Accessibility

Critical Sector Auditing and Risk Analysis Workshop Opened with a High-Level Conference in Malaysia

Organised in cooperation between EU CyberNet and National Cyber Security Agency of Malaysia (NACSA), the workshop on critical sector auditing and risk analysis for Malaysia opened today, 20 May 2026 with a high-level conference.

The conference focused on strengthening awareness and understanding of cybersecurity auditing, compliance and risk management as well as provided international perspectives on cyber resilience, governance and critical infrastructure protection. The conference was declared open by Ir. Dr. Megat Zuhairy Megat Tajuddin, the Chief Executive of National Cyber Security Agency (NACSA) of Malaysia and Dr. Insa Ewert, Deputy Head of Mission of the European Union to Malaysia. In their opening remarks, both stressed the value of collaboration between the European Union and Malaysia in building bi-regional cyber resilience and forging trusted partnership.  

Navigating Cyber Security Audit and Compliance 

The first session by Norhayati binti Ahmad Mansor, the Director of NACSA’s Cyber Security Legal Division, provided participants an overview of the Cyber Security Act 2024 (Act 854), its key provisions, instructional framework and compliance requirements. Building on this, the next session by Ts. Dr. Nurul Aisyah Sim binti Abdullah, the Director of NACSA’s Audit and Compliance Department, explained how cybersecurity audit and compliance under the aforementioned Act helps to strengthen the readiness, security and resilience on NCII sectors, including highlighting the role of sector leads in supporting, coordinating and guiding. Session also covered key audit processes, reporting expectations and actions to support the development of more secure NCII nation. 

Muhammad Dawud Wimon from KMPG Malaysia offered industry insights on navigating cyber security audit and compliance obligations. He highlighted key challenges faced by organisations, preparing for audits, maintaining documentation and the importance of embedding compliance into daily operations.  

The European Perspective and Experience 

The second half of the opening conference focused on sharing practical experiences from the European Union. EU CyberNet’s Deputy Director Cormac Callanan chaired a panel with three EU experts that provided an high-level overview of European approaches and practices to cyber auditing and explained the purpose of audits, the importance of supervision and the need for collaborative engagement in strengthening cybersecurity and promoting continuous improvement across critical sectors. The session also introduced different audit perspectives and types, including government and industry approaches, supply chain audits, the importance of auditor independence and role of certification in demonstrating compliance and resilience.  

Ilmar Toom, Head of Supervision in the Estonian Information System Authority and EU CyberNet expert, explained to participants the importance and possibilities of auditing and risk management based on Estonia’s model, including the Estonian Information Security Standard. 

EU CyberNet expert Nick Small introduced the importance of maturity assessment for successful  auditing of NCII cybersecurity operations of CSIRTs, CERTs and SOCs and followed up by discussion on handling and reporting cyber incidents in critical infrastructure led by EU CyberNet expert and CEO of Cybershield, Christian Schlehuber 

Following the opening conference, the second and third day of the program will transition into a closed technical workshop dedicated exclusively to NACSA officers. 

Links 



Keep reading similar articles
At CyCon 2026: Municipal Resilience in Crisis, Conflict and Systemic Disruption

EU CyberNet hosted an interactive workshop, titled “Securing Cities: Municipal Cyber Resilience in Crisis, Conflict and Systemic Disruption” at CyCon 2026 on 26 May 2026.

Critical Sector Auditing and Risk Analysis Workshop Concluded After Three Days

The critical sector auditing and risk analysis workshop for Malaysia concluded after three days with practical table-top exercise to implement different auditing approaches.

Day 2 of the Critical Sector Auditing and Risk Analysis Workshop

Following the high-level opening conference, the second day of the critical sector auditing and risk analysis workshop for Malaysia focused on understanding different auditing approaches and their uses.

EU CyberNet Crash Course #3: Communication in Cybersecurity

The 3rd EU CyberNet Crash Course, titled “Communication in Cybersecurity” and led by Jussi Toivanen explored the fundamentals and role of communication in cyber-related crises and raising cyber awareness.

Workshop on Critical Sector Auditing and Risk Analysis to Take Place This Week in Malaysia

EU CyberNet in cooperation with the National Cyber Security Agency (NACSA) of Malaysia and the Delegation of the European Union to Malaysia is organising a three-day programme on critical sector auditing and risk analysis from 20 to 22 May in Putrajaya, Malaysia.

EU CyberNet Stakeholder Community Day: Advancing Europe’s Cybersecurity Partnerships

Today, on 13 May 2026, EU CyberNet gathered representatives of EU institutions and its member states’ national cyber authorities and organisations in Brussels for the annual Stakeholder Community Day meeting under the title “Advancing Europe’s Cybersecurity Partnerships: Made in Europe, Delivered Globally”.