Mandatory National Drill

Are You Ready for NACSA'sOctober 2026 OT Security Drill?

Malaysia's first national Operational Technology security drill is coming. CID is an official national security preparation partner.

--
Days
--
Hours
--
Minutes
--
Seconds

Time until October 2026 drill

The Reality: Most Organizations Are NOT Ready

79% of Malaysian OT systems are vulnerable

NACSA has mandated the first-ever national OT security drill for all NCII operators. This is not optional—it's mandatory for organizations with:

SCADA (Supervisory Control and Data Acquisition)
ICS (Industrial Control Systems)
PLC (Programmable Logic Controllers)
DCS (Distributed Control Systems)
Building Management Systems
Manufacturing control systems
Energy grid controls
Water treatment controls
Oil & gas pipeline controls

Why This Drill Matters

Unlike IT systems, OT systems control physical infrastructure

Manufacturing

Lines shut down - millions in losses per hour

Power Grids

Blackouts affecting millions of people

Water Treatment

Public health crisis

Pipelines

Environmental disasters

Hospitals

Patient safety at risk

This isn't about compliance. It's about national security, public safety, and operational continuity.

The CID Advantage

Official National Security Partner

National Security Partner

Officially recognized as a national security preparation partner—few organizations can claim this.

OT Security Expertise

34 years of security experience via CF Group, with specialized OT capabilities across critical sectors.

Proven Methodology

4-phase approach ensures drill readiness: Discovery, Hardening, Preparation, and Drill Support.

End-to-End Services

From initial assessment to post-drill remediation—we cover everything you need.

The 18-Month Preparation Timeline

Don't wait. Start now.

Start in Q1 2025 → Be drill-ready by September 2026

Start in Q3 2025 → Likely to struggle

Start in 2026 → You WILL fail

Who Must Participate?

All NCII Operators with OT Systems

Energy

TNB, Petronas, IPPs, gas distribution, renewables

Water & Utilities

State water authorities, sewage, waste management

Manufacturing

Semiconductors, chemicals, pharma, F&B, automotive

Transportation

Rail systems, ports, airports, traffic management

Healthcare

Major hospitals with BMS, medical equipment OT

If your operations would impact national security, economy, public health, or safety when disrupted—you MUST participate.

Free 60-Point OT Readiness Assessment

Assess your current OT security posture, identify critical gaps, and create your preparation timeline.

Start Assessment

OT Drill Preparation Services

Complete solutions from discovery to drill day

OT Quick Start Assessment

RM 80,000

Timeline: 2 weeks

Best for: Small-medium NCII entities, budget-conscious organizations

  • 2-week OT discovery and inventory
  • Basic vulnerability scanning
  • Executive briefing presentation
  • High-level remediation roadmap
Request Quote
Most Popular

Drill Ready Program

RM 350,000

Timeline: 9-12 months

Best for: Mid-sized critical infrastructure operators

  • Full OT assessment (4 weeks)
  • Security hardening implementation (3 months)
  • 2 tabletop exercises
  • 1 full mock drill
  • On-site support during actual drill
  • 30-day post-drill support
Request Quote

OT Transformation

RM 1,200,000+

Timeline: 18 months

Best for: Large power plants, major manufacturers, national infrastructure

  • Comprehensive OT security transformation
  • Network redesign and segmentation
  • 24/7 OT SOC implementation
  • 12-month preparation program
  • Full drill support team
  • 6-month post-drill managed services
  • Ongoing OT monitoring and support
Request Quote

Need a custom solution? Contact us for tailored preparation programs.

Partner Success Stories

How we've prepared critical infrastructure

Regional Power Plant

Challenge:

25-year-old SCADA system, no OT security, 8 months until drill

Solution:

Rapid assessment, emergency network segmentation, OT monitoring deployment, intensive training

Result:

Successful drill completion, zero critical findings, now a national security best practice example

Timeline: 8 monthsRM 680,000

Water Treatment Facility

Challenge:

Multiple sites, mixed vendors, legacy PLCs, limited budget

Solution:

Phased approach focusing on highest-risk sites, cost-effective segmentation, centralized monitoring

Result:

Passed drill at all locations, 40% reduction in cyber risk, ongoing monitoring partnership

Timeline: 12 monthsRM 420,000

Manufacturing Plant

Challenge:

Production-critical OT, zero downtime tolerance, multinational compliance requirements

Solution:

Zero-downtime hardening, passive monitoring deployment, extensive simulation training

Result:

Exemplary drill performance, production never interrupted, model for other facilities

Timeline: 16 monthsRM 1.4 million

Frequently Asked Questions

NACSA's mandatory national exercise for all NCII operators with Operational Technology systems. It will test your ability to detect, respond to, and recover from OT cyber incidents.

All NCII entities with OT systems—power plants, water facilities, manufacturing plants, transportation systems, hospitals with BMS, and other critical infrastructure.

October 2026. Exact dates to be announced by NACSA.

Minimum 12 months, ideally 18 months. Organizations starting in 2026 will likely struggle or fail.

Penalties up to RM500K under Act 854, operational restrictions, mandatory remediation, additional oversight, and potential criminal liability for executives.

Technically yes, but OT security requires specialized expertise. Most organizations lack internal OT security capabilities. Partnering with experts like CID significantly increases success probability.

RM 80K - RM 1.2M+ depending on complexity, number of sites, and current security posture. Much less than the cost of failure.

We're an official national security preparation partner with 34 years of security experience, proven OT expertise, and a track record across Malaysian critical infrastructure.

Yes! The sooner you start, the better prepared you'll be. Contact us for a free consultation.

Yes. Under Act 854, NCII entities must participate. Non-participation or failure can result in severe penalties.

The Cost of NOT Preparing

What happens if you fail the drill?

Financial

Up to RM500,000 in penalties

Operational

Mandatory restrictions & oversight

Reputational

Public disclosure of failures

Legal

Up to 10 years imprisonment

Preparation costs RM350K - RM1.2M

Failure costs MILLIONS + reputational damage

Don't Wait Until It's Too Late

The October 2026 deadline is fixed. Your preparation timeline is not.

📧 otdrill@cidcyber.com.my | 📞 Contact us for immediate assistance

Central Intelligence Department (CID) - Official National Security OT Drill Preparation Partner. Part of CF Group - 34 Years of Security Excellence.