Is the company watching over your systems legally allowed to do so? This is a question every organisation should be asking.
What the Cyber Security Act 2024 Changed
Since the Cyber Security Act 2024 came into force, that question has a hard legal answer. Only two categories of cyber security services are prescribed for licensing in Malaysia: managed security operations centre (SOC) monitoring services and penetration testing services. Anyone providing these services without a NACSA license faces a fine of up to RM500,000, imprisonment of up to 10 years, or both. This is not a formality. It is Parliament drawing a line around who may be trusted to look inside another person’s computer systems.
SIAGA Is Now a Licensed Managed SOC Monitoring Provider
We, SIAGA Informatics Sdn Bhd have acquired the Managed SOC Monitoring Service License (License No: 20345-01) by NACSA. This license legally authorises us to monitor the cyber security of our clients’ systems — acquiring, identifying and scanning information to detect threats, and determining the measures needed to respond to incidents and prevent them from recurring.
From the Courtroom to the Control Room
For SIAGA, this completes a circle. For years, we have been the team called in after the breach — conducting digital forensic investigations, preserving evidence, and standing in court as expert witnesses. We have seen, up close, what a single undetected intrusion costs a business, a government agency, a family. That experience now flows directly into how we monitor: we watch for threats knowing exactly how attacks unfold, how evidence is hidden, and how cases are won or lost. Detection, response, investigation, testimony — one accountable, licensed provider.
Our Honest View: A License Is the Floor, Not the Ceiling
Let us also say something the industry does not say often enough. A license, on its own, does not stop a single attack. What it does is make providers answerable — to NACSA, to the law, and to you. That distinction matters to us, because in our forensic work we have sat across the table from victims of breaches that a competent, accountable monitoring provider would have caught. Some were let down by vendors who overpromised and quietly underdelivered, with no regulator to answer to.
Our concern now is complacency in the other direction: organisations treating the license as a checkbox and stopping their due diligence there. Please don’t. Ask who is actually watching your alerts at 3am. Ask how findings are documented, and whether they would survive scrutiny in court. Licensing has raised the floor for Malaysia’s cyber security industry — it is up to providers like us to keep raising the ceiling. We intend to.
Bigger Than Any One Company
But this is bigger than us. The Act 854 licensing regime is Malaysia’s declaration that the defence of our critical national information infrastructure will not be left to the unregulated and the unaccountable. By subjecting ourselves to NACSA’s scrutiny, SIAGA takes ownership of a small but real piece of the nation’s cyber defence. That is a responsibility we carry with pride.
Ask the Question
So we end where we began: ask your SOC provider for their license number. If they hesitate, you already have your answer.
Ours is 20345-01. Verify it. Then, let’s talk.
SIAGA Informatics Sdn Bhd (A NACSA-licensed Managed SOC Provider) provides court-ready digital forensics, incident response and cybersecurity expertise across Malaysia.







