Don’t do SECURITY. Do business SECURELY.

Hong Kong’s critical infrastructure cyber security law takes effect

Hong Kong’s first cyber security law now requires designated critical infrastructure operators to manage cyber risks and report incidents.

Hong Kong’s Protection of Critical Infrastructures (Computer Systems) Ordinance comes into force today, its first dedicated cyber security legislation.

Key points

  • Designated operators must maintain a computer-system security management unit.
  • Security risk assessments and audits are required.
  • Serious incidents must be reported within 12 hours and other incidents within 48 hours.
  • Operators must take part in security drills and submit emergency response plans.
  • Fines reach HK$5 million.

UK organisations supplying technology or services to Hong Kong critical operators, including banking, energy and telecoms, should expect security requirements to flow into contracts.

Source: Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653 (Hong Kong e-Legislation)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights