PILLAR 3 · CYBER VALIDATION
Prove it before the auditor asks.
Nebula Systems provides vulnerability assessment and penetration testing in Malaysia through its Schrodinger brand. Licensed by NACSA for penetration testing under the Cyber Security Act 2024. The consequence: findings you can hand to a regulator, a customer, or a board.
SERVICES
Test it, assess it, harden it.
FIND
Vulnerability assessment
Scheduled VA across infrastructure and applications, findings ranked with context, not raw scanner output.
FIND
Penetration testing
Licensed by NACSA under the Cyber Security Act 2024. Scoped, executed, and reported by named testers.
ASSESS
Compliance assessment
Gap analysis against PDPA, RMiT, and the frameworks your regulator or customer names.
HARDEN
Pre-deployment hardening
New infrastructure reviewed and hardened before it faces traffic, not after the first incident.
NACSA LICENSED
Licensed by NACSA for penetration testing under the Cyber Security Act 2024. For NCII entities that licence is a procurement requirement. For everyone else it is the difference between a test and a claim.
HOW IT RUNS
Find. Fix. Verify. Repeat.
A finding without a retest is a to-do list. Every engagement closes the loop: findings ranked by severity, fixes made by your team or ours, and a verification pass that states what is now closed. The report is written for three readers: your engineer, your auditor, and your board.
WHEN IT MATTERS
Three moments this gets bought.
The audit is in eight weeks
Assess against the framework now, fix on a ranked list, and walk in with the retest report instead of promises.
A customer sent a security questionnaire
A recent penetration test from a NACSA licensed provider answers half the document on page one.
Something new is going live
Pre-deployment hardening costs a week. The incident it prevents costs the quarter.
FAQ
What buyers ask.
Why does the NACSA licence matter for testing?
Penetration testing under the Cyber Security Act 2024 is a licensed activity. For NCII entities, using a licensed provider is a procurement requirement. For everyone else, it separates a test from a claim.
Will testing break production?
Scope and rules of engagement are agreed in writing before anything runs. Destructive techniques are off by default and only used in isolated environments.
Who fixes the findings?
Your team, ours, or both. Findings arrive ranked with remediation steps. The retest verifies closure either way.
How often should we test?
Assess continuously, test at least annually and after major changes. Regulated entities usually have the cadence set for them; we align to it.
Does an assessment make us compliant?
No assessment makes you compliant by itself. It shows where you stand against your obligations and gives you the ranked path to close the gaps. The obligations stay yours.
NEXT STEP
Name the deadline. Audit, launch, or renewal.
A specialist replies on the next business day.