Content Hub | Corinium Intelligence

Malaysia’s Cybercrime Bill 2026: What Changes for CISOs and Security Leaders?

Written by Eleen Meleng | Aug 18, 2026, 6:49:04 AM

Malaysia’s cyber threat landscape has changed dramatically since the Computer Crimes Act 1997 was introduced. Ransomware, AI-generated fraud, identity theft and digitally manipulated content were not the threats the original legislation was designed to address.

Now, Malaysia is attempting to bring its legal framework into the present.

The Cybercrimes Bill 2026, which seeks to repeal and replace the Computer Crimes Act 1997, was passed by the Dewan Rakyat on 1 July and subsequently by the Dewan Negara on 20 July. The Bill contains 61 clauses covering a much broader range of cybercrime, including unauthorised access, ransomware and malicious attacks, computer-related fraud, identity-related offences, misuse of National Digital Identity credentials, and AI-generated or manipulated content.

For CISOs, however, the more important question is not simply what the new legislation prohibits.

It is whether organisations are prepared for the operational consequences of a cybercrime framework that is catching up with the realities of modern digital risk.

The law is catching up. Has security strategy?

The Government's rationale for replacing the 1997 Act is straightforward. Cybercrime has evolved beyond conventional hacking and data theft to include identity theft, online fraud, ransomware and the misuse of technologies such as AI.

The scale of the problem reinforces that argument. Parliamentary debate cited 66,204 cybercrime cases recorded in Malaysia in 2025, compared with 35,368 in 2024, an increase of 87%. Reported losses also rose from RM1.57 billion to RM2.97 billion.

These numbers raise an uncomfortable question for security leaders: are organisations still designing security programmes around the assumption that cyber incidents are primarily technical events?

Increasingly, they are not.

A ransomware attack can become a business continuity crisis. A compromised identity can become a fraud investigation. An AI-generated deepfake can become a reputational and legal problem. A breach involving sensitive data can quickly involve regulators, law enforcement, customers, suppliers and the board.

The implication is significant. The CISO cannot operate in isolation from legal, risk, compliance, fraud, communications and business continuity teams.

Cybersecurity is becoming an increasingly multidisciplinary response function.

Ransomware is no longer just an IT problem

The Bill explicitly strengthens provisions relating to attacks against computer systems, including ransomware and malicious software. Parliamentary material describes offences affecting the confidentiality, integrity and availability of computer systems and data, alongside unauthorised access, interception and misuse of devices.

This matters because ransomware has fundamentally changed the way organisations need to think about resilience.

The traditional question was:

How do we stop ransomware from getting in?

The more useful question is now:

What happens to the business when it gets in?

That requires security leaders to think beyond endpoint protection and detection. Can critical systems be isolated quickly? Can privileged access be contained? Can evidence be preserved? Can the organisation recover without paying an attacker? Can legal and law enforcement teams obtain the information they need? Can executives make decisions with confidence during the first few hours of an incident?

The new legislation should therefore be viewed as an opportunity to examine whether incident response plans are genuinely operational, rather than simply documented.

AI is where things become more complicated

Perhaps the most interesting development is the Bill's treatment of AI-generated and digitally manipulated content.

The legislation introduces offences relating to computer-generated or manipulated content, including deepfakes, where the required criminal intent and other elements of an offence can be established. The Government has also clarified that AI-generated content is not automatically an offence simply because AI was used; prosecution must establish the relevant criminal intent, purpose and consequences.

That distinction matters.

AI is simultaneously becoming:

  • a tool for attackers
  • a tool for defenders
  • a source of new fraud risks
  • an emerging enterprise technology
  • and now a consideration within Malaysia's cybercrime framework

For CISOs, this creates a governance challenge that cannot be solved simply by blocking AI tools.

Organisations need to understand how AI is being used, what data is entering AI systems, what permissions AI-enabled applications have, and what happens when AI is integrated into business-critical workflows.

The security question is moving from “Is AI safe?” to “What controls do we need around AI-enabled activity?”

That is a much harder question.

Stronger enforcement also means stronger governance

The Bill gives investigators mechanisms relating to the preservation and disclosure of computer data, but the Government has stressed that these powers are subject to prescribed legal procedures and safeguards. For example, a notice to preserve computer data requires an investigator to be satisfied that the data is reasonably required for an investigation and at risk of being deleted, altered or destroyed.

For organisations, this highlights an area that often receives less attention than prevention: evidence readiness.

When a serious cyber incident occurs, can your organisation quickly identify:

  • what happened
  • when it happened
  • which systems were affected
  • what data was involved
  • who had access
  • what actions were taken
  • and what evidence needs to be preserved?

Security teams should not have to figure this out in the middle of a crisis.

This is where CISOs need stronger relationships with legal, compliance, internal audit and risk teams. Incident response is no longer purely a SOC or security operations exercise. It is increasingly a governance exercise.

Regulation should not become another compliance checkbox

There is also a legitimate tension here.

The Government has emphasised that the Bill does not grant authorities unlimited powers and that access to computer systems and data must follow legal procedures. During parliamentary debate, MPs nevertheless raised concerns around privacy, safeguards and the extent of investigative powers.

That tension is important for security leaders.

A stronger cybercrime framework is necessary. But stronger enforcement must exist alongside clear accountability, appropriate controls and respect for privacy.

For CISOs, this reinforces a broader principle: security maturity is not simply about having more controls. It is about being able to demonstrate why those controls exist, who can exercise them, and how their use is governed.

The CISO's role is changing again

The Cybercrimes Bill 2026 is ultimately a legislative response to a changing threat environment. But its impact will be felt inside organisations.

CISOs will need to work more closely with legal and risk teams. Incident response programmes will need to consider evidence preservation and regulatory obligations alongside technical containment. AI adoption will require clearer governance. Identity and access controls will become increasingly important as fraud and digital identity risks converge.

Most importantly, security leaders will need to move beyond asking whether their organisation is compliant.

They need to ask whether it is prepared.

Prepared to detect an attack.
Prepared to preserve evidence.
Prepared to contain disruption.
Prepared to recover.
Prepared to explain what happened to the board, regulators, customers and potentially law enforcement.

Malaysia has taken a significant step towards modernising its cybercrime framework. The harder work now sits with organisations themselves.

The law is changing. The threat landscape has already changed. The question is whether security strategies have changed quickly enough.


 

Join us at CISO Malaysia 2027 to learn more about the latest challenges and developments for infosec executives in the country. Reach out to Eleen Meleng to learn more.