Section 23
Duty to give notification on cyber security incident
If it comes to the knowledge of a national critical information infrastructure entity that a cyber security incident has or might have occurred in respect of the national critical information infrastructure owned or operated by the national critical information infrastructure entity, the national critical information infrastructure entity shall notify the Chief Executive and its national critical information infrastructure sector lead of such information within the period and in such manner as may be prescribed.
(2)
Any national critical information infrastructure entity which contravenes this section commits an offence and shall, on conviction, be liable to a fine not exceeding five hundred thousand ringgit or to imprisonment for a term not exceeding ten years or to both.