Regulatory Update

The Hong Kong Cyber Security Division (CSD), under the Government Information Security Office (GISO), has published updated guidelines for cybersecurity practices at Critical Information Infrastructure (CII) operators.

Key Changes

  • Enhanced incident reporting: CII operators must report significant cybersecurity incidents to CSD within 24 hours (previously 72 hours)
  • AI security requirements: New guidelines for organisations deploying AI systems in critical operations
  • Supply chain security: Mandatory assessment of third-party vendor security practices
  • Penetration testing: Requirement for annual penetration testing by accredited assessors
  • Board-level accountability: Cybersecurity to be included as a standing agenda item at board meetings

Sector Coverage

The updated guidelines apply to operators in the following critical sectors:

  • Financial services
  • Healthcare
  • Energy and utilities
  • Transportation
  • Telecommunications
  • Government services

Timeline

Organisations are expected to achieve compliance within 18 months of publication. CSD will be conducting outreach sessions and providing implementation guidance throughout the transition period.

HKISG Guidance

Hong Kong organisations in regulated sectors should review the updated guidelines immediately and begin gap analysis against current security practices. HKISG will be hosting a specialist briefing session in July 2026.

Hong Kong operator checklist

  1. Confirm whether the systems, vendors, or practices described apply to your estate.
  2. Assign an owner and a review date — do not leave findings as unread newsletter content.
  3. Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
  4. Brief leadership with a dated one-page note when residual risk remains high.

What “good” looks like

  • Controls are operated, not only documented
  • Privileged access uses phishing-resistant MFA where feasible
  • Detection and response paths are exercised at least annually
  • Third-party dependencies have an owner and an exit plan

Sources and further reading

Editorial note

This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.

Frequently asked questions

Who should read this?

Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims.

Does this change any public HKISG rating?

No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.

How often is this content reviewed?

HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.