South East Asia

External attack surface management for Malaysian organisations

Malaysia’s rules now use the words attack surface. Bank Negara Malaysia’s RMiT expects financial institutions to measure and manage the external exposure their third parties create, and to run nothing with known vulnerabilities. The Cyber Security Act 2024 adds duties for national critical information infrastructure. EASMLens gives CISOs and boards the continuous, outside-in evidence these rules assume.

Serving organisations in Kuala Lumpur, Putrajaya, Cyberjaya, Penang, Johor Bahru.

What the rules in Malaysia expect

BNM RMiT: third-party attack surfaces

Bank Negara Malaysia’s Risk Management in Technology policy document took effect in revised form on 28 November 2025 and was reissued on 25 September 2026 with a new Appendix 12 for NCII entities in banking and finance. Its "S" paragraphs are binding standards.

Several apply directly to the external estate. S 10.17 says no system may run with known vulnerabilities, outdated platforms or end-of-life technology. S 10.16 requires policies to reduce shadow IT. S 11.3 calls for a complete and accurate view of critical systems and assets, with automated tracking of the asset inventory. S 10.49 asks institutions to build towards continuous monitoring of third-party service providers’ cyber posture, including measuring the infrastructure footprint third parties expose and managing it to mitigate cyber-attack surfaces. Appendix 5 adds quarterly vulnerability assessment of external and internal network components that support critical systems.

Cyber Security Act 2024 (Act 854)

Act 854 came into force on 26 August 2024 for designated national critical information infrastructure (NCII) entities across 11 sectors. NCII entities must implement their sector code of practice, carry out a risk assessment at least once a year and an audit at least every two years, and notify incidents through NACSA’s NC4 system: immediately, with further particulars within 6 hours and supplementary information within 14 days. Failing to notify carries penalties of up to RM500,000, ten years’ imprisonment, or both.

NACSA’s own advisories show the exposure problem. In June 2026 NC4 warned of active attacks on Malaysian web servers through unauthenticated remote code execution flaws in popular Joomla extensions.

Personal Data Protection Act

Since 1 June 2025, the amended PDPA requires data controllers to notify the Commissioner of a personal data breach within 72 hours, and affected individuals within 7 days of that notice where significant harm is likely. The 72-hour figure belongs to the PDPA, not to Act 854.

What each rule asks for, and what EASMLens shows you

RuleWhat it asks forWhat EASMLens shows you
RMiT S 10.49Measure the footprint third parties expose and manage it to mitigate cyber-attack surfacesSupplier and vendor exposure monitored alongside your own estate
RMiT S 10.17No system running with known vulnerabilities or end-of-life technologyExposed services with known CVEs and end-of-life software, flagged continuously
RMiT S 10.16, S 11.3Reduce shadow IT; complete, automated asset inventoryAssets missing from your register, discovered from DNS and certificates
RMiT S 10.20Annual review of cryptographic standards on external-facing applicationsTLS versions, weak ciphers and certificate issues on every public endpoint
Act 854 s 22Annual risk assessment and two-yearly audit for NCIIAn external exposure baseline to feed each assessment

Reporting clocks

  • NCII entities (Act 854)

    Immediately, further particulars within 6 hours, supplementary information within 14 days

  • Data controllers (PDPA)

    72 hours to the Commissioner; 7 days to affected individuals where significant harm is likely

Questions for the board

  1. 1For RMiT S 10.49: how do we measure and monitor the external exposure our critical third parties create, and is that roadmap approved?
  2. 2If we are, or may become, NCII, could we produce a current list of every internet-facing system we own, including systems acquired through projects and vendors?
  3. 3How many of our internet-facing systems run software with known vulnerabilities or past end of life today?

How EASMLens supports these obligations

  • Third-party attack surface monitoring aligned to RMiT S 10.49
  • Continuous discovery of shadow IT and unregistered internet-facing assets
  • Exposure intelligence on known CVEs, end-of-life software and weak TLS
  • Email domain security grading to support RMiT anti-spoofing expectations
Malaysia licenses two cyber security services under the Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024: managed security operation centre monitoring and penetration testing. EASMLens does not provide SOC monitoring or exploit-based testing, but it does run automated vulnerability checks, and regulation 5(c) defines penetration testing broadly enough to include identifying and measuring vulnerabilities. NACSA has not ruled on automated exposure platforms. Malaysian customers should take legal advice before active checks run against assets located in Malaysia, and talk to us about how scope is set.

EASMLens discovers your attack surface from DNS, certificate transparency, internet-wide scan datasets and public records, then runs non-destructive checks against the assets in your scope. It never attempts exploitation. It provides discovery, monitoring and evidence. It does not certify an organisation against any framework, and no product can.

Frequently asked questions

Does RMiT really mention attack surfaces?
Yes. S 10.49 asks financial institutions to measure the footprint their third parties expose and manage those external exposures to mitigate cyber-attack surfaces, as part of a roadmap to continuous third-party monitoring.
Is incident reporting under Act 854 72 hours?
No. NCII incidents must be notified immediately, with further particulars within 6 hours and supplementary information within 14 days. The 72-hour rule is the PDPA breach notification duty.
Is EASMLens a penetration testing or SOC service?
No. EASMLens is a software platform: it discovers your internet-facing estate and runs automated, non-destructive vulnerability checks. It does not exploit systems or monitor inside your network. See the licensing note above for how Malaysian rules may treat automated checks.

More in South East Asia