Malaysia - Cyber Security Strategy (2020-2024)
Malaysia Cyber Security Strategy 2020–2024 (MCSS)
Malaysia
RAI-MY-NA-MCSS2XX-2020The Malaysia Cyber Security Strategy (MCSS) 2020–2024 is a national, medium-term strategic framework launched on 12 October 2020 to strengthen Malaysia’s cyber resilience across government, critical infrastructure and society, structured around five pillars and 12 implementation strategies. (cydes.my)
Summary
The Malaysia Cyber Security Strategy (MCSS) 2020–2024 was published as a government-led, whole-of-nation framework to address escalating cyber threats and to strengthen national-level governance, incident response, legislative frameworks, capacity building, R&D and international cooperation. The MCSS articulates a vision of a secure, trusted and resilient cyberspace that supports economic prosperity and citizen well-being and is organized into five pillars covering: effective governance and management; strengthening legislative frameworks and enforcement; catalysing world-class innovation, technology and industry; developing capacity, capability, awareness and education; and strengthening global collaboration. The strategy contains 12 implementation strategies, 35 action plans and over 100 programmes across government, private sector and civil society stakeholders and includes a government allocation announced at launch to resource priority activity. The MCSS identifies Critical National Information Infrastructure (CNII) sectors, promotes public-private partnerships for risk reduction and response, and sets out priorities for incident management, active cyber defence, national-level coordination (including NC4 structures), workforce development, a national R&D programme and steps towards a licensing and regulatory ecosystem for cybersecurity services. While MCSS itself is a non-binding strategic instrument (a roadmap), it explicitly directs responsible agencies (including the National Cyber Security Agency (NACSA) under the National Security Council and related ministries and agencies) to develop implementing regulations, operational plans, monitoring mechanisms and to coordinate with subsequent legal instruments (including later cybersecurity legislation and regulations). The strategy has served as the blueprint for policy, programme and institutional activity between 2020 and 2024 and informed subsequent regulatory developments in Malaysia's cyber policy landscape. ([nacsa.gov.my](https://www.nacsa.gov.my/index.php/doc/National%20Cyber%20Security%20Baseline%20V.1.0.pdf?utm_source=openai))
Full article
Read full text ↗Overview
The Malaysia Cyber Security Strategy 2020–2024 (MCSS) was launched by the Government of Malaysia on 12 October 2020 as a medium-term national roadmap to improve the country’s cyber resilience across government, industry and society. The MCSS sets a national vision and mission and is organised around five pillars and 12 implementation strategies that collectively cover governance, legislation and enforcement, innovation and R&D, capacity development and international cooperation. The strategy is hosted and published by national security institutions and made publicly available (see the official MCSS document). MCSS (full text) and national agency pages summarise the structure and resource commitments. The strategy promotes a "Whole Nation Approach" that integrates public-private partnership (PPP), incident management (including NC4/CSIRT structures), and targeted programmes for talent development and national R&D. ([cydes.my](https://cydes.my/press/cydes-2021-embedding-resilience-in-our-cyber-space?utm_source=openai))
Definitions
For the purposes of MCSS, key terms are defined to align operational and policy activities across agencies: "Cyber resilience" denotes the ability to anticipate, withstand and recover from cyber incidents; "CNII" (Critical National Information Infrastructure) describes infrastructure and services identified by government as essential to national security and continuity; "Active cyber defence" refers to authorised defensive measures and proactive detection and containment; "Whole Nation Approach" means coordinated government, private sector and civil society engagement; and "incident notification" and "risk assessment" are used in MCSS as procedural building blocks for preparedness and response. MCSS also references common international definitions for terms such as cybercrime, CSIRT/CERT functions and threat actor typologies to ensure interoperability with partners.
Governance and Institutional Framework
The MCSS designates roles and coordinating responsibilities across the National Cyber Security Agency (NACSA), the National Security Council / Majlis Keselamatan Negara (MKN), sectoral ministries, CyberSecurity Malaysia, Communications and Multimedia Commission (MCMC) and law enforcement (PDRM). Implementation calls for NACSA to lead national coordination, policy implementation and monitoring while sectoral agencies remain responsible for CNII protection within their domains. The strategy establishes mechanisms for cross-sector information sharing, incident escalation (through NC4 or equivalent national coordination nodes), and a governance architecture that requires the alignment of agency-level risk management frameworks with national policy objectives. Implementation guidance in the document directs agencies to adopt standards-based security management (e.g., information security management systems), conduct regular risk assessments and to participate in national exercises. The document also envisions an inter-agency steering committee and periodic reporting to government leadership to maintain political oversight and budgetary alignment. NACSA and MKN pages provide institutional background and the MCSS document sets out responsibilities for each named actor. ([nacsa.gov.my](https://www.nacsa.gov.my/index.php/doc/National%20Cyber%20Security%20Baseline%20V.1.0.pdf?utm_source=openai))
Key Focus Areas
MCSS concentrates activity across (1) governance & risk management (strengthening national coordination, defining CNII sectors, and improving agency risk governance); (2) legislative reform and enforcement (updating laws and strengthening cybercrime enforcement capabilities); (3) innovation, R&D and local industry development (establishing national R&D programmes, promoting local solutions and a competitive industry ecosystem); (4) capacity building, talent development, awareness and education (national awareness masterplans, cyber curricula and workforce training pipelines); and (5) international cooperation and norms (active engagement with ASEAN, APCERT, APEC and bilateral partners). Within these focus areas MCSS lists 12 implementation strategies and over 30 action plans addressing incident response maturity, national crisis management, information sharing platforms, certification pathways, national testing capabilities and targeted initiatives for priority sectors such as finance, energy, health and transport. The strategy emphasises measurable outputs (programmes, training targets, R&D milestones) and prioritises public-private partnerships to scale national capabilities. ([cydes.my](https://cydes.my/press/cydes-2021-embedding-resilience-in-our-cyber-space?utm_source=openai))
Implementation Framework
MCSS sets out an implementation framework that pairs strategic objectives with actions, responsible agencies and indicative resources. The strategy recommends phased implementation, starting with governance reforms, CNII identification and strengthening incident management (NC4/CSIRT), then expanding to legislative changes, licensing frameworks for cybersecurity services and scaling R&D and workforce programmes. The document envisages an operational plan with monitoring indicators and annual reviews to re-prioritise programs. It also calls for resource allocations from central budgets and delineates roles for national agencies, including NACSA (coordination), CyberSecurity Malaysia (technical capability and industry outreach) and MCMC (telecoms/communications sector regulation). The approach balances policy-level actions with operational tools such as national awareness campaigns, accredited training, certification schemes and coordinated exercises.
Monitoring and Evaluation
MCSS requires an outcomes-focused monitoring and evaluation (M&E) regime: periodic progress reports, key performance indicators (KPIs) mapped to each implementation strategy, and governance oversight via inter-agency steering committees. The strategy recommends annual reviews, mid-term assessments and an end-of-term evaluation at 2024 to measure delivery against targets such as workforce numbers, incident response times, CNII protection baselines and industry uptake of local technologies. MCSS stresses use of validated metrics, third-party evaluations and public transparency on headline delivery while preserving operational secrecy for sensitive national security activities. Technical audits, compliance checks and sectoral maturity assessments are named as tools for M&E.
Penalties, Liability, and Appeals
As a strategic roadmap, MCSS does not itself create statutory penalties or litigation remedies; instead it directs reforms to the legislative and enforcement architecture to provide legal powers, sanctions and a regulatory baseline. MCSS explicitly states that implementation of some elements will require new or revised legislation, regulations and licensing regimes that will carry enforcement measures (for example, subsequent cyber legislation and sectoral rules). Where the strategy requires mandatory compliance (e.g., for CNII operators), MCSS anticipates implementing instruments that will set out offences, penalties, audit requirements and appeals processes through formal regulation. For enforcement detail, the strategy points to agencies to draft enabling regulations and to align any sanctions with due process and judicial review. ([nacsa.gov.my](https://www.nacsa.gov.my/index.php/doc/National%20Cyber%20Security%20Baseline%20V.1.0.pdf?utm_source=openai))
Relationship to Other Instruments
MCSS was designed to build on and replace prior national-level policy statements (including earlier National Cyber Security Policy documents) by providing a wider whole-of-nation framework for 2020–2024. It intentionally links to existing instruments such as the Personal Data Protection Act (PDPA) for privacy matters, sectoral regulatory regimes (finance, telecommunications, energy, health) for CNII protections, and law enforcement frameworks for cybercrime. The strategy also serves as the policy precursor to later legislation and regulatory instruments (including cybersecurity acts and licensing rules) that operationalise elements of MCSS. MCSS recommends harmonisation across sectoral regulators and the development of secondary legislation to convert strategy objectives into enforceable obligations.
International Alignment
MCSS recognises that cyber threats are transnational and that Malaysia must align with international norms, standards and cooperative frameworks. The strategy references engagement with ASEAN, APCERT/APT networks, APEC and bilateral partners to share threat intelligence, conduct joint exercises and strengthen cyber diplomacy. MCSS endorses use of internationally-recognised standards (ISO/IEC, NIST frameworks) for risk management and encourages Malaysia to participate in norm-development and capacity building activities in multilateral fora. The document frames cross-border cooperation as central to incident response, law enforcement cooperation and supply-chain security.
Implementation Timeline
| Phase | Indicative Dates | Key Actions |
|---|---|---|
| Launch & Immediate (Governance) | Q4 2020–Q2 2021 | Establish NACSA coordination, identify CNII, commence NC4 upgrades, allocate initial funding. |
| Medium-term (Laws & Capacity) | 2021–2022 | Draft enabling regulations, scale workforce programmes, begin national R&D programme and industry engagement. |
| Consolidation | 2022–2024 | Implement licensing & regulatory instruments, maturity assessments, public-private exercises and international agreements. |
Sources and References
| Source | Type |
|---|---|
| Malaysia Cyber Security Strategy 2020-2024 (full text, MKN asset) | Primary Source |
| National Cyber Security Agency (NACSA) – MCSS page | Primary Source |
| Press coverage: RM1.8 billion allocation (news) | Secondary Source |
Requirements for a company
What an organisation has to do under Malaysia - Cyber Security Strategy (2020-2024), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
13- Lead national coordination, policy implementation, and monitoring.National Cyber Security Agency (NACSA).
- Protect Critical National Information Infrastructure within your domain.Sectoral agencies.
- Align agency-level risk management frameworks with national policy objectives.Government agencies.
- Adopt standards-based security management systems.Government agencies.
- Conduct regular risk assessments.Government agencies.
- Participate in national cybersecurity exercises.Government agencies.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Malaysia - Cyber Security Strategy (2020-2024), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | National Cyber Security Agency (NACSA). | Lead national coordination, policy implementation, and monitoring. “Implementation calls for NACSA to lead national coordination, policy implementation and monitoring...” | — | — | Important |
| 2 | Sectoral agencies. | Protect Critical National Information Infrastructure within your domain. “...sectoral agencies remain responsible for CNII protection within their domains.” | — | — | Important |
| 3 | Government agencies. | Align agency-level risk management frameworks with national policy objectives. “...a governance architecture that requires the alignment of agency-level risk management frameworks with national policy objectives.” | — | — | Important |
| 4 | Government agencies. | Adopt standards-based security management systems. “Implementation guidance in the document directs agencies to adopt standards-based security management (e.g., information security management systems)...” | — | — | Important |
| 5 | Government agencies. | Conduct regular risk assessments. “...conduct regular risk assessments...” | — | — | Important |
| 6 | Government agencies. | Participate in national cybersecurity exercises. “...and to participate in national exercises.” | — | — | Important |
| 7 | NACSA and Sector CSIRTs. | Implement incident reporting and NC4 coordination. “Implement incident reporting & NC4 coordination” | — | — | Important |
| 8 | Agencies involved in MCSS implementation. | Submit periodic progress reports. “MCSS requires an outcomes-focused monitoring and evaluation (M&E) regime: periodic progress reports...” | — | — | Important |
| 9 | Agencies involved in MCSS implementation. | Track key performance indicators mapped to implementation strategies. “...key performance indicators (KPIs) mapped to each implementation strategy...” | — | — | Important |
| 10 | Agencies involved in MCSS implementation. | Participate in inter-agency steering committees for governance oversight. “...governance oversight via inter-agency steering committees.” | — | — | Important |
| 11 | Government agencies and Critical National Information Infrastructure operators. | Adopt the national risk management framework. “Adopt national risk management framework” | — | — | Important |
| 12 | Employers and education institutions. | Participate in national workforce and awareness programmes. “Participate in workforce & awareness programmes” | — | — | Important |
| 13 | Industry, research institutes, and MIMOS. | Engage in national R&D and local industry support initiatives. “Engage in national R&D & local industry support” | — | — | Important |
Related Regulations
© Regulations.AI · updated on 13-Jun-2026