Free cyber risk score for Malaysian SMEs
Free. 21 checks, about 8 minutes. Your answers stay in your browser and are never sent to us.
Scoring. Yes = 2, Partly = 1, No = 0, Not sure = 0. Seven sections are weighted Access 18, Data and PDPA 18, Backups 16, Devices 14, Vendors 12, People 10, Visibility and fraud 12, for a total of 100. "Not sure" counts as a gap because a control you cannot confirm cannot be relied on during an incident. Fixes are ranked by points lost.
Basis. Sections are informed by the six functions of the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover) and common SME good practice. This is not a certification, audit or compliance assessment. Not covered in this version: encryption, limiting administrator rights, physical security, data retention and website security. A short self-assessment cannot replace a professional assessment.
Legal reference. Personal Data Protection Act 2010 as amended by the Personal Data Protection (Amendment) Act 2024, and the Cyber Security Act 2024 (Act 854) with its regulations. Legal points were checked on 3 October 2026 against published legal summaries of the PDPA amendments (in force 1 June 2025), the Commissioner's February 2025 breach notification and DPO guidelines, and the Cyber Security Act 2024 regulations. Recheck primary sources from the Department of Personal Data Protection and the National Cyber Security Agency (NACSA) before relying on them.
Version. Content v1.2, written 3 October 2026. Reviewed by: BK Soon. Next review: 12 January 2027.
1. General information only. This check provides general information and self-assessment guidance. It is not legal, regulatory, financial, insurance or other professional advice, and using it does not create a professional or advisory relationship between you and BK Soon ("we", "us").
2. No audit or assurance. Results are based solely on your own answers, which we do not verify. A score does not certify, guarantee or indicate that your business is secure, that it complies with any law, standard or regulation, or that it will be free from cyber incidents.
3. Laws may change. References to laws, regulations and guidelines, including the Personal Data Protection Act 2010 and the Cyber Security Act 2024, summarise our understanding at the date shown, may be incomplete or out of date, and are not a substitute for the official texts or advice from a qualified adviser.
4. No warranty. The check is provided "as is" and "as available", without warranties of any kind, express or implied, including as to accuracy, completeness, reliability or fitness for a particular purpose.
5. Limitation of liability. To the fullest extent permitted by applicable law, we and our directors, partners, employees and contributors are not liable for any loss or damage of any kind, whether direct, indirect, incidental or consequential, including loss of profit, data, goodwill or business, or any regulatory fine or penalty, arising from your use of, or reliance on, this check or any decision you make based on it. You use the check at your own risk and remain responsible for your own security and compliance decisions.
6. Liability that cannot be excluded. Nothing in these terms excludes or limits any liability that cannot be excluded or limited under applicable law.
7. Third parties. Links to third-party websites, if present, are provided for convenience. We do not endorse third-party products or services and are not responsible for third-party content or websites.
8. Privacy. Your assessment answers are processed in your browser and are not sent to us.
9. Changes and governing law. We may update the check and these terms at any time, and the version date applies. These terms are governed by the laws of Malaysia.
Terms last updated: 3 October 2026.