Malaysia’s cybercrimes and cyber security laws may sound similar, but they address different risks, regulate different parties and serve different legal purposes.
According to Monash University Malaysia’s School of Business senior lecturer Dr Ridoan Karim, cybercrimes law targets those who use technology to commit offences, while cyber security law governs how organisations protect critical systems from attacks.
He said the cybercrimes law focuses on criminal offences committed using computers and digital technologies, including the use of artificial intelligence (AI) for illegal activities.
“The cyber security law, in contrast, concerns the protection of critical national information infrastructure, cybersecurity governance and regulatory obligations,” Dr Ridoan said, while emphasising that they are two separate pieces of legislation.
To better understand the distinction, here are five key differences between the two.
- Crime Versus Protection
The cybercrimes framework deals with illegal conduct such as hacking, digital fraud, identity theft, data interference and the criminal misuse of AI.
Cyber security law focuses on protecting important digital systems and reducing vulnerabilities before attacks occur.
- Offenders Versus Organisations
Cybercrimes legislation primarily targets individuals, groups or syndicates accused of committing digital offences.
Cyber security legislation mainly regulates organisations responsible for critical infrastructure and essential services.
These may include operators in sectors such as finance, telecommunications, energy and transport.
- Punishment Versus Prevention
Cybercrimes law defines offences, establishes penalties and gives authorities powers to investigate and prosecute offenders.
Cyber security law is more preventive and regulatory, requiring relevant organisations to manage risks, strengthen safeguards and comply with security obligations.
- Criminal Liability Versus Regulatory Compliance
Under cybercrimes law, the key question is whether a person committed a prohibited act using computers or digital technology.
Under cyber security law, the focus is whether an organisation adequately protected its systems, reported incidents and met prescribed governance requirements.
- Separate Laws That Can Work Together
A major cyberattack could trigger both legal frameworks.
The perpetrators could be investigated under cybercrimes law, while the affected organisation could face scrutiny under cyber security law over whether it fulfilled its protection and reporting duties.
The two laws are therefore complementary, but not interchangeable.
One targets those who weaponise technology to commit crimes, while the other seeks to ensure Malaysia’s most important digital systems are resilient enough to withstand them.
On July 20, the Dewan Negara passed the Cybercrimes Bill 2026, equipping Malaysian authorities with tougher cross-border enforcement powers against increasingly sophisticated cyber offences.
The eight-part, 61-clause Bill was approved by a majority vote after debate by 21 senators and passed unanimously without amendments at the committee stage.
It will repeal the Computer Crimes Act 1997, replacing the nearly three-decade-old law with a framework covering modern digital threats and the criminal misuse of emerging technologies.
Related
Click Here For The Original Source.
