How will Hong Kong’s critical infrastructure cybersecurity regime affect your business?
Introduction
On 1 January 2026, Hong Kong’s long-anticipated Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) (“PCICSO”) and its accompanying Code of Practice came into force, creating a dedicated statutory cybersecurity regime for operators of critical infrastructure in Hong Kong. The framework moves the city from largely voluntary controls to legally enforceable obligations around governance, technical safeguards, and incident response for key computer systems that underpin essential services. We covered the Bill of PCICSO in our March 2025 article, ‘Key insights on the Protection of Critical Infrastructures (Computer Systems) Bill’.
What the Ordinance is trying to achieve
PCICSO’s core objective is to reduce the risk that cyberattacks on critical computer systems disrupt essential services and, by extension, the day‑to‑day functioning of Hong Kong society. It does this by imposing statutory duties on designated critical infrastructure operators (“CIOs”) to adopt appropriate organisational, preventive, and incident‑response measures for their covered systems.
The Ordinance is overseen by the Commissioner of Critical Infrastructure (Computer‑system Security) (the “Commissioner”), under the Security Bureau, and supported by designated authorities such as the Communications Authority (“CA”) and the Hong Kong Monetary Authority (“HKMA”) for sectors within their remit.
Who is in scope
The regime focuses on “critical infrastructures” that provide services essential to Hong Kong, including energy, information technology, transport (air, land and maritime), finance, healthcare, and telecommunications and broadcasting. It also extends to major sports and performance venues and research and development parks, reflecting the broader economic and social importance of these facilities.
Within those sectors, specific operators may be designated as CIOs and then become subject to the obligations under the Ordinance and Code of Practice (the “Code”). Even organisations that are not formally designated are encouraged to use the Code as a benchmark for strengthening their own cybersecurity posture and resilience.
Three categories of statutory obligations
PCICSO groups CIOs’ duties into three broad categories:
Category 1 – Organisational: duties include maintaining an office in Hong Kong, notifying changes (i.e. change in ownership) in the operator of the critical infrastructure, and establishing a dedicated computer‑system security management unit overseen by suitably qualified staff.
Category 2 – Preventive: duties include notifying material changes to critical computer systems (“CCSs”), putting in place and implementing a formal computer‑system security management plan, and conducting regular security risk assessments and system security audits.
Category 3 – Incident reporting and response: duties include taking part in security drills, maintaining and implementing an emergency response plan, and reporting qualifying computer‑system security incidents to the Commissioner within prescribed timeframes.
Non‑compliance with these statutory obligations, or with directions issued by the Commissioner, is a criminal offence that can attract significant fines, ranging from HKD 300,000 up to HKD 5 million, with daily penalties for continuing breaches.
The role and status of the Code of Practice
The Commissioner has issued a Code under section 8 of PCICSO to provide practical guidance on how CIOs can satisfy their category 1, 2 and 3 obligations in concrete, operational terms. The Code is not subsidiary legislation, and failing to follow it is not, by itself, a criminal offence; however, it will be a key reference point for supervisory expectations and for any enforcement directions.
Designated authorities such as the CA and HKMA may formally adopt the Code for category 1 and 2 obligations in their sectors and can issue additional sector‑specific codes to tailor requirements to particular risk profiles. In practice, CIOs are expected to treat the Code as the baseline against which their policies, controls and incident‑response capabilities will be assessed.
What counts as a “Critical Computer System”
A computer system that is accessible by a CIO in or from Hong Kong and is essential to the core function of a designated critical infrastructure can be designated as a CCS. The Code provides indicators to guide this assessment, including the system’s importance to essential services, the severity of impact if it is disrupted, whether it processes sensitive digital data, and its dependencies with other CIOs or other CCSs.
Crucially, the Code makes clear that operational technology such as supervisory control and data acquisition systems, distributed control systems and programmable logic controllers are treated as computer systems and may therefore be CCSs. Underlying IT infrastructure components, such as network devices, operating platforms, middleware, Internet‑of‑Things devices and power backup systems, may also be regarded as part of a relevant computer system for regulatory purposes.
Governance, planning, and supplier management
On the organisational side, the Code clarifies that maintaining an office in Hong Kong means having real business operations here, not merely a correspondence address. The security management unit’s supervising employee must have appropriate professional qualifications and experience in computer‑system security, aligned with the risk profile of the CCSs.
For preventive controls, CIOs must prepare a comprehensive security management plan that addresses governance, policies and standards, risk management, access control, supplier and cloud service contracts, and staff training, among other matters. The plan must be approved at Board or equivalent senior level and reviewed at least every two years or after significant changes, with security risk assessments typically performed annually and system security audits every two years.
The Code places particular emphasis on supply chain and cloud security, requiring CIOs to ensure that suppliers and cloud providers contractually adhere to specified security requirements, including confidentiality protections and clearly defined shared responsibilities for CCS security.
Incident reporting and drills
When a CCS is affected by a cybersecurity incident, CIOs must notify the Commissioner within strict timelines. Serious incidents that have disrupted, are disrupting or are likely to disrupt the core function of the critical infrastructure must be reported within 12 hours of the CIO becoming aware of them, while other notifiable incidents must be reported within 48 hours.
While the mandatory reporting timeframe might be tight, yet not all incidents that affect critical computer systems need to be reported. The Code explains that a CIO is regarded as being “aware” once it has a reasonable degree of certainty that an incident has occurred, and it clarifies that certain events (such as pure technical failures, natural disasters, mass power outages, or personal data leaks arising solely from human error) do not count as notifiable computer‑system security incidents. CIOs are also expected to participate in security drills organised by the Commissioner, which test the effectiveness of their emergency response plan and staff readiness without requiring live deployment of production CCSs.
Practical implications for organisations
For organisations that are, or may become, designated CIOs, PCICSO and the Code require a structured, well‑resourced compliance programme rather than ad hoc cybersecurity measures. That will typically involve establishing or upgrading governance structures, mapping and designating CCSs, formalising security management plans and emergency response plans, and embedding regular risk assessments, audits and drills into business as usual operations.
Even entities outside the formal scope, particularly suppliers and cloud providers to CIOs, are likely to feel the effects through enhanced contractual requirements and higher expectations around cybersecurity standards and incident handling. Against this backdrop, organisations should review their current arrangements, benchmark them against the Code, and, where appropriate, seek legal and technical advice to ensure they are prepared for regulatory scrutiny under Hong Kong’s new critical infrastructure cybersecurity regime.
For enquiries, please feel free to contact us at: |
|
E: technology@onc.hk T: (852) 2810 1212 19th Floor, Three Exchange Square, 8 Connaught Place, Central, Hong Kong |
|
Important: The law and procedure on this subject are very specialised and complicated. This article is just a very general outline for reference and cannot be relied upon as legal advice in any individual case. If any advice or assistance is needed, please contact our solicitors. |
|
Published by ONC Lawyers © 2026 |




