AIWiki
Malaysia
Back to all articles
Malaysian Contextnacsamalaysiacybersecurity

National Cyber Security Agency (NACSA)

5 min readUpdated May 2026
National Cyber Security Agency (NACSA)
Type
Federal cyber security agency
Established
February 2017
Reports to
Ministry of Digital, Malaysia
Headquarters
Cyberjaya, Selangor
Key remit
National cyber policy, CNII protection

The National Cyber Security Agency, known by its acronym NACSA, is the Malaysian federal agency designated as the national lead body for cyber security matters. Established in February 2017 and originally placed under the National Security Council, NACSA was later realigned under the Ministry of Digital. Its mandate covers the coordination of cyber security policy, the protection of Critical National Information Infrastructure (CNII), cyber crisis management, and the development of national capability. The agency has emerged as the principal Malaysian government actor on the cyber-security implications of artificial intelligence.

Mandate and structure

NACSA is responsible for developing and implementing national-level cyber security policies and strategies, protecting CNII, undertaking strategic measures to counter cyber threats, leading cyber security awareness and capacity-building programmes, formulating the strategic approach to cyber crime, advising agencies on cyber risk management, optimising shared resources across the public sector, and fostering regional and global cyber security partnerships. The agency operates from Cyberjaya and works closely with related bodies including CyberSecurity Malaysia (the operational arm under the same ministry), the Malaysian Communications and Multimedia Commission (MCMC), the Royal Malaysia Police's commercial crime investigation department, and Bank Negara Malaysia for the financial sector. NACSA also represents Malaysia in ASEAN cyber forums and in bilateral cyber dialogues with partners including Singapore, Japan, the United Kingdom, Australia, and the United States.

Cyber Security Act 2024

The Cyber Security Act 2024, which came into force in 2024, gave NACSA statutory powers for the first time. Prior to the Act, NACSA operated under administrative authority. The Act establishes a formal regime for the designation of National Critical Information Infrastructure sectors, mandates incident reporting, empowers NACSA to direct audits and risk assessments, and creates licensing obligations for managed cyber security service providers operating in Malaysia. The Act applies to eleven CNII sectors including banking and finance, transportation, energy, water, health services, government, defence and national security, emergency services, food and agriculture, trade and industry, and information and communications.

Cyber Security Strategy 2025–2030

NACSA is finalising Malaysia's next national Cyber Security Strategy, covering the period 2025 to 2030. The strategy, which succeeds the Malaysia Cyber Security Strategy 2020–2024, explicitly incorporates emerging technologies including artificial intelligence, generative AI, and the cyber-security threats they enable. Public statements from the Ministry of Digital have confirmed that the strategy will address AI-enabled phishing, deepfake fraud, autonomous offensive cyber tools, and the security of AI supply chains used by Malaysian government systems.

AI security committee

In parallel with the strategy refresh, the Ministry of Digital has announced the formation of a national AI security committee under NACSA's coordination. The committee draws members from across the public sector, academia, and industry, with the remit of assessing AI technology against national security and ethical standards. Its work is intended to complement the broader Malaysia AI Governance Framework being developed by MDEC and the Ministry of Digital, and to ensure that AI systems used on CNII meet appropriate assurance levels.

Operational programmes

NACSA runs several recurring national exercises. The X-Maya cyber drill series tests CNII operators against simulated attacks across multiple sectors. The agency also coordinates the Malaysia Cyber Defence Operations Centre (MyCDOC) and contributes to the ASEAN Computer Emergency Response Team network. National cyber security awareness campaigns under the CyberSAFE programme, run by CyberSecurity Malaysia in coordination with NACSA, are extended to schools, universities, and small and medium enterprises across the country. NACSA's expanding remit over AI risk affects Malaysian organisations across every CNII sector. For banks regulated by Bank Negara Malaysia, NACSA guidance now intersects with BNM's Risk Management in Technology (RMiT) policy and the e-KYC Policy Document; banks such as Maybank, CIMB, Public Bank, RHB, and Hong Leong Bank routinely benchmark their AI model risk programmes against NACSA expectations alongside BNM requirements. In the energy and utilities sector, Tenaga Nasional Berhad, Petronas, Air Selangor, and Indah Water rely on NACSA-led threat intelligence sharing for the protection of operational technology environments where AI is increasingly used for predictive maintenance and anomaly detection. Transportation operators including Malaysia Airports, Prasarana, KTM Berhad, and the AirAsia group are also CNII designated entities subject to incident reporting obligations under the Cyber Security Act 2024. For technology service providers based in Cyberjaya, Penang, and Iskandar Malaysia — including AI specialists such as AITG Sdn Bhd, which operates the Teragrid Ai Platform and Teragrid Agent products — NACSA's evolving licensing regime affects how managed AI services are offered to CNII customers. Service providers serving CNII operators are likely to require licences under the Cyber Security Act, and AI components of those services will be assessed under the forthcoming AI security committee framework. For the broader Malaysian public, NACSA is the primary federal authority on AI-enabled scams, deepfake-driven impersonation fraud, and AI-related identity theft, and works with the Royal Malaysia Police, MCMC, and the National Anti-Financial Crime Centre (NFCC) on enforcement.

See Also

References

  1. National Cyber Security Agency Malaysia. (2024). Official Mandate and Functions. nacsa.gov.my.
  2. Parliament of Malaysia. (2024). Cyber Security Act 2024. Federal Gazette.
  3. Ministry of Digital Malaysia. (2025). Malaysia Cyber Security Strategy 2025–2030 Public Consultation.
  4. Bernama. (2025). NACSA Finalising Malaysia's Cybersecurity Strategy 2025–2030. Bernama News.
  5. CyberSecurity Malaysia. (2024). Annual Report on National Cyber Incidents. CSM.