Success
Fail
logo

The Cybersecurity Power Play: Three clocks start at once - are you ready?

Aug 27, 2026

By: Krishna Rajagopa

  • Malaysia's new cyber-AI rules can be enforced against you personally
  • Three regulators, four laws, and a director who can be charged under all of them

The phone rings at 5:30 on a Sunday morning. Not the polite chime of a calendar reminder, the kind that keeps ringing until somebody picks up. Your monitoring vendor has found encryption running on a file server and it is spreading. Nobody can tell you how far. Nobody can tell you whose data is inside. The forensics team is eight hours away, and whoever did this has had the whole weekend to work their mischief.

Think that is an unlikely scenario? Think again. I have sat on the other end of that call many times over my 25 years of dealing with incident response. The details change from case to case. The question that follows never does, usually after a long pause: who do we have to tell, and when?

Put yourself in that room, because the law already puts you there. If you sit on a Malaysian board, deadlines you may never have read are already counting down.

Clock one: Bank Negara, 2 hours. If your regulator is the central bank, someone must notify it of a significant incident within two hours under RMiT. It is now 5:47. A third of that hour is already gone, and the person with authority to make the call is asleep. (RMiT are a comprehensive set of requirements aimed at enhancing the technology risk management practices of financial nstitutions in Malaysia).

Clock two: NACSA, 6 hours. If your company is designated National Critical Information Infrastructure (NCII), you have six hours (no, that is not a typo) to submit prescribed information to the National Cyber Security Agency (NACSA). The Cyber Security Act 2024 covers 11 sectors, among them banking and finance, healthcare, energy, water, transport, agriculture, defence, government, and information, communication and digital. A hospital group or a port operator can be designated the same way a bank can. And the threshold is low: Section 23 engages where an incident has occurred, or might have. Confirmation is not required.

Clock three: the PDP Commissioner, 72 hours. If personal data is involved, and at 5:30 in the morning you must assume it is, the amended Personal Data Protection Act gives you 72 hours to notify the Commissioner. This one catches almost every company in Malaysia, designated or not. A late notification needs a written explanation with supporting evidence, and that explanation becomes part of the record. Affected individuals follow within seven days; NACSA takes a supplemental report at Day 14.

One event, three regulators, sometimes more, and the shortest deadline is a single hour. None of them waits for forensics. Two years ago a day like this ended in a post-mortem and a hard conversation with the CIO. The Cyber Security Act, in force since 26 August 2024, turns two this week. These days the day ends in a file, and the name on the cover belongs to the board.

How ready are the people whose name is on the cover?

Between Dec 2025 and March 2026, Accenture Malaysia and FIDE Forum put an AI questionnaire in front of roughly a hundred board directors at Malaysian banks, insurers and takaful operators. About a third replied, which the authors themselves flagged as a finding, and credit to them for saying so. Of those who answered, 78% rated their grasp of AI as merely aware. Nine per cent called themselves fluent. Nobody claimed expertise.

And these are the most supervised boardrooms Malaysia has. If they mark themselves this low, I see no reason to believe less regulated sectors would mark better. They have just never been asked.

Four laws, and every one of them can name you personally

Directors tend to read the deadlines and assume that is the exposure. It is not. Four laws apply to a day like this, and a director can be charged under each of them personally.

Layer one is the Cyber Security Act 2024. Follow the code of practice, assess risk annually, submit to audit, report incidents immediately. Then there is Section 58, which most directors I meet have never heard of: an officer can be charged as though they committed the offence personally. Your defence, if it comes to that, is proving no knowledge or consent, and reasonable precautions taken.

Layer two is the PDPA as amended. Boards tend to assume that appointing the mandatory Data Protection Officer settles the matter. It does not. Section 133 reaches individual decision-makers, and what protects you is a registered officer, a maintained breach register and a notification procedure someone has actually tested rather than filed.

Layer three is your sector regulator's overlay. Bank Negara's RMiT is the sharpest version; the Securities Commission, MCMC and others run their own. These carry legal force against directors and officers, so you want a board-approved policy, a named accountable officer, and minutes showing the board reviewed a current gap assessment.

Layer four is the Companies Act 2016, and no delegation can absorb it. Reasonable care, skill and diligence belongs to each director personally and applies to any foreseeable risk. After two years of Act 854 and a breach headline every other week, foreseeability is no longer arguable. What saves you is the most ordinary thing in governance: minutes showing the question asked, the answer received and the decision taken, made at the time and not after.

Notice what all four defences have in common? Each rests on paperwork created before the event. Where the record is silent, no defence exists, and the night the phone rings is far too late to start writing.

The governance gap is not a technology gap

We have the clearest data from the financial sector, showing that large-scale AI adoption could boost the pre-tax profit of Malaysia's six biggest banks by about US$1.8 billion (RM7.1 billion), over three years. But the catch is that only 26% of the boards surveyed regularly discuss responsible AI, and a mere 4% have metrics in place to track its progress. What sticks out like a thorn is that 43% manage AI risk using controls designed for other risk types. These controls assume systems act predictably, which AI systems often don't.

Now, the worrying part for boardrooms is that 65% of Malaysian financial institutions develop their AI technologies internally. This is quite high compared to 9% in the Asia-Pacific region and 6% globally. If there's a flaw in the existing infrastructure, everything built on it inherits the problem. This isn't just a banking issue. It's like a company trying to integrate a chatbot into a 15-year-old ERP system, which is essentially running an unsupervised experiment.

The rulebook is being written faster than org charts

Things have been changing fast. In March, we got the MY-AI Standards, which made over 80 international AI standards available to everyone. Then in July, the National AI Office finished getting feedback on Malaysia's first AI Governance Bill, which should be finished by the end of the year. This Bill makes a difference between the people who create AI systems and the people who use them in real life. Sometimes, one company can be both. But the idea that AI is only the vendor's problem, which has been a comfortable thought for many people in Malaysian boardrooms, is becoming less true as time goes on.

Cyber went through this already. A company does not need NCII designation to live under the standard, because the standard arrives by contract: the designated customer, the audit clause, the procurement questionnaire. A logistics firm serving a port inherits it the day the ink dries. Obligations travel down supply chains the way liability always has, quietly and in writing.

Actionable next steps for the board

  • Confirm your status: Your NCII designation position and your sector's reporting deadlines, in writing, reviewed once a year.
  • Name the notifier: One name, one deputy, standing authority outside business hours, appointment minuted.
  • Sign the AI inventory: Every model, agent and third-party tool touching customer data, signed by an owner and refreshed quarterly.
  • Rebuild the risk controls: Purpose-built for AI, with model drift, prompt injection and data poisoning on the register and owners named.
  • Buy independent assurance: Penetration tests, tabletop exercises, third-party review. Proof carries weight with regulators, customers and courts. Assertion carries none. (Tabletop exercise is a simulated crisis discussion involving the relevant people — management, IT, legal, comms, operations, sometimes board members — and walking through a realistic cyber incident scenario.)
  • Minute everything: Every question asked, answer received, decision taken. The record you build this quarter is the defence you will lean on later.

What is missing is not tools or budget or another strategy deck. It is ownership, the willingness to put your own name against a risk you do not yet fully understand, then do the work to understand it. The clocks are already installed. The only real question is where you find out how they run: at a drill on a quiet Tuesday afternoon, or at 5:30 on a Sunday morning.


Source:

https://www.digitalnewsasia.com/insights/cybersecurity-power-play-three-clocks-start-once-are-you-ready