Many small and medium businesses in Malaysia want to know where they stand on cybersecurity but cannot justify a full assessment. This free check gives a quick, plain-language self-assessment: a score, ranked fixes and a 90-day plan.
The checks are informed by the NIST Cybersecurity Framework 2.0 and common good practice for small organisations. Legal notes reflect our understanding of Malaysia's Personal Data Protection Act as amended in 2024, the Commissioner's 2025 guidelines, and the Cyber Security Act 2024, as at the date shown on the check. The method, the scoring and the limits of the check are explained on the main page.
BK Soon is a cybersecurity professional with more than two decades of experience in information technology and cybersecurity governance. He built his foundation in IT project management and earned a Postgraduate Diploma with Distinction from RMIT University.
He is a Partner at Casaba Security, a CREST-approved security firm, and Chair of the CREST Asia Regional Council (2025–2028), which covers 11 Asia-Pacific jurisdictions. His work spans project management, business development, relationship management, and the legal and regulatory frameworks that shape cybersecurity.
Outside his professional work, he is interested in youth development and in the career pathways open to the next generation.
Disclosure: This site is BK Soon’s personal project. The views and content are his own. It is independent of, and does not represent and is not endorsed by, Casaba Security, CREST International or the CREST Asia Regional Council.
This check is independent. It is not affiliated with, endorsed by or certified by NIST, the National Cyber Security Agency (NACSA), the Department of Personal Data Protection, or Google. It is general information, not professional advice. Please read the Terms of use on the main page.
If you find an error or an out-of-date legal reference, please tell us at bksoon.my@gmail.com. We review the content regularly and record the date of each review on the main page.