For years, cybersecurity in Malaysia was treated as good practice. Something companies should do, budget permitting. That changed on 26 August 2024, when the Cyber Security Act 2024 came into force, giving the National Cyber Security Agency (NACSA) real regulatory teeth over how organisations protect the systems the country depends on.

This is not a minor policy update. It marks the point where digital trust stopped being a competitive advantage and became a legal obligation, at least for the organisations the law now governs. And it explains why ISACA certifications, once seen mainly as career credentials, are increasingly relevant to the audit, risk, governance and cybersecurity capabilities organisations need to support regulatory compliance.

| What Actually Changed Under the Cyber Security Act 2024

The Act introduces the concept of National Critical Information Infrastructure, or NCII, covering 11 sectors that include government, banking, healthcare, energy, and transportation. Organisations designated as NCII entities now carry specific legal duties, not just recommendations.

A few things worth knowing if you work in or around these sectors:

01

NCII entities must conduct a cybersecurity risk assessment at least once a year and undergo a formal audit at least once every two years, with documentation the Chief Executive of NACSA can request at any time.

Source

02

The Act has extra-territorial reach, meaning it can apply to offences involving Malaysian NCII even when the offender is based outside the country.

Source

03

Certain cybersecurity service providers, specifically those providing managed security operation centre monitoring and penetration testing services covered by the regulations, must obtain a licence from NACSA.

Source

In short, audit trails, documented risk assessments, and named accountable personnel are no longer optional paperwork. They are now the baseline for staying on the right side of the law.

| The Skills Gap Sitting Behind This New Law

Malaysia is not short on ambition when it comes to going digital. It is short on people who can actually secure that digital growth.

CyberSecurity Malaysia’s latest incident data shows why this matters. The Cyber999 Incident Response Centre recorded 1,881 cybersecurity incidents in Q4 2025. While this represented a 7 percent decrease from the previous quarter, data breach incidents increased by 20 percent, from 142 to 171 cases. Fraud remained the most reported category, accounting for approximately 78 percent of all incidents.

The pressure is also changing what organisations need from cybersecurity professionals. As regulatory requirements become more structured and technologies such as AI introduce new risks, organisations need capabilities that extend beyond technical defence into areas such as risk assessment, governance, audit and assurance.

Put simply, the law now demands documented, auditable cybersecurity practices, at the exact moment the talent pool qualified to deliver them is stretched thin.

| Why Employers Are Nervous Even While They’re Growing

Here is the part that tends to surprise people outside HR and hiring circles. Malaysian businesses are actually optimistic about growth, but confidence in workforce readiness tells a different story.

Randstad’s Workmonitor 2026 found that 95 percent of Malaysian employers are confident about business growth this year, compared with only 68 percent of talent. Randstad points to acute talent scarcity, particularly in highly technical and specialised roles emerging from digital transformation.

That concern is also visible at the leadership level. PwC’s 29th Global CEO Survey found that 35 percent of CEOs in Malaysia report high exposure to persistent skills shortages, making talent availability one of the country’s leading business concerns in 2026. Cyber risk and technological disruption follow closely, both at 33 percent.

Employer outlook

That confidence gap shows up in boardrooms too. Persistent skills shortages remain one of the biggest risks CEOs in Malaysia are flagging for the year ahead, a concern echoed across recent regional workforce surveys.

Why the gap is widening

A few reasons this gap keeps widening:

Digital investment and transformation are increasing demand for specialised technology capabilities.

AI is changing the capabilities organisations need across cybersecurity, risk, governance and assurance.

Regulatory obligations under the Cyber Security Act 2024 increase the need for organisations to establish clear cybersecurity responsibilities, documented risk management processes and evidence that required controls and assessments are being carried out.

| Where ISACA Certifications Fit into This Picture

This is where ISACA’s certification pathway becomes particularly relevant. Rather than a single generic qualification, it offers role-specific credentials across audit, cybersecurity, governance, risk, privacy and AI, helping professionals build capabilities that are increasingly important in Malaysia’s evolving digital trust and regulatory environment.

A quick breakdown of where each credential tends to fit:

CISA

CISA (Certified Information Systems Auditor) for professionals working in information systems audit, assurance and control, capabilities increasingly relevant as NCII entities face formal cybersecurity audit requirements.

CISM

CISM (Certified Information Security Manager) for those managing and governing an organisation’s overall information security programme.

CRISC

CRISC (Certified in Risk and Information Systems Control) for professionals responsible for identifying, assessing and managing technology and enterprise risk.

CGEIT

CGEIT (Certified in the Governance of Enterprise IT) for leaders responsible for enterprise IT governance and accountability structures.

CDPSE

CDPSE (Certified Data Privacy Solutions Engineer) for technical roles building privacy into systems by design.

CCOA

CCOA (Certified Cybersecurity Operations Analyst) for hands on operational defenders working incident response and threat detection.

AI

AAIA, AAISM, and AAIR, ISACA’s newer advanced credentials in AI audit, AI security management, and AI risk, built specifically for the growing overlap between artificial intelligence and enterprise risk.

ISACA’s global track record backs this up. The organisation reports more than 300,000 certifications awarded to holders in 186 countries, with renewal rates above 90 percent, reflecting sustained value rather than a one time credential grab.

| What This Means for Your Career, Not Just Your Compliance Checklist

Career value

Recognised certifications can provide career value by helping professionals demonstrate validated expertise across information systems audit, security management, governance and risk.

Regulatory value

More importantly, recognised certifications can help professionals demonstrate expertise in areas such as risk, governance, audit and security management. These capabilities are increasingly relevant as organisations strengthen their cybersecurity practices and respond to regulatory requirements.

Malaysia’s digital economy is not slowing down. Digital investment keeps climbing, AI adoption keeps accelerating, and the legal bar for protecting all of it keeps rising.

For professionals who want to be the ones organisations turn to when the audit request lands or the NCII designation letter arrives, ISACA certification is becoming an increasingly relevant way for professionals to demonstrate specialised capabilities in audit, governance, risk and cybersecurity.

If you are weighing which certification path fits your role, mapping your current responsibilities against the list above is a practical place to start. The law has already decided that digital trust needs to be demonstrated. The only question left is whether you can prove it.

| Start Building Your Digital Trust Credentials Today

Knowing which certification you need is one thing. Getting role ready before your organisation’s next audit or NCII review is another. Trainocate Malaysia’s ISACA certification pathway supports professionals across audit, governance, risk, privacy, cybersecurity and AI, from globally recognised credentials such as CISA, CISM and CRISC to newer AI-focused certifications including AAIA, AAISM and AAIR.

Explore the full ISACA learning journey and find the certification that matches where you sit in Malaysia’s new digital trust landscape.