
Malaysia’s Cyber Security Act 2024 marks an important milestone in the country’s regulatory architecture, signalling a serious intent to raise the floor on cybersecurity governance.
Yet the recent compromise of multiple government portals through a known, patchable vulnerability exposes a harder truth: legislation, however robust, cannot by itself deliver operational resilience.
The limits of law
This is the central tension in modern cyber governance. A statute can compel reporting, set baseline duties and formalise accountability, but it cannot install patches, enforce disciplined asset management or ensure that legacy systems are retired before they become liabilities.
In that sense, law is necessary but never sufficient. It provides the framework; it does not provide the muscle.
The problem is not unique to Malaysia, but Malaysia’s case is especially revealing because the country has invested significant policy effort in strengthening its cyber posture. When a vulnerability already known to defenders remains unaddressed long enough to be exploited, the issue is no longer merely technical. It becomes managerial, organisational and, ultimately, political.
Compliance is not resilience
Too often, compliance becomes a proxy for security. Organisations file reports, complete audits and tick the required boxes, then assume they are safe. That mindset is dangerous. A system can be compliant on paper and still be highly exposed in practice if patch cycles are slow, vulnerabilities are poorly triaged and accountability is diffuse.
Real resilience depends on habits, not headlines. It requires timely patching, asset visibility, continuous monitoring and a security culture that treats basic cyber hygiene as non-negotiable. It also requires decision-makers to recognise that operational security is not an IT side issue; it is a governance responsibility.
The governance gap
The recent breaches highlight a familiar gap between the policy centre and the operational front line. Governments can draft strong laws, but if agencies lack the resources, discipline or coordination to implement them, the result is a fragile security state dressed in formal assurances. That gap is where attackers operate.
This is why cybersecurity governance must be judged not only by the quality of its statutes, but by the maturity of its execution.
Are critical systems patched promptly? Are vulnerable services exposed unnecessarily? Are there measurable consequences for repeated neglect? These questions matter more than the mere existence of regulatory language.
What must change
Malaysia should now treat these incidents as a serious test of institutional credibility. The issue is no longer simply whether rules exist, but whether they are enforced with the urgency and discipline that modern cyber risk demands.
For critical public systems, mandatory minimum patch timelines should be non-negotiable. A vulnerability that is already known, documented and actively exploitable should never be allowed to linger long enough to become a public failure. In cybersecurity, delay is not caution; it is exposure.
The second priority is to elevate vulnerability management to the same level of scrutiny as financial controls. That means audits should not be treated as box-ticking exercises or procedural theatre. They should ask hard questions: Are assets fully identified? Are vulnerabilities ranked by risk? Are remediation deadlines met consistently? Are exceptions approved, tracked and closed?
If financial controls are expected to prevent leakage and misuse of public funds, cyber controls should be expected to prevent leakage and misuse of public systems. Anything less reflects a dangerous double standard.
Third, agencies must be measured not only by whether they claim compliance, but by whether they can demonstrate a real reduction in exposure over time. The goal is not paperwork; the goal is resilience. That requires evidence of fewer high-risk vulnerabilities, faster remediation cycles, stronger configuration discipline and clearer accountability when known weaknesses are left unresolved.
There is also a broader lesson for public-sector leadership. Cybersecurity cannot be relegated to periodic compliance exercises or rushed into action only after an incident has already damaged trust. It must be embedded into procurement, system design, maintenance and board-level oversight from the start. If a known vulnerability can still bring down government portals, then the problem is not an absence of law.
It is an absence of operational discipline, institutional urgency and leadership that understands cybersecurity as a core function of governance rather than a technical afterthought.
A harder standard
The Cyber Security Act 2024 is significant, but its credibility will ultimately rest on whether it improves outcomes in the real world. Citizens do not experience cybersecurity through statutes; they experience it through whether services remain available, data remains protected and public institutions respond swiftly when threats emerge. That is the uncomfortable but necessary conclusion.
Strong legislation can strengthen accountability, but it cannot compensate for weak operational security. In cybersecurity, resilience is built in the daily grind of patching, monitoring and enforcing standards – long before a breach becomes public knowledge.
Murugason R. Thangaratnam is a cybersecurity practitioner and Adjunct Professor of Practice. The views expressed here are the personal opinion of the writer and do not represent that of Twentytwo13.


