South East Asia
External attack surface management for Malaysian organisations
Malaysia’s rules now use the words attack surface. Bank Negara Malaysia’s RMiT expects financial institutions to measure and manage the external exposure their third parties create, and to run nothing with known vulnerabilities. The Cyber Security Act 2024 adds duties for national critical information infrastructure. EASMLens gives CISOs and boards the continuous, outside-in evidence these rules assume.
Serving organisations in Kuala Lumpur, Putrajaya, Cyberjaya, Penang, Johor Bahru.
What the rules in Malaysia expect
BNM RMiT: third-party attack surfaces
Bank Negara Malaysia’s Risk Management in Technology policy document took effect in revised form on 28 November 2025 and was reissued on 25 September 2026 with a new Appendix 12 for NCII entities in banking and finance. Its "S" paragraphs are binding standards.
Several apply directly to the external estate. S 10.17 says no system may run with known vulnerabilities, outdated platforms or end-of-life technology. S 10.16 requires policies to reduce shadow IT. S 11.3 calls for a complete and accurate view of critical systems and assets, with automated tracking of the asset inventory. S 10.49 asks institutions to build towards continuous monitoring of third-party service providers’ cyber posture, including measuring the infrastructure footprint third parties expose and managing it to mitigate cyber-attack surfaces. Appendix 5 adds quarterly vulnerability assessment of external and internal network components that support critical systems.
Cyber Security Act 2024 (Act 854)
Act 854 came into force on 26 August 2024 for designated national critical information infrastructure (NCII) entities across 11 sectors. NCII entities must implement their sector code of practice, carry out a risk assessment at least once a year and an audit at least every two years, and notify incidents through NACSA’s NC4 system: immediately, with further particulars within 6 hours and supplementary information within 14 days. Failing to notify carries penalties of up to RM500,000, ten years’ imprisonment, or both.
NACSA’s own advisories show the exposure problem. In June 2026 NC4 warned of active attacks on Malaysian web servers through unauthenticated remote code execution flaws in popular Joomla extensions.
Personal Data Protection Act
Since 1 June 2025, the amended PDPA requires data controllers to notify the Commissioner of a personal data breach within 72 hours, and affected individuals within 7 days of that notice where significant harm is likely. The 72-hour figure belongs to the PDPA, not to Act 854.
What each rule asks for, and what EASMLens shows you
| Rule | What it asks for | What EASMLens shows you |
|---|---|---|
| RMiT S 10.49 | Measure the footprint third parties expose and manage it to mitigate cyber-attack surfaces | Supplier and vendor exposure monitored alongside your own estate |
| RMiT S 10.17 | No system running with known vulnerabilities or end-of-life technology | Exposed services with known CVEs and end-of-life software, flagged continuously |
| RMiT S 10.16, S 11.3 | Reduce shadow IT; complete, automated asset inventory | Assets missing from your register, discovered from DNS and certificates |
| RMiT S 10.20 | Annual review of cryptographic standards on external-facing applications | TLS versions, weak ciphers and certificate issues on every public endpoint |
| Act 854 s 22 | Annual risk assessment and two-yearly audit for NCII | An external exposure baseline to feed each assessment |
Reporting clocks
NCII entities (Act 854)
Immediately, further particulars within 6 hours, supplementary information within 14 days
Data controllers (PDPA)
72 hours to the Commissioner; 7 days to affected individuals where significant harm is likely
Questions for the board
- 1For RMiT S 10.49: how do we measure and monitor the external exposure our critical third parties create, and is that roadmap approved?
- 2If we are, or may become, NCII, could we produce a current list of every internet-facing system we own, including systems acquired through projects and vendors?
- 3How many of our internet-facing systems run software with known vulnerabilities or past end of life today?
How EASMLens supports these obligations
- Third-party attack surface monitoring aligned to RMiT S 10.49
- Continuous discovery of shadow IT and unregistered internet-facing assets
- Exposure intelligence on known CVEs, end-of-life software and weak TLS
- Email domain security grading to support RMiT anti-spoofing expectations
EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.
Frequently asked questions
- Does RMiT really mention attack surfaces?
- Yes. S 10.49 asks financial institutions to measure the footprint their third parties expose and manage those external exposures to mitigate cyber-attack surfaces, as part of a roadmap to continuous third-party monitoring.
- Is incident reporting under Act 854 72 hours?
- No. NCII incidents must be notified immediately, with further particulars within 6 hours and supplementary information within 14 days. The 72-hour rule is the PDPA breach notification duty.
- Is EASMLens a penetration testing or SOC service?
- No. EASMLens is a software platform: it discovers your internet-facing estate and runs automated, non-destructive vulnerability checks. It does not exploit systems or monitor inside your network. See the licensing note above for how Malaysian rules may treat automated checks.
Related guides
Primary sources
- BNM Risk Management in Technology (RMiT)
- NACSA legislation page
- NACSA NC4 alerts
- PDPA data breach notification guideline
Regulatory content reviewed on . General information only, not legal advice.