A Conceptual Framework for OT/ICS Cybersecurity Governance in Malaysian Manufacturing Environments Under Industry 4.0

OT/ICS Cybersecurity IT/OT Convergence Industrial Control Systems Cybersecurity Governance Malaysian Manufacturing SDG 9

Authors

Vol. 10 No. 2 (2026)
Original Research
August 21, 2026
August 28, 2026

Downloads

The convergence of Information Technology (IT) and Operational Technology (OT) in Malaysian manufacturing environments has created a cybersecurity governance problem that existing frameworks were not designed to solve. Malaysia's manufacturing sector contributes 24.5% of national GDP (EPU, 2022) and is overwhelmingly made up of small and medium-sized enterprises (SMEs) that typically have no dedicated security function at all, let alone one capable of addressing OT/ICS-specific threats. The situation has become more urgent following the enactment of the Cyber Security Act 2024, which places binding legal obligations on critical infrastructure entities but provides no OT/ICS-specific operational guidance for manufacturers. This paper proposes the Malaysian Industrial Cybersecurity Governance Framework (MICGF), a five-pillar governance model developed through Design Science Research (DSR) methodology. The framework draws on IEC 62443, NIST SP 800-82 Revision 3, and NIST CSF 2.0, and contextualises these international standards within Malaysia's regulatory and industrial environment, including the National Cybersecurity Policy 2020, the Industry 4WRD Policy, the MyDIGITAL blueprint, and the Cyber Security Act 2024. The MICGF makes three contributions that no existing international standard provides: it aligns OT/ICS governance requirements with the full Malaysian regulatory stack; it introduces a three-tier SME implementation model providing resource-proportionate entry points for manufacturers with no dedicated security function; and it elevates workforce capability development to a co-equal governance pillar. The five pillars are: Asset Visibility and Classification, Network Architecture and Segmentation, Threat Detection and Incident Response, Governance Integration and Policy Alignment, and Workforce Capability Development. Each pillar operates across three capability tiers to accommodate the wide range of resource levels among Malaysian manufacturers. The framework was evaluated through a multi-layer non-contact validation approach comprising standards traceability mapping, comparative benchmark analysis, and scenario-based threat modelling across three documented OT/ICS attack patterns.