Thursday 08 Oct 2026
main news image

KUALA LUMPUR (Nov 11): Bursa Malaysia has introduced cyber resilience enhancements requiring brokers to oversee third-party tech providers, like order management system (OMS) vendors, to ensure compliance with the exchange’s regulations.

The move is to strengthen the integrity of the stockbroking ecosystem after the April 24 incident where about 80 accounts — less than 0.01% of all online trading accounts — were affected by unauthorised trades.

Bursa Malaysia in a statement said the standards related to people, processes, and governance — especially recovery planning and incident management — must be implemented within three months. System and infrastructure upgrades must be completed by Dec 31, 2026.

The enhancements come from a recommendation paper by an industry working group formed in June 2025, including representatives from bank-backed and non-bank brokers, plus cybersecurity experts. 

Chaired by Bursa Malaysia’s chief regulatory officer, Julian M Hashim, the working group reviewed industry cybersecurity practices, identified vulnerabilities, and developed IT risk management and incident response standards, along with regulatory and operational improvements.

The recommendations align with Securities Commission Malaysia and Bank Negara Malaysia technology risk frameworks, aiming to improve industry-wide cybersecurity and resilience.

Bursa Malaysia’s nine cybersecurity pillars:

  1. Access controls: Restrict system and data access to authorised personnel.
  2. Threat detection: Monitor and respond to cyber threats.
  3. Patch management: Keep software updated to fix vulnerabilities.
  4. Infrastructure resilience: Ensure reliable and recoverable IT systems.
  5. Recovery planning: Have tested procedures to restore critical systems quickly.
  6. Third-party oversight: Ensure tech providers follow security standards.
  7. Incident management: Detect, report, and resolve cyber incidents efficiently.
  8. Training & awareness: Educate staff and stakeholders on cyber risks.
  9. Dedicated cybersecurity roles: Assign qualified personnel to manage cybersecurity.

“Our priority is to protect investors and uphold the trust they place in our securities market. These enhancements represent the industry’s commitment to every investor that cybersecurity safeguards are taken seriously, and are of prime importance. By strengthening the cyber resilience of the stockbroking ecosystem, we are actively taking steps to fortify the marketplace where investors can trade with confidence, knowing their investments are protected against cyber threats,” Bursa Malaysia chief executive officer Datuk Fad’l Mohamed said.

Edited ByPresenna Nambiar
      Print
      Text Size
      Share