the NACSA directives.

National Cyber Security Baseline Assessment (NCSB)

Assessment against the national cyber security baseline, with gap closure.

Crisis Management Plan (CMP)

Development and exercising of a crisis management plan for cyber incidents.

Key benefits

Readiness for Malaysia's Cyber Security Act 2024 (Act 854) as an appointed NCII entity
Meet time-sensitive obligations: audit every two years, CSRA annually, PQC within three months of notice
Independent NCII cyber security audit and National Cyber Security Baseline Assessment
Incident notification, response and crisis management aligned to NACSA directives
Delivered by Malaysia's largest local risk and compliance consulting team
NACSA-licensed and CREST-accredited provider

How we work

01
Identify
Project planning, kick-off and gap analysis against Act 854 and the relevant NACSA directives.
02
Initiate
Scope and framework establishment, with policy and procedure development.
03
Implement
Risk assessment, risk treatment, awareness and training across the organisation.
04
Inquire
Implementation review, internal audit and management review.
05
Improve
Compliance and certification audit, with post-audit recommendations for continuous improvement.
Scope this engagement

Tell us your target scope and timeline. A consultant responds within one business day.

Request a quote
Why Nexagate
Act 854
Cyber Security Act 2024 readiness for NCII entities
NACSA
Licensed cybersecurity service provider
CREST
Accredited provider since 2020
Not sure which standard applies to you?

ISO 27001, RMiT, ISO 20000 and ISO 22301 overlap more than most organisations expect. A short call usually narrows it down.

Request a quote