Hong Kong’s Protection of Critical Infrastructures (Computer Systems) Ordinance comes into force today, its first dedicated cyber security legislation.
Key points
- Designated operators must maintain a computer-system security management unit.
- Security risk assessments and audits are required.
- Serious incidents must be reported within 12 hours and other incidents within 48 hours.
- Operators must take part in security drills and submit emergency response plans.
- Fines reach HK$5 million.
UK organisations supplying technology or services to Hong Kong critical operators, including banking, energy and telecoms, should expect security requirements to flow into contracts.
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.