EXECUTIVE PROFILE · CYBERSECURITY · TECHNOLOGY RISK

Risk. Resilience.
Governance that moves.

Cybersecurity, technology risk and regulatory compliance translated into clear decisions, stronger controls and resilient business outcomes.

Ts. Khairul Nadzmi bin Mohd Yusof

Head of Cybersecurity Compliance · Technology Risk · Governance, Risk & Compliance Leader

20+Years experience
6Industry sectors
9Professional credentials
Khairul Nadzmi in a black suit and glasses

Turn complex cyber risk into governance decisions leaders can act on.

IMPACT AT A GLANCE

Built across regulators, financial services, telecoms and national cyber initiatives.

1.5 LoD

Independent Oversight

Cyber compliance, technology risk and control effectiveness oversight in a governance-focused operating model.

2017-Now

Community Leadership

Co-Founder and Executive Committee member of rawSEC / Malaysian Cybersecurity Community Organization.

National

Cyber Ecosystem

Experience spanning sector coordination, regulatory engagement, cyber resilience and capability development.

End-to-End

Risk to Resilience

From technical security operations and assurance to enterprise governance, strategy and executive advisory.

WHAT THE BOARD & C-SUITE NEED

Security without the fog.

Governance that makes cyber and technology risk understandable, defensible and actionable at executive level.

01

Cyber & Technology Risk Oversight

Independent challenge, risk assessment and governance reporting that surface systemic control gaps and enable informed risk decisions.

02

Regulatory & Control Assurance

Compliance and control-effectiveness programmes aligned to regulatory and industry requirements, including RMiT, SWIFT CSCF, NCSB and CGSO expectations.

03

Cyber Resilience & Transformation

Governance frameworks, remediation strategies and enterprise programmes that strengthen security maturity while supporting business change.

04

Data Security & Protection

Enterprise data governance, privacy and protection translated into practical controls across business operations, cloud platforms and third parties.

LEADERSHIP PHILOSOPHY

Clarity. Accountability. Resilience.

01

Governance with clarity

Make risks visible in business language so leaders can make timely, evidence-based decisions.

02

Assurance that enables

Use independent oversight to improve control effectiveness without turning governance into unnecessary friction.

03

Resilience by design

Connect policy, people, technology and response capability so resilience is built into the operating model.

EXPERIENCE SNAPSHOT

Two decades across cybersecurity, risk, regulation and engineering.

2023-Present

Bank Negara Malaysia

Head of Cyber Compliance, Technology Governance

Leads cyber compliance within the 1.5 Line of Defence, covering governance, technology risk, compliance assurance, control effectiveness and executive risk insights.

2020-2023

Maxis Berhad

Data Security & Protection Senior Specialist, Cybersecurity Dept

Led data security, privacy, governance and cyber risk initiatives across business operations, cloud platforms and third-party ecosystems.

2018-2020

Johor Corporation

Senior Manager, Cybersecurity Division

Led group cybersecurity transformation, enterprise cyber risk management, standards and executive cyber risk reporting across JCorp and subsidiaries.

2018

KPMG

Manager, Information Protection & Business Resilience

Led cybersecurity, technology risk, business resilience and regulatory assurance engagements for financial institutions and large enterprises.

2011-2018

Securities Commission Malaysia

Manager, Technology Department

Led cybersecurity governance, technology risk oversight and incident coordination; established SC-CERT and represented the capital market sector in national cyber initiatives.

2008-2011

CyberSecurity Malaysia

Analyst, Secure Technology Services

Hands-on foundations in security operations, incident response

2008-2011

Syniverse

System Engineer

System support engineer for Celcom and RHB Core Banking

2008-2011

System Consultancy Services (SCS)

R&D Engineer, Special Project Division

Developed Malaysia's 1st UAV System and Integrated Communication System for Ministry of Defence (MINDEF)Malaysia

PROFESSIONAL CREDENTIALS

Security leadership grounded in professional practice.

2024

CISSP

Certified Information Systems Security Professional · ISC2

2024

CIPT

Certified Information Privacy Technologist · IAPP

2024

CASP+

CompTIA Advanced Security Practitioner · CompTIA

2024

PenTest+

CompTIA PenTest+ · CompTIA

2024

CySA+

CompTIA Cybersecurity Analyst · CompTIA

2021

CISM

Certified Information Security Manager · ISACA

2020

MBOT

Professional Technologies - CyberSecurity

2012

ISO 27001

IRCA ISO 27001:2013 Lead Auditor · BSI

2010

C|EH

EC-Council Certified Ethical Hacker v6

EDUCATION

Continuous learning, applied to real-world governance and compliance.

2025-2026 · Ongoing

Master of Science Cybersecurity

Universiti Kebangsaan Malaysia

2002-2006

Bachelor of Science Information Technology(hons)

Universiti Tenaga Nasional (UNITEN)

PROFESSIONAL LEADERSHIP

Growing Malaysia's cybersecurity ecosystem.

Co-Founder & Executive Committee, rawSEC / Malaysian Cybersecurity Community Organization (MCCO), 2017-Present.

FLAGSHIP PROGRAMMES
MINICONJURUSRECAPCTFMonthly Meetups

Strategic leadership across community capability development, national initiatives, partnerships, sponsorship engagement, branding and programme governance.

LET'S CONNECT

For executive conversations on cyber risk, resilience, governance and compliance.

Based in Kuala Lumpur, Malaysia.