Hong Kong: Protection of Critical Infrastructures (Computer Systems) Ordinance including cybersecurity regulation introduced to Legislative Council

Description

Protection of Critical Infrastructures (Computer Systems) Ordinance including cybersecurity regulation introduced to Legislative Council

On 6 December 2024, Protection of Critical Infrastructures (Computer Systems) Ordinance (Ordinance No. 4 of 2025) including cybersecurity regulation was introduced to the Legislative Council. The Ordinance would establish cybersecurity obligations for operators of critical infrastructures, including infrastructure that is essential to the continuous provision of certain essential services or which, if damaged, would hinder or substantially affect critical societal or economic activities in Hong Kong. Critical infrastructure operators would be required to set up a computer-system security management unit, conduct systemic risk assessments and security audits, participate in security drills, and implement an emergency response plan. Further, operators would need to notify security incidents within 48 hours of becoming aware of them in general, and within 12 hours if the incident entails disruptions to the core functions of the critical infrastructure. Operators who fail to do so can be liable for HKD 3 million on summary conviction and HKD 5 million on conviction on indictment.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: internet and telecom services, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
Implementation Level
national
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2024-12-06
under deliberation

On 6 December 2024, Protection of Critical Infrastructures (Computer Systems) Ordinance (Ordinance …

2025-03-19
adopted

On 19 March 2025, Protection of Critical Infrastructures (Computer Systems) Ordinance (Ordinance No…

2025-03-28
in grace period

On 28 March 2025, the Legislative Council's Protection of Critical Infrastructures (Computer System…

2026-01-01
in force

On 1 January 2026, the Legislative Council's Protection of Critical Infrastructures (Computer Syste…