Skip to content
Ethical Hacking & Cybersecurity (CEH v13 / Security+ SY0-701 / OSCP / CISSP / NACSA-aligned)

Ethical Hacking & Cybersecurity Training in Malaysia

Ethical hacking and cybersecurity training in Malaysia is structured 1-to-1 coaching toward industry certifications: CompTIA Security+ SY0-701, CEH v13 by EC-Council, OSCP / PEN-200 by Offensive Security, and CISSP by (ISC)²: aligned to the legal scope set by Akta Cybersecurity 2024 (Act 854), Akta Jenayah Komputer 1997 (Act 563), BNM RMiT, and NIST CSF 2.0. Strictly authorised-only practice.

4.6(141 reviews)RM80 – RM200 / hour
The essentials

What is Ethical Hacking & Cybersecurity Training?

Ethical Hacking & Cybersecurity Training in Malaysia

Ethical hacking and cybersecurity training in Malaysia covers the full adult career pathway across three certification tiers and one regulated legal scope. Tier 1 (foundation, vendor-neutral): CompTIA Security+ SY0-701 for blue-team baseline, plus networking (CompTIA Network+), Linux (LPI / Kali Linux fluency), and Python / Bash scripting. Tier 2 (offensive baseline): CEH v13 by EC-Council (exam 312-50, 125 MCQ, 4 hours, delivered via Pearson VUE Malaysia through Authorized Training Centres such as INFOSEC ATC, NetAssist, Iverson Associates, Trainocate). Tier 3 (hands-on practical): OSCP / PEN-200 by Offensive Security (24-hour practical exam compromising live machines plus professional report), recognised as the practical industry benchmark. Tier 4 (senior architect): CISSP by (ISC)², 8 domains, requires 5 years cumulative paid experience. The legal scope is non-negotiable: Akta Jenayah Komputer 1997 (Computer Crimes Act, Act 563) criminalises unauthorised access (s.3, up to RM 150,000 fine and 10 years imprisonment); Akta Keselamatan Siber 2024 (Act 854, enforced 26 August 2024) designates 11 NCII sectors and requires mandatory incident reporting; PDPA 2010 + Amendment 2024 (Act A1716) requires breach notification to JPDP. Sector-specific overlays apply: BNM Risk Management in Technology (RMiT) for fintech and banking, Securities Commission Guidelines on Cyber Risk for capital markets, KKM Medical Device Authority guidance for connected medical devices. NACSA (National Cyber Security Agency under PM Department) coordinates NCII sector lead agencies. CyberSecurity Malaysia (CSM) under MOSTI operates MyCERT (Malaysia Computer Emergency Response Team, since 1997), Cyber999 incident-help line, and the MyCC scheme under ISO/IEC 15408. Edustar matches a coach to the right cert pathway: Security+ first for IT career-switchers, OSCP for hands-on pen-test ambition, CISSP for senior-architect track, within a written Rules of Engagement that keeps every lab exercise legal.

  • 01Akta Keselamatan Siber 2024 (Act 854, enforced 26 August 2024) designates 11 NCII sectors and licenses cybersecurity service providers, biggest single MY demand driver
  • 02Akta Jenayah Komputer 1997 (Act 563), unauthorised access is criminal (s.3, up to RM 150,000 fine and 10 years imprisonment); ethical hacking is legal only with written authorisation
  • 03CEH v13 by EC-Council: exam 312-50 (125 MCQ, 4 hours, Pearson VUE Malaysia); ATCs include INFOSEC ATC, NetAssist, Iverson Associates, Trainocate
  • 04CompTIA Security+ SY0-701 (latest revision November 2023), vendor-neutral baseline, the most common SOC analyst entry requirement in MY MSSPs
  • 05OSCP / PEN-200 by Offensive Security, 24-hour practical exam considered the hands-on industry benchmark for penetration testers in MY
  • 06CISSP by (ISC)², 8 domains, requires 5 years cumulative paid experience; dominates MY CISO and Head of Cyber roles
  • 07BNM Risk Management in Technology (RMiT) governs all MY financial institutions, annual penetration testing and SOC capability mandatory
  • 08CyberSecurity Malaysia (CSM under MOSTI) operates MyCERT (since 1997, ITU-recognised national CSIRT), Cyber999, MyCC under ISO/IEC 15408, and CSM-ACE
  • 09MDEC + MyDigital Blueprint (MOSTI 2021-2030) targets ~500,000 digital workers; APU runs the first MQA-accredited BSc Cyber Security in MY (since 2010)
  • 10HRD Corp claim possible for adult learners via SBL-Khas through levy-paying employers; free baseline awareness via HRD Corp e-LATiH
  • 11Reference frameworks adopted in MY: NIST CSF 2.0 (Govern, Identify, Protect, Detect, Respond, Recover), ISO/IEC 27001:2022 (93 controls), MITRE ATT&CK, OWASP Top 10
By the numbers

What ethical hacking & cybersecurity training with Edustar covers

The honest scope, stated plainly: structured year-round coaching across the whole MY cybersecurity career pathway, held to strict legal-scope discipline, with no promised cert pass, no promised job, and no invented pass-rate.

Adult career

All-level adult pathway (no school exam track)

4 cert ladders

Security+ SY0-701 / CEH v13 / OSCP-PEN-200 / CISSP: plus ISACA CRISC / CISM / CISA risk track

11 NCII sectors

Aligned to Akta Cybersecurity 2024: Government, Banking & Finance, Transportation, Defence, ICM, Energy, Medical, Water, Healthcare, Trade, STI

Nationwide + online

1-to-1 mentored sessions, HRD Corp claim possible via levy-paying employer

Curriculum

What ethical hacking & cybersecurity training covers

Three modules mapped to the MY industry career path, Foundations (networking + Linux + scripting + crypto baseline), Defensive (CompTIA Security+ + blue-team SIEM / SOC + incident response NIST CSF 2.0), Offensive (CEH v13 + OSCP / PEN-200 + HTB / THM / PortSwigger labs inside a written Rules of Engagement).

Module 1, Foundations (networking + Linux + Python / Bash + crypto basics)

Prerequisite layer. Coaches assume zero security background and build the network + Linux + scripting + cryptography baseline that every CEH / Security+ / OSCP candidate must have before exam study even starts.

Networking depth: OSI 7-layer model, TCP/IP stack, IPv4 / IPv6, subnetting and CIDR, NAT and PAT, routing fundamentals, common protocols (HTTP/S, DNS, DHCP, SMTP, SSH, FTP, SMB, RDP), packet analysis with Wireshark, port scanning with nmap (TCP SYN / UDP / version detection / scripting engine), firewall and IDS / IPS concepts, VPN (IPsec, OpenVPN, WireGuard). Recommended cert ladder before Security+: CompTIA Network+. Linux fluency: Kali Linux + Parrot OS as the standard pentesting distributions; file system hierarchy, permissions (chmod, chown, setuid / setgid), processes, systemd, package management (apt, dpkg), bash command pipeline (grep, sed, awk, xargs, find), shell scripting (loops, conditionals, functions), SSH and key management. Scripting for security: Python 3 for automation (requests, scapy, paramiko, BeautifulSoup), Bash for one-liners, PowerShell for Windows operators. Cryptography baseline: symmetric (AES, ChaCha20) vs asymmetric (RSA, ECC, Diffie-Hellman, Ed25519), hashing (SHA-256, SHA-3, bcrypt, Argon2, MD5 / SHA-1 deprecation), TLS 1.3 handshake, PKI and certificate chains, digital signatures, JWT pitfalls, basic cryptanalysis intuition. Operating system internals: Windows process model, Active Directory basics (domain, OU, GPO, Kerberos vs NTLM), Linux process and memory model. Sandbox lab environment: VMware Workstation Player or VirtualBox with isolated host-only network; deliberately vulnerable VMs (Metasploitable 2 / 3, DVWA, OWASP Juice Shop) running on student's own kit. **Strict rule from lesson 1: no traffic leaves the lab segment.** Suits IT-career-switchers, fresh CS / IT graduates, and working IT professionals pivoting from sysadmin / network admin into security.

Module 2, Defensive (CompTIA Security+ SY0-701 + blue-team SIEM / SOC + incident response NIST CSF 2.0)

Blue-team and defensive track. The most common MY first-cert path because Security+ is the baseline SOC-analyst requirement at MSSPs, and blue-team skills map directly to BNM RMiT, NIST CSF 2.0 and CSM operational practice.

CompTIA Security+ SY0-701 (latest revision November 2023): five domains: (1) General Security Concepts, (2) Threats, Vulnerabilities & Mitigations, (3) Security Architecture, (4) Security Operations, (5) Security Program Management & Oversight. Exam: 90 minutes, up to 90 questions (MCQ + performance-based), 750 / 900 pass mark, delivered via Pearson VUE Malaysia. NIST Cybersecurity Framework 2.0 (published February 2024), six functions: Govern (new in 2.0), Identify, Protect, Detect, Respond, Recover. Used by CSM and BNM as common reference. ISO/IEC 27001:2022: 93 Annex A controls reorganised into 4 themes (organisational, people, physical, technological); audit cycle and Statement of Applicability. Blue-team SIEM / SOC operations: Splunk, Elastic Security (ELK), Microsoft Sentinel, IBM QRadar, Wazuh; writing correlation rules, building dashboards, alert triage workflow, false-positive tuning, threat hunting basics. Logging discipline: Windows Event Logs (4624, 4625, 4688, 4768), Linux auditd, Sysmon, EDR (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint) telemetry. MITRE ATT&CK Framework: tactics, techniques, sub-techniques; mapping detections to TTPs; ATT&CK Navigator. Incident response: NIST SP 800-61r2 four-phase lifecycle (Preparation, Detection & Analysis, Containment / Eradication / Recovery, Post-Incident); chain-of-custody for digital forensics; MyCERT incident reporting via Cyber999. Vulnerability management: CVE / CVSS scoring, Nessus / OpenVAS / Qualys, patch lifecycle, KEV (Known Exploited Vulnerabilities) catalogue. Identity and access: IAM, MFA, SSO (SAML, OIDC), PAM, zero-trust architecture (Forrester / NIST SP 800-207). Cloud security entry: AWS / Azure / GCP shared responsibility model, common misconfigurations (open S3 buckets, exposed IAM keys), AWS Config / Security Hub, Azure Defender. Past-paper drilling: Security+ SY0-701 performance-based-question practice (PBQs), CompTIA CertMaster Practice, dump-quality awareness (Edustar coaches teach exam fundamentals, not brain-dumps). Suits SOC-analyst aspirants, IT operations staff moving into security, BNM-regulated bank IT staff under RMiT mandate, and NCII compliance officers.

Module 3, Offensive (CEH v13 + OSCP / PEN-200 + HTB / THM / PortSwigger labs inside written Rules of Engagement)

Offensive and red-team track. The legal scope here is non-negotiable: every lab is run inside a written Rules of Engagement (RoE) or against deliberately vulnerable platforms (TryHackMe, HackTheBox, PortSwigger Web Security Academy, local VMs). Targeting third-party systems without written authorisation is a criminal offence under Akta Jenayah Komputer 1997.

CEH (Certified Ethical Hacker) v13 by EC-Council: exam 312-50 (125 MCQ, 4 hours, 70% pass typical), delivered via Pearson VUE Malaysia through Authorized Training Centres including INFOSEC ATC, NetAssist, Iverson Associates and Trainocate. CEH Practical (optional second exam, 6 hours, 20 challenges) for CEH Master designation. CEH v13 syllabus modules, Introduction to Ethical Hacking; Footprinting & Reconnaissance; Scanning Networks; Enumeration; Vulnerability Analysis; System Hacking; Malware Threats; Sniffing; Social Engineering; Denial-of-Service; Session Hijacking; Evading IDS / Firewalls / Honeypots; Hacking Web Servers; Hacking Web Applications; SQL Injection; Hacking Wireless Networks; Hacking Mobile Platforms; IoT and OT Hacking; Cloud Computing; Cryptography. OSCP / PEN-200 by Offensive Security, the practical industry benchmark. 24-hour hands-on exam: compromise multiple lab machines (standalone + Active Directory set) plus a 24-hour professional report submission. Course includes Kali Linux and the Penetration Testing with Kali (PWK) lab. Active Directory pentesting: enumeration (BloodHound, PowerView), Kerberoasting, AS-REP roasting, NTLM relay, DCSync, golden / silver tickets, lateral movement. Web application pentesting: full OWASP Top 10 (2021 release + 2025 candidate): A01 Broken Access Control, A02 Cryptographic Failures, A03 Injection (SQL, NoSQL, OS command), A04 Insecure Design, A05 Security Misconfiguration, A06 Vulnerable & Outdated Components, A07 Identification & Authentication Failures, A08 Software & Data Integrity Failures, A09 Logging & Monitoring Failures, A10 SSRF. Tooling: Burp Suite (Community + Pro), OWASP ZAP, sqlmap, ffuf / gobuster, nuclei. Network and infrastructure: Metasploit Framework, msfvenom payload generation, manual exploitation (buffer overflow basics on Linux + Windows, ASLR / DEP / stack canaries), privilege escalation (LinPEAS, WinPEAS, GTFOBins, lolbas-project), reverse and bind shells. Lab platforms: HackTheBox Academy (modular paths aligned to OSCP and CPTS), TryHackMe (beginner-friendly, monthly subscription), PortSwigger Web Security Academy (free, OWASP-aligned), VulnHub VMs, INE / eLearnSecurity ladder. **Rules of Engagement discipline**: every external engagement requires a signed Statement of Work (SoW) and RoE listing scope (in-scope IPs / domains), out-of-scope assets, testing window, methods authorised, emergency contacts, data-handling clauses, and reporting format. Edustar coaches refuse any work outside this frame. Bug bounty pathway: HackerOne, Bugcrowd, Intigriti programmes (legal alternative to unauthorised testing). Suits OSCP aspirants, future pentest consultants at MY MSSPs, bug bounty hunters, and offensive engineers at NCII operators.

For Whom

Who ethical hacking & cybersecurity training in Malaysia is for

We match the coach, cert pathway and intensity to where the learner actually is: career-switcher from IT, fresh CS / IT graduate, working IT professional pivoting up, or NCII compliance officer under Akta Cybersecurity 2024.

IT career-switcher (existing IT background, pivoting to cyber)

Most common adult cohort. Sysadmin, network engineer, IT support or junior developer with 2-7 years of general IT experience who wants to move into a security role. Already comfortable with Linux command line, Windows admin, basic scripting and TCP/IP. Coaching focus is fast-track to CompTIA Security+ SY0-701 (often 8-12 weeks weekly evenings), then a structured HackTheBox or TryHackMe path while preparing CEH v13. Realistic timeline to first SOC analyst or junior pentester role: 6-12 months. HRD Corp SBL-Khas claim almost always applies.

  • Plenty of certifications in the market (CompTIA, EC-Council, Offensive Security, (ISC)², ISACA, AWS, Azure) no clear MY-specific roadmap of which to do first
  • Vendor marketing pitches CEH as 'the cert' while MY MSSP job ads ask for Security+ + OSCP, confusing for self-direction
  • Worry that legal grey areas (testing on home network vs employer's network vs cloud) will turn into a Computer Crimes Act 1997 problem
  • Wants to land a BNM-regulated bank or NCII operator role but does not know what RMiT / NCII actually require of staff

Fresh CS / IT graduate (BSc Computer Science / Information Security / Cyber Security)

Recent graduate from a public IPTA (UM, USM, UKM, UPM, UTM, UTeM) or MDEC Premier Digital Tech Institute (APU, MMU, Taylor's, Sunway) with academic baseline but no production cybersecurity experience. Coaching focus is bridging from coursework to industry-ready: hands-on HackTheBox / TryHackMe rooms, an OSCP / PEN-200 attempt within 12-18 months of graduation, building a public GitHub portfolio of pentest writeups (without breaching scope), and interview prep for MY MSSPs (LGMS, Securelytics, Firmus) and BNM-regulated bank in-house teams.

  • Final year project covered theory but the OSCP exam is a different intensity, needs structured lab time + mentor feedback
  • MY MSSP and bank SOC interviews ask hands-on questions (live nmap walkthroughs, AD attack path) that university lab time did not cover
  • No clear answer to 'which cert do I attempt first as a fresh grad', most peers attempt CEH, but OSCP is harder and more respected at the hiring tier they want
  • Wants to build a public portfolio of HTB / THM writeups but worried about violating any code of conduct or scope

Working IT professional pivoting up (sysadmin / DevOps moving to senior security)

Mid-career (5-12 years) IT or DevOps professional whose role is increasingly security-adjacent (cloud security, container security, IAM, zero trust). Often already informally doing security work without a security job title. Coaching focus is structured CISSP prep within 6-9 months (5-year experience requirement met), CCSP for cloud-security depth, plus optional CEH for hiring-keyword coverage and ISACA CRISC for risk-track. Goal is to land a Security Architect or Head of Security role at a BNM-regulated bank, NCII operator or MSC-status tech firm.

  • Job ads for Security Architect / Head of Cyber want CISSP, but the 5-year requirement was vague and unclear how to document
  • CISSP CBK is wide (8 domains) and 100-150 adaptive questions over 3 hours is harder to revise for than vendor exams
  • Needs a structured 6-9 month coaching plan that fits around full-time work, not a 5-day bootcamp
  • Considering whether CISSP + CCSP, CISSP + CISM (ISACA), or CISSP + CRISC is the strongest senior-track combo for MY market

NCII compliance officer / BNM-RMiT-regulated staff (post-Akta Cybersecurity 2024)

Staff at a NCII-designated employer (Petronas, TNB, TM, MAHB, MAS, BNM-regulated bank, healthcare provider, Securities Commission-regulated capital market entity) responsible for translating Akta Keselamatan Siber 2024, BNM RMiT or SC Guidelines on Cyber Risk into operational practice. Often promoted from IT operations or risk / audit, may not have a hands-on cyber background but needs vocabulary depth across NIST CSF 2.0, ISO/IEC 27001:2022, MITRE ATT&CK, and incident-response workflow. Coaching focus is governance and reporting: Security+ for vocabulary, CISA / CRISC (ISACA) for audit / risk depth, optional CEH for offensive-vocabulary literacy, plus structured walk-through of BNM RMiT and the new NACSA Code of Practice.

  • Akta Cybersecurity 2024 is new (enforced 26 August 2024), the Code of Practice per NCII sector is still being issued; needs current orientation
  • BNM RMiT requires annual penetration testing and incident reporting within prescribed timelines, needs vocabulary to manage external pentest vendors and respond to audit
  • PDPA Amendment Act 2024 (Act A1716) brings mandatory breach notification to JPDP, needs the breach-classification + reporting workflow
  • Wants a 6-month structured Security+ + ISACA CRISC plan that fits around full-time governance role, not a hands-on red-team curriculum
How It Works

From first call to first cybersecurity lesson

How starting ethical hacking & cybersecurity training with Edustar works: cert pathway matched to career goal, lab environment set up before lesson 1, written Rules of Engagement signed before any hands-on work.

  1. 1

    Free needs assessment (Day 0)

    Share your current role and IT background (sysadmin, network admin, fresh graduate, IT manager, risk / audit), prior cyber exposure (any TryHackMe / HackTheBox / OWASP work, any certs already held, any home-lab practice), target career destination (MY MSSP SOC analyst, BNM-regulated bank in-house, MSSP pentest consultant, NCII compliance, CISO track), realistic weekly hour commitment, and budget (out-of-pocket vs HRD Corp claim through employer). We brief honestly on which cert ladder is realistic in the window available, and refuse to oversell. Computer Crimes Act 1997 + Akta Cybersecurity 2024 legal scope explained on call 1.

    ~20 min
  2. 2

    Diagnostic: short hands-on task at baseline

    Level-appropriate diagnostic: a TryHackMe room (Pre-Security / Introduction to Cyber Security path) for absolute beginners; a Security+ SY0-701 sample exam (20 questions, mixed objective + scenario) for IT-baseline learners; an easy-rated HackTheBox machine walkthrough for fresh CS / IT graduates; a CISSP CBK domain sample for senior architect-track. Focus is current fluency, debugging habit and the ability to read a brief, going well beyond the final flag.

    Before lesson 1
  3. 3

    Coach matching (cert-specialist)

    We match a coach to the right cert pathway: Security+ SY0-701 + NIST CSF 2.0 for blue-team baseline; CEH v13 + OWASP Top 10 for offensive baseline; OSCP / PEN-200 + Active Directory pentesting for hands-on red-team; CISSP CBK for senior architect; ISACA CRISC / CISM / CISA for risk-track. BNM RMiT-fluent coaches available for fintech / banking. Subject-specialist match means no wasted weeks on the wrong syllabus.

    1-3 days
  4. 4

    First lesson: lab environment + legal-scope briefing + Lesson 1 task

    Coach helps set up the sandbox lab: VMware Workstation Player or VirtualBox with host-only network, Kali Linux + Parrot OS VM, Metasploitable 2 / 3, DVWA, OWASP Juice Shop, plus accounts on TryHackMe + HackTheBox. Critical Lesson 1 step: written briefing on Akta Jenayah Komputer 1997 (s.3 unauthorised access (RM 150,000 / 10 years), Akta Cybersecurity 2024 (Act 854), and PDPA 2010 + Amendment 2024) and a signed Rules of Engagement template that we use for every external scope. Lesson 1 ends with first TryHackMe or Security+ topic completed and logged in your portfolio.

    Lesson 1
  5. 5

    Weekly drilling: topic-by-topic curriculum

    Weekly 1.5-2 hour sessions structured around the chosen curriculum module, Foundations (networking + Linux + Python / Bash + crypto baseline) for prerequisite gaps, Defensive (Security+ SY0-701 + blue-team SIEM / SOC + NIST CSF 2.0 incident response) for SOC analyst track, Offensive (CEH v13 + OSCP / PEN-200 + HTB / THM / PortSwigger labs) for pentest track. Every week the learner ships a writeup or lab note to a private GitHub repo, documentation discipline becomes muscle memory.

    Ongoing: 8-16 weeks per module
  6. 6

    Lab sprint + past-paper / cert drilling

    Mid-module: a 3-4 week lab sprint that ships a portfolio writeup (full HackTheBox machine walkthrough sanitised for public sharing, OWASP Juice Shop solution log, AD attack-path narrative, or blue-team detection rule pack). For cert-track learners, the final 4-6 weeks shift to exam-format drilling: Security+ SY0-701 performance-based questions, CEH v13 312-50 MCQ banks, OSCP / PEN-200 lab machines with timing pressure, CISSP CBK domain quizzes.

    Mid-module (lab) + final 4-6 weeks pre-exam (drill)
  7. 7

    Exam-day prep + post-cert career review

    Final 1-2 weeks pre-exam: timed mock exams under official conditions (Security+ 90 min / 90 Q, CEH 4 h / 125 Q, OSCP 24 h hands-on + 24 h report, CISSP adaptive 100-150 Q). Pearson VUE Malaysia booking checklist. Post-cert: portfolio review (private + public GitHub repos, sanitised writeups, LinkedIn updates), interview prep for MY MSSP / BNM bank / NCII employer roles, and plan for the next cert in the ladder (Security+ → CEH → OSCP, or CISSP → CCSP / CISM).

    Final 1-2 weeks + post-cert review
Good to know

Things parents ask us first

  • Legal scope is non-negotiable: Akta Jenayah Komputer 1997 + Akta Keselamatan Siber 2024

    Unauthorised access to any computer system is a criminal offence under section 3 of Akta Jenayah Komputer 1997 (Computer Crimes Act, Act 563), fine up to RM 150,000 and / or imprisonment up to 10 years. Akta Keselamatan Siber 2024 (Cyber Security Act 2024, Act 854, enforced 26 August 2024) adds licensing requirements for cybersecurity service providers and mandatory incident reporting across 11 NCII sectors. 'Ethical' hacking is only legal inside a written Statement of Work (SoW) and signed Rules of Engagement (RoE): or against systems you own, or against deliberately vulnerable lab platforms (HackTheBox, TryHackMe, PortSwigger Web Security Academy, local VMs). Edustar coaches refuse to demonstrate techniques against third-party systems without that paperwork. This rule appears on day one and stays for every lesson.

  • CEH vs CompTIA Security+ vs OSCP: which certification first?

    This is the single most-asked question from MY career-switchers. Common pathway: **Security+ first** if you are entering the MY MSSP / SOC analyst market: vendor-neutral baseline (SY0-701), broadly accepted by BNM-regulated banks and government contractors, knowledge-test format (90 minutes, 90 questions). **CEH v13 second** if you want the well-known offensive-baseline credential for HR keyword search: EC-Council exam 312-50 (125 MCQ, 4 hours via Pearson VUE MY at INFOSEC ATC / NetAssist / Iverson / Trainocate), broader but less practical than OSCP. **OSCP / PEN-200 third** if your target is the practical pentest consultant track at MY MSSPs (LGMS, Securelytics, Firmus, CSM-affiliated firms), 24-hour hands-on exam, the industry benchmark for 'can actually pentest'. **CISSP later** (5 years experience required) for senior architect / CISO track. Picking Security+ → CEH → OSCP over 18-30 months is a common honest plan; OSCP first is possible but brutal without the Linux + networking baseline.

  • BNM RMiT compliance is the biggest MY fintech / banking demand driver

    Bank Negara Malaysia's Risk Management in Technology (RMiT) policy document (first issued 18 December 2019 and refreshed) applies to every MY bank, insurer, takaful operator, DFI and digital bank licensee. RMiT mandates: board-level accountability for cyber risk, an independent cyber risk management function, annual penetration testing of critical systems, continuous vulnerability assessment, SOC capability with 24x7 monitoring, threat intelligence integration, and incident reporting to BNM within prescribed timelines. The Securities Commission Guidelines on Management of Cyber Risk (October 2016, refreshed) extend equivalent obligations to capital market entities including digital asset exchange operators (DAX). This is why BNM-regulated employers in Kuala Lumpur's financial district pay strongly for Security+ / CEH / OSCP holders. Coaching toward this market is one of our most common engagements.

  • 11 NCII sectors under Akta Cybersecurity 2024 = published demand signal

    Akta Keselamatan Siber 2024 designates 11 National Critical Information Infrastructure (NCII) sectors: (1) Government, (2) Banking & Finance, (3) Transportation, (4) Defence & National Security, (5) Information, Communication & Multimedia, (6) Energy, (7) Medical, (8) Water, Sewerage & Waste Management, (9) Healthcare Services, (10) Trade, Industry & Economy, (11) Science, Technology & Innovation. Each sector has a lead agency coordinating with NACSA. Major NCII operators include Petronas (energy), Tenaga Nasional Berhad / TNB (energy), Telekom Malaysia / TM and Maxis (communications), MAHB (transportation: Malaysia Airports), Malaysia Airlines / MAS (transportation), and BNM-regulated banks (banking & finance). All eleven now carry mandatory incident reporting and licensed-MSSP requirements. This is a published, real demand signal (not a fabricated count) and it shapes which certs HR teams now ask for.

  • HRD Corp claim works for cybersecurity certs: file via SBL-Khas

    An employed adult whose company is registered with HRD Corp can usually claim most cybersecurity certification prep through the SBL-Khas (Skim Bantuan Latihan Khas) scheme. The firms that pay the levy under Akta PSMB 2001 are generally those with annual sales above RM 2.5M or a headcount past 10. What falls inside the eligible list is broad: CompTIA Security+, CEH v13, OSCP / PEN-200, CISSP prep, and the cloud-security tracks (AWS Security Specialty, Azure AZ-500, GCP Professional Cloud Security Engineer). To make the paperwork easy, we hand over a written training breakdown covering module hours, learning outcomes, coach profile and the certificate of completion, so your HR or L&D team can lodge it cleanly. Before paying for certification prep, it is worth clearing HRD Corp e-LATiH's free baseline cyber-awareness courses too.

  • CISSP: the senior architect track (not an entry cert)

    CISSP (Certified Information Systems Security Professional) by (ISC)² is the standard senior-level credential and dominates MY CISO, Head of Cyber and Security Architect roles. Eight Common Body of Knowledge (CBK) domains: Security & Risk Management, Asset Security, Security Architecture & Engineering, Communication & Network Security, Identity & Access Management, Security Assessment & Testing, Security Operations, Software Development Security. **5 years cumulative paid work experience required** (1-year waiver for a recognised degree or another approved cert). Exam: adaptive 100-150 questions, up to 3 hours. Endorsement required from another (ISC)² holder post-pass. Not realistic as a first cert; plan it for the 5-7 year mark of a cyber career. ISACA Malaysia equivalents (CISM (manager), CISA (audit) and CRISC (risk)) are also common at the senior tier, especially in Big4 audit firms and BNM-regulated banks.

Compare

Edustar 1-to-1 cybersecurity coach vs 3-6 month bootcamp vs self-study (TryHackMe + HackTheBox) vs MDEC PDTI degree (e.g. APU BSc Cyber Security)

Four ways into a Malaysian cybersecurity career, compared head to head. Most serious learners mix a couple, and which one leads depends on where you start, zero IT, an IT background, fresh-grad or mid-career, and on budget.

★ Recommended

Edustar 1-to-1 cybersecurity coach

  • Format

    Weekly 1-to-1 mentored sessions (1.5-2 hours), year-round, cert-track customised (Security+ SY0-701, CEH v13, OSCP, CISSP). Pair-debugging in shared lab.

  • Best for

    IT-career-switchers, fresh CS / IT graduates pivoting to cyber, working IT pros (sysadmin / network) moving up, NCII compliance officers and BNM-regulated bank staff under RMiT mandate.

  • Typical cost (MYR)

    RM 150-300 / hr depending on cert track and coach seniority (Security+ mid, OSCP and CISSP upper); HRD Corp claim possible via levy-paying employer.

  • Certifications targeted

    Calibrated to coachee target: Security+ SY0-701 first, then CEH v13, then OSCP / PEN-200, then CISSP later. ISACA CRISC / CISM / CISA for risk-track learners under BNM RMiT.

  • Legal-scope discipline (Akta Jenayah Komputer 1997 + Akta Cybersecurity 2024)

    Day 1 briefing on Computer Crimes Act 1997 (s.3 unauthorised access, RM 150k / 10y) and Akta Cybersecurity 2024 NCII / licensing. Every lab inside written RoE or against deliberately vulnerable platforms.

  • Time-to-first-cyber-role (realistic, honest)

    6-18 months depending on starting baseline and weekly hours; Security+ + portfolio of HTB / THM writeups + 1 pen-test lab project is the typical first interview-worthy package.

3-6 month cybersecurity bootcamp (full-time, adult)

  • Format

    Full-time immersive 3-6 months (Mon-Fri 9-5), structured cohort, instructor-led, capstone project.

  • Best for

    Adult career-changers (25-40) wanting first cyber role in 6-12 months and able to commit full-time.

  • Typical cost (MYR)

    RM 12,000-30,000 total (3-6 months); HRD Corp SBL-Khas claim possible.

  • Certifications targeted

    Typically Security+ + CEH + intro pentest project; some include OSCP attempt during programme.

  • Legal-scope discipline (Akta Jenayah Komputer 1997 + Akta Cybersecurity 2024)

    Usually covered in legal-and-ethics module early in cohort.

  • Time-to-first-cyber-role (realistic, honest)

    3-6 months programme + 1-3 months job search; bootcamp-graduate outcomes depend heavily on prior IT experience.

Self-study (TryHackMe + HackTheBox + PortSwigger + OffSec PEN-200 lab)

  • Format

    Self-paced. No live mentor; community Discord support. Pure lab grind.

  • Best for

    Highly self-driven learners with strong English reading discipline and existing IT baseline.

  • Typical cost (MYR)

    RM 0 to ~RM 2,500 / year (TryHackMe Premium ~USD 14/mo, HackTheBox VIP+ ~USD 20/mo, OffSec PEN-200 lab + exam bundle USD 1,649-2,499); plus exam fees if attempted.

  • Certifications targeted

    Whatever the learner picks; no MY market signal: relies on self-direction.

  • Legal-scope discipline (Akta Jenayah Komputer 1997 + Akta Cybersecurity 2024)

    Easy to miss without supervision, common reason novice testers cross legal lines unintentionally.

  • Time-to-first-cyber-role (realistic, honest)

    12-36 months: variance huge; many never finish.

MDEC PDTI degree (e.g. APU BSc Cyber Security, MMU, Taylor's, Sunway)

  • Format

    Full-time MQA-accredited 3-year undergraduate degree at an MDEC Premier Digital Tech Institute.

  • Best for

    School leavers (post-STPM / A-Level / Foundation) wanting the full academic foundation plus internship pipeline.

  • Typical cost (MYR)

    RM 60,000-120,000 total tuition (3 years) at MDEC PDTI private universities; PTPTN loan available; partial scholarship via MDEC, Yayasan, or institutional.

  • Certifications targeted

    Bachelor's degree (BSc Cyber Security / Computer Forensics / Information Security); industry certs typically pursued in final year or post-graduation.

  • Legal-scope discipline (Akta Jenayah Komputer 1997 + Akta Cybersecurity 2024)

    Compulsory subject within the MQA-accredited syllabus.

  • Time-to-first-cyber-role (realistic, honest)

    3 years to graduate + internship; typical first role within 0-6 months of graduation if internships are landed during study.

Levels & Exam Systems

Where ethical hacking sits in the MY cybersecurity pathway

SPM ICT/CS → Diploma Cybersecurity → BSc CyberSec → CEH/OSCP junior pentester → Senior security engineer.

  1. 01

    SPM Sains Komputer 4571 / ICT

    KSSM Sains Komputer subject covers basic networking, programming logic, computational thinking, the entry hook for cybersecurity interest.

  2. 02

    Diploma Cybersecurity / Pra-U IT

    3-year diploma at APU, Asia Pacific University, Politeknik METrO. CompTIA Security+ foundation. Or A-Level Computer Science / STPM ICT.

  3. 03

    BSc Cybersecurity / Computer Science

    UM Computer Science, UTM Cyber Security, APU Forensic Computing, Taylor's Cybersecurity. CyberSecurity Malaysia (CSM) accredited curricula preferred.

  4. 04

    Junior Pentester / SOC Analyst (CEH / Security+)

    EC-Council CEH, CompTIA Security+, eJPT certifications. Entry roles RM3,500–6,000/month at CyberSecurity Malaysia, Maybank GTSO, Petronas SOC, BAE Systems MY.

  5. 05

    Senior Security Engineer / Red Team (OSCP / OSCE)

    Offensive Security OSCP, OSCE, OSEP, OSWE certifications. RM10,000–25,000/month at MNC red teams, MyCERT incident response, private bug bounty professional.

FAQ

Frequently Asked Questions

Common questions from Malaysian career-switchers, fresh graduates and working professionals about ethical hacking and cybersecurity training.

Next step

Start Ethical Hacking & Cybersecurity training with Edustar

Free needs assessment + cert-specialist coach matched within 1-3 days. Security+ SY0-701, CEH v13, OSCP / PEN-200 and CISSP specialists, nationwide in-person or online, aligned to Akta Cybersecurity 2024 and BNM RMiT.

  • Free needs assessment + honest cert-pathway briefing
  • Coach matched by cert (Security+ SY0-701, CEH v13, OSCP / PEN-200, CISSP, ISACA CRISC / CISM / CISA)
  • Written Rules of Engagement on every lab, Akta Jenayah Komputer 1997 + Akta Cybersecurity 2024 compliance from day 1
  • BNM RMiT, NIST CSF 2.0 and ISO/IEC 27001:2022 fluency built in
  • Private GitHub portfolio + sanitised HackTheBox / TryHackMe writeups for interview readiness
  • HRD Corp SBL-Khas claim support for eligible adult learners
  • Home or online: nationwide

Edustar — Malaysian private tuition, KPM-aligned tutors.