Our Cyber Security Act 2024 training helps Malaysian organisations understand their duties as national critical information infrastructure (NCII) entities, meet Bank Negara Malaysia’s Risk Management in Technology (RMiT) policy, and comply with the amended Personal Data Protection Act. SSC delivers practical courses live online or on-site in Kuala Lumpur and across Malaysia.

| Course | Typical duration | Best for |
|---|---|---|
| Cyber Security Act 2024 for NCII entities | 1 day | Leadership, risk and security teams of NCII entities |
| NACSA baseline self-assessment workshop | 1 day | Teams completing the National Cyber Security Baseline assessment |
| BNM RMiT practitioner | 2 days | Technology risk, security and compliance teams in financial institutions |
| PDPA 2024 amendments and breach notification | 1 day | Data protection officers, legal and IT teams |
| Cyber incident response tabletop | 1 day | Crisis, IT, security and communications teams |
The Cyber Security Act 2024 came into force on 26 August 2024. It is administered by the National Cyber Security Agency (NACSA) and places duties on entities designated as national critical information infrastructure across 11 sectors, including government, banking and finance, transportation, defence and national security, information, communication and digital, healthcare, water, sewerage and waste management, energy, agriculture and plantation, trade, industry and economy, and science, technology and innovation. Duties include providing information on NCII, complying with codes of practice, conducting risk assessments and audits, and notifying cyber security incidents.
Typical duration: 1 day. Who it is for: leadership, risk and security teams in designated or likely NCII entities.
You will be able to: explain your organisation’s obligations under the Act and plan how to meet them.

Bank Negara Malaysia’s RMiT policy document applies to licensed banks, insurers, takaful operators, development financial institutions, and specified payment and e-money providers. It covers technology risk governance, technology operations, cyber security, cloud services, multi-factor authentication, third-party risk and resilience. BNM re-issued the document in September 2026, adding a code of practice for financial institutions designated as NCII. Our practitioner course covers the requirements, the self-assessment, and how to evidence compliance to supervisors.

The Personal Data Protection (Amendment) Act 2024 introduced mandatory data breach notification to the Personal Data Protection Commissioner, a requirement to appoint a data protection officer, direct obligations for data processors and a right to data portability. Our PDPA course covers each change and how to run a breach assessment quickly. Our incident response tabletop brings these obligations together in one realistic exercise.
Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.
Related: the GRCLens NACSA baseline and BNM RMiT modules and the Malaysia framework pack. See all training courses.
On 26 August 2024. The Act, also known as Act 854, is administered by the National Cyber Security Agency (NACSA).
Entities designated as national critical information infrastructure (NCII) entities across 11 sectors, through their NCII sector leads. The training helps you understand whether and how you are affected.
Licensed banks, insurers and takaful operators, prescribed development financial institutions, and specified e-money issuers, payment system operators and other payment providers.
The Personal Data Protection (Amendment) Act 2024 introduced mandatory breach notification, data protection officer appointment, direct obligations for data processors and a right to data portability.
Yes. We deliver private on-site courses in Malaysia as well as live online classes.
Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.
Prefer email? Write to info@secsolutionshub.com

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.