SC Malaysia Guidelines on Technology Risk Management
Key Clauses, Market Events and Vendor Obligations
Quick Summary: Under the Securities Commission Malaysia's Guidelines on Technology Risk Management (GTRM), capital market entities must report technology incidents, cyber incidents and near miss events through the Vault system on the day of detection. Market events since 2025 show that meeting this duty depends on vendor notification terms, pre-deployment testing under paragraphs 7.13A and 9.23A, and documented approvals that an appointed reviewer can inspect.
Malaysia's capital market has spent two years testing its technology risk rulebook against real events. The Securities Commission's Guidelines on Technology Risk Management took effect in August 2024, and the incidents since have shown where the provisions bind in practice. Reading the clauses against what happened is more instructive than reading them on their own.
Key Clauses at a Glance
Paragraph 10.03 (Incident and near miss notification): Vault reporting on the day an incident or near miss event is detected.
Paragraphs 8.06 and 8.13(g) (Third-party oversight): outsourcing does not transfer compliance responsibility, and service level agreements must require immediate notification by the provider.
Paragraphs 7.13A and 9.23A (Pre-deployment testing): a cyber security assessment before a system is deployed, and penetration testing before any new critical system or major change to one.
Paragraphs 6.03, 6.06 and 5.10 (Evidence and review): senior management approval for deviations, a board-approved technology risk register, and an SC-appointed independent reviewer at the entity's cost.
Same-Day Incident Reporting: How April 2025 Tested Paragraph 10.03
On the afternoon of 24 April 2025, several brokers identified failed client logins along with unauthorised access and trading executed through a limited number of clients' online trading accounts, and reported it to the SC and Bursa Malaysia that day. Paragraph 10.03 requires exactly that timing, obliging a capital market entity to notify the SC through the Vault system on the day it detects a cyber incident or a technology incident affecting business operations or clients. The regulators' joint response the next morning directed all brokers to have clients reset credentials and to implement multi-factor authentication and stricter password policies. Same-day reporting worked here because the compromise was unmistakable.
Near Miss Reporting: Applying Paragraph 10.03 Without a Volume Threshold
Paragraph 10.03 also covers near miss events, which the guidelines define as events with high potential to become a technology or cyber incident that were detected and mitigated before any substantial impact occurred. Bursa Malaysia said in March 2026 that several brokers had encountered cyber security incidents within their system components, had contained them by isolating the affected component and activating internal incident response controls, and that there was no evidence of unauthorised trading activity or financial loss. That is the near miss category with a recognisable shape. The SC's FAQ adds intrusion attempts and unauthorised access attempts as further examples, sets no volume threshold, and tells entities to submit on detection and update the Vault record as investigation proceeds. An entity that waits for a clean account of what happened will miss the deadline while producing a better report.
Vendor Risk Management: Immediate Notification Under Paragraph 8.13(g)
Paragraph 8.06 states that outsourcing the operation or maintenance of IT systems does not relieve a capital market entity of responsibility for compliance. Paragraph 8.13(g) is what makes the reporting duty workable, requiring the service level agreement to include a clearly defined arrangement for immediate notification by the provider in the event of a technology or cyber incident. The industry response has converged on the same surface. The recommendation paper issued by Bursa Malaysia and the stockbroking industry in November 2025 set expectations for brokers' oversight of the independent software vendors running their order management systems, and in March 2026 the exchange directed all brokers and selected vendors to review their systems. An entity cannot file on the day if its provider escalates the following week, and that outcome is decided by contract language signed long beforehand.
Remediation Deadlines and the Pre-Deployment Testing Squeeze
Bursa Malaysia has targeted full compliance with the system and infrastructure pillars of the recommendation paper by 31 December 2026, with its enhanced IT Security Standards for brokers due in the fourth quarter of 2026. Those upgrades carry their own obligations under the guidelines. Paragraph 7.13A requires a cyber security assessment commensurate with the entity's risk exposure before a system is deployed, and paragraph 9.23A requires penetration testing before deploying any new critical system or making any major change to one. A remediation programme running to a hard year-end date therefore generates fresh pre-deployment testing at exactly the point when the schedule has least room for a failed test.
What an Appointed Reviewer Asks For
Paragraph 5.10 allows the SC to appoint an independent party to review an entity's compliance, including a technology audit, with the cost borne by the entity. Four records carry the weight in that review.
The board-approved key technology risk register required by paragraph 6.06.
Senior management approvals for any deviation from the framework, policies or procedures under paragraph 6.03.
Pre-deployment assessment and penetration testing results under paragraphs 7.13A and 9.23A.
Vault submission timestamps set against internal detection logs.
The trail either shows decisions taken on the days the guidelines specify or it does not. Two years of market events have made clear which of those days matter.
Key Takeaways for Boards and Compliance Officers
Treat detection as the trigger: Vault reporting runs from detection rather than conclusion, so file first and update the record as the investigation develops.
Read vendor notification clauses against your own deadline: paragraph 8.13(g) requires an arrangement for immediate notification, and agreements drafted before August 2024 were never written to meet it.
Book pre-deployment testing early: work due by 31 December 2026 pulls paragraph 7.13A and 9.23A obligations into the same window.
Keep deviation approvals current: paragraph 6.03 requires senior management approval supported by a justification and either an alternative solution or a timeframe to comply.
Sources & Regulatory References
Guidelines on Technology Risk Management, SC-GL/2-2023 (R1-2024), Securities Commission Malaysia — https://www.sc.com.my/api/documentms/download.ashx?id=2f253636-07dd-4355-b89e-010b2ef581c1
Frequently Asked Questions, Guidelines on Technology Risk Management, Securities Commission Malaysia, revised 19 August 2024 — https://www.sc.com.my/api/documentms/download.ashx?id=c8bc454c-0ebf-4697-8284-ece579f93cb2
Joint Media Statement SC and Bursa Malaysia, 25 April 2025 — https://www.sc.com.my/resources/media/media-release/joint-media-statement-sc-and-bursa-malaysia
Bursa Malaysia, stockbroking industry issue cyber resilience enhancement recommendation paper, New Straits Times, 11 November 2025 — https://api.nst.com.my/business/corporate/2025/11/1313023/bursa-malaysia-stockbroking-industry-issue-cyber-resilience
Bursa Malaysia: Broker-level cybersecurity incidents contained, market integrity intact, The Edge Malaysia, 12 March 2026 — https://theedgemalaysia.com/node/795944
Summary of Amendments, Revised Guidelines on Technology Risk Management, Securities Commission Malaysia, 19 August 2024 — https://www.sc.com.my/api/documentms/download.ashx?id=86cafbc3-a04c-4e19-94fd-13bd1dbfd117
Regulatory Disclaimer
This article is provided for general information and does not constitute legal, regulatory or compliance advice. References to the Guidelines on Technology Risk Management reflect the version published by the Securities Commission Malaysia at the time of writing, and references to market events are drawn from published regulator and exchange statements. Capital market entities should verify current requirements against the primary documents and obtain professional advice on their own circumstances.
Questions on the technology risk guidelines
Five points capital market entities raise most often about reporting duties, outsourcing and pre-deployment testing under SC-GL/2-2023 (R1-2024).
-
The Guidelines on Technology Risk Management, SC-GL/2-2023 (R1-2024), are the Securities Commission Malaysia's regulatory framework for managing technology and cyber risk in capital market entities. They superseded the 2016 Guidelines on Management of Cyber Risk when the revised version took effect on 19 August 2024.
-
Paragraph 10.03 requires notification through the Vault system on the day the incident occurs, upon detection of any cyber incident, near miss event, or technology incident affecting business operations or clients. The SC's FAQ confirms that cyber incidents are reportable regardless of severity and that reports may be updated in Vault as the investigation progresses.
-
A near miss event is an event with high potential to become a technology or cyber incident that was detected and mitigated before any substantial impact occurred. The SC's FAQ gives intrusion attempts, denial of service attempts and unauthorised access attempts as cyber examples, and a primary internet provider outage covered by failover as a technology example.
-
Paragraph 8.06 states that outsourcing the operation or maintenance of IT systems does not relieve a capital market entity of responsibility for compliance with the guidelines. Paragraph 8.13(g) further requires the service level agreement to include a clearly defined arrangement for immediate notification by the service provider in the event of a technology or cyber incident.
-
Paragraph 7.13A requires a cyber security assessment commensurate with the entity's risk exposure before a system is deployed, and paragraph 9.23A requires penetration testing before deploying any new critical system or making any major change to a critical system. These sit above the annual penetration testing minimum in paragraph 9.23.
Source: Securities Commission Malaysia, SC-GL/2-2023 (R1-2024)