Cybersecurity for Banks after the Critical Infrastructure Ordinance: Same Same, But Different

Sep 14 2026

First published in the July/August 2026 edition of Banking Today, the official publication of the Hong Kong Institute of Bankers (HKIB).

The thumbnail description of cybersecurity laws in Hong Kong before 2026 was that there was no cybersecurity law. This unflattering description was technically inaccurate, but it rang true for many industry sectors. The notable exception was the regulatory framework that the Hong Kong Monetary Authority (HKMA) has applied to Authorized Institutions for more than 10 years.

The Protection of Critical Infrastructure (Computer Systems) Ordinance (CI Ordinance) came into force on 1 January 2026. It is the first horizontal cybersecurity legislation in Hong Kong and applies to critical computer systems of designated critical infrastructure operators across a number of sectors, including banking and finance. What, then, has changed for Authorized Institutions under the regulatory oversight of the HKMA?

The position before the CI Ordinance

The cybersecurity of Authorized Institutions has been regulated by the HKMA under its risk-based supervisory framework as a core focus long before the implementation of the CI Ordinance. The regulatory policy and framework were first set out in the Cybersecurity Fortification Initiative which was introduced in 2016 and further enhanced in 2021. The Cybersecurity Fortification Initiative has three core pillars:

• the Cyber Resilience Assessment Framework;

• the Professional Development Programme; and

• the Cyber Intelligence Sharing Platform.

The Cyber-Resilience Assessment Framework (C-RAF) is a comprehensive, structured risk-based framework for banks to assess their risk profiles, and to benchmark the maturity and level of defence and resilience required to protect against cyber-attacks. C-RAF comprises:

a) an inherent risk assessment based on risk factors such as business size, operational characteristics, technology profile, and usage;

b) a maturity assessment for Authorized Institutions to assess whether their cybersecurity controls are commensurate with their inherent risk levels. The maturity assessment covers a number of domains, including:

• governance;

• protection;

• detection;

• response and recovery;

• situational awareness;

• third-party risk management; and

• identification.

c) Intelligence-led Cyber-attack Simulation Testing (iCAST) for Authorized Institutions with “medium” or “high” inherent risk ratings to test their cyber resilience by simulating reallife cyber-attacks.

The C-RAF is not a public document. However, based on other similar public framework documents, the C-RAF will likely include requirements to have internal policies and procedures such as:

• regular reporting to the board or senior management on the status of cybersecurity and business continuity programmes; routine penetration testing and vulnerability scanning;

• annual training and skills development of staff covering the latest cyber threats, issues, and incident response;

• well-defined playbooks for incident response and recovery steps; and

• escalation channels for prompt reporting of cyber events from any level of the organization.

The Professional Development Programme is a local certification scheme and training programme to train cybersecurity practitioners in the banking and information technology industries. The programme has a particular focus on technical capabilities for conducting cyber resilience assessments and simulation testing. The certification scheme recognises the equivalence of qualifications in major overseas jurisdictions.

The Cyber Intelligence Sharing Platform is a commonly shared intelligence platform to help share threat intelligence in the banking sector in respect of cyber-attacks.

The HKMA also facilitates and participates in industry-led cyber-attack simulations to enhance the sector’s collective preparedness against cyber incidents. The most recent example of this was the extreme weather scenario conducted as the Whole Industry Simulation Exercise (WISE) 2025.

Supervisory Policy Manual

The HKMA sets out its general policy in the Supervisory Approach to Cyber Risk Management (Module TM-C-1) of its Supervisory Policy Manual (Cyber Risk Management Guideline). The policy sets out the best practice and advisory standards and minimum regulatory expectations of the HKMA in respect of cyber risk management. The Cyber Risk Management Guideline is supplemented by additional statutory guidelines published in the “Supervisory Policy Manual on Technology Risk Management, Business Continuity, Operational Resilience and Outsourcing”.

The Cyber Risk Management Guideline and its related guidelines require Authorized Institutions to maintain governance arrangements, internal policies and procedures, incident response arrangements, escalation channels, audit, training, and board or senior management reporting. Critically, the Cyber Risk Management Guideline specifically incorporates C-RAF implementation and assessment.

The Cyber Risk Management Guideline is a statutory guideline issued by the HKMA. Statutory guidelines do not themselves have the force of law. However, failure to fulfil its requirements may lead to the HKMA forming the view that the Authorized institution is not meeting the minimum regulatory expectations of the HKMA to satisfy the minimum requirements for authorisation under the Banking Ordinance or other statutory obligations under the Banking Ordinance.

The CI Ordinance

The CI Ordinance came into operation on 1 January 2026. It created a dedicated statutory regime for protecting critical computer systems operated as part of critical infrastructure in Hong Kong. This changed the legal landscape in Hong Kong. Cybersecurity obligations for designated critical infrastructure operators became statutory obligations rather than regulatory expectations under sector-specific guidance.

The CI Ordinance established the Office of the Commissioner of Critical Infrastructure (Computer-system Security) under the Security Bureau (CI Commissioner). The CI Commissioner regulates operators of critical infrastructure in a number of sectors that have been expressly designated as critical for the delivery of essential services in Hong Kong. These sectors include the banking and financial services sector. The statutory obligations are organised into three categories:

1. Organisational obligations. These include maintaining an office in Hong Kong for carrying on its business in Hong Kong; notifying changes to the operator of critical computer systems; and establishing a computer-system security management unit.

2. Preventive obligations. These include notifying material changes to critical computer systems; implementing a computer-system security management plan; and conducting computer-system security risk assessments and computer-system security audits every two years.

3. Reporting and response obligations. These include participating in computer-system security drills conducted by the CI Commissioner; implementing an emergency response plan; and notifying the CI Commissioner of incidents within specified timeframes.

The CI Ordinance designates the HKMA as a “designated competent regulator” to directly supervise the responsibilities relating to organisational and preventive obligations under the CI Ordinance in respect of Authorized Institutions [1] designated by the HKMA as operators of critical infrastructure (CI Operators). The CI Commissioner will retain sole regulatory responsibility and authority for incident reporting and response obligations under the CI Ordinance. The CI Operators must still fulfil sector-specific reporting obligations of the HKMA in addition to the reporting obligations to the CI Commissioner.

Developments after the CI Ordinance effective date

Memorandum of Understanding

The HKMA entered into a Memorandum of Understanding (MoU) with the CI Commissioner on 29 May 2026 to ensure a coordinated approach to implementation work for which the

HKMA is a designated regulator, and to reduce the compliance burden for CI Operators where practicable. The key principles for co-operation under the MoU are:

• The HKMA and the CI Commissioner will notify and consult each other prior to issuing a written direction to a CI Operator for non-compliance with obligations under the CI Ordinance.

• The HKMA and the CI Commissioner will consult each other prior to the issue of or changes of any codes of practice.

• The HKMA and the CI Commissioner will keep each other informed on the designation or revocation of CI Operators and critical computer systems.

• The HKMA will provide assistance to the CI Commissioner regarding the CI Commissioner’s function of monitoring the reporting of computer-system security incidents by CI Operators. This is specifically limited to streamlining compliance by the CI Operators with overlapping obligations under the CI Ordinance and the Banking Ordinance.

• The HKMA will provide assistance to the CI Commissioner to respond to computer-system security threats or incidents in connection with CI Operators, particularly where threats or incidents may impact multiple sectors.

• The HKMA and the CI Commissioner will co-operate with each other in the investigation and prosecution of potential offences committed by CI Operators.

• The CI Commissioner will inform the HKMA prior to performing any function in respect of a specified critical infrastructure regulated by the HKMA.

• The CI Commissioner and the HKMA may share with each other information obtained under the CI Ordinance to avoid making duplicate information requests.

• The CI Commissioner and the HKMA will consult each other in advance on public communications matters relating to their performance of their respective functions under the CI Ordinance to ensure consistency and clarity in public messaging.

The purpose of the MoU is to address the risk of duplication of effort and resources both by regulators and by CI Operators. Inevitably, though, there is an increased compliance burden.

HKMA Sectoral Code of Practice

The CI Commissioner published a General Code of Practice on 1 January 2026 (General Code). On 2 June 2026, the HKMA published a Code of Practice for Authorized Institutions designates as CI Operators (HKMA Code). The HKMA Code is not subsidiary legislation, and failure to comply with its provisions would not in itself constitute an offence. However, the HKMA may issue written directions to require CI Operators to take appropriate actions in relation to compliance with organisational and preventive obligations in the HKMA Code. Failure to comply with those directions would be an offence.

The HKMA Code translates the obligations under the General Code into banking sector implementation expectations. Sometimes, the HKMA clarifies its regulatory expectation. For instance, the HKMA requires separate notification of the office in Hong Kong of the CI Operator of the CI Ordinance, even though the office may have been separately notified under the Banking Ordinance. Also, organisation restructuring and transfer of the banking licence are specifically identified by the HKMA as a change of operator event, and the CI Operator must notify the HKMA of these changes for the purpose of the CI Ordinance. Mostly, the HKMA’s approach is to correlate the obligations in the General Code to existing obligations of the CI Operator under the Supervisory Policy Manual or other HKMA guidance, or under relevant control principles outlined in the applicable C-RAF maturity assessment matrix sub-domain.

The HKMA Code is broadly divided into sections addressing the HKMA designation process, the organisational obligations overseen by the HKMA and the preventive obligations overseen by the HKMA. The HKMA Code expressly excludes reporting and response obligations under the CI Ordinance as the HKMA has no direct regulatory authority to oversee and regulate those obligations under the CI Ordinance. The HKMA also published template notification forms. In practice, CI Operators designated by the HKMA must integrate these new processes into existing HKMA supervisory channels, including their usual supervisory contacts and technology risk teams.

AI cyber threat landscape

A further post-commencement development is the HKMA’s circular on strengthening cyber resilience amid AI-empowered cyber threats, issued on 2 June 2026. This circular highlights the recent emergence of increasingly capable frontier AI models that mark a step change in the global cyber risk landscape, particularly the capacity to independently identify and exploit zero-day vulnerabilities in critical software and infrastructure.

The circular sets out the regulatory expectation of the HKMA for Authorized Institutions generally to review and assess the sufficiency of existing cyber defence controls, improve incident response and recovery capabilities, and enhance data resilience to counter destructive cyber attacks.

The circular also provided an update on the development of the Cyber Resilience Testing Framework (CRTF). This is a new supervisory framework that will provide Authorized Institutions with a systematic method to stress test their ability to respond to and recover from actual “breach” situations. It augments and complements existing cyber initiatives by extending cyber resilience capabilities from detection and prevention-based approaches to those oriented also around response and recovery.

This is an example of a thematic circular from the HKMA that is addressed to all Authorized Institutions, and which is of particular relevance to CI Operators. Notably, the circular was published on the same date as the publication of the HKMA Code.

Concluding thoughts

By the time of implementation of the CI Ordinance, the banking sector had almost 10 years of experience under the Cybersecurity Fortification Initiative of the HKMA. As a consequence, Authorized Institutions were already substantially fulfilling many of the obligations under the CI Ordinance. CI Operators can have cautious optimism that their designation by the HKMA will not cause a seismic shift in either their compliance obligations to the HKMA for organisational and preventive obligations under the CI Ordinance, or in the risk-based approach they adopt based on prior HKMA requirements. It is, in effect, a continuation and evolution of their prior regulatory position.

The most substantial change for CI Operators will be their new response and reporting obligations under the direct regulatory authority of the CI Commissioner [2] These are supplementary to any overlapping obligations that may be owed to the HKMA under sector-specific regulations. This will require a new relationship with a new regulator, and new processes and procedures (and training and awareness) for the relevant notification, reporting, and response obligations. Even so, the CI Operators can expect to be generally well-prepared to meet those obligations. The 12-hour and 48-hour notification obligations to the CI Commissioner are not as onerous as the regulatory expectations of the HKMA for Authorized Institutions. It should be possible to meet and fulfil those obligations concurrently, albeit through different communication channels.

Perhaps the most significant change for CI Operators is less what has happened to date, and more what lies ahead. Hong Kong now has a statutory framework and dedicated regulator for the protection of critical computer systems of CI Operators. We can expect that there will be further specific codes of practice and other guidance and circulars from the CI Commissioner, which will be adapted and adopted by the HKMA as a designated regulator. These are likely to focus on core topics such as services supply-chain risk, artificial intelligence, risk assessment frameworks, and more granular, specific risk controls. We will also learn from enforcement actions brought by the CI Commissioner and from the case law and legal principles that emerge from prosecutions under the CI Ordinance.

The introduction of the CI Ordinance is a significant step forward that improves the security of critical infrastructure necessary for the delivery of essential services in Hong Kong. For the banking sector, that journey had already started, and Authorized Institutions are well aware that there is a long road ahead.

Pádraig Walsh

If you want to know more about the content of this article, please contact:

Pádraig Walsh

Partner | [email protected]

Disclaimer: This article is general in nature and is not intended to constitute legal advice. You should seek professional advice before taking any action in relation to the matters dealt with in this article. This article was last reviewed on [14 September 2026].


[1] The designation of the HKMA applies in respect of its role as regulator of Authorized Institutions, stored value facility licensees, and system operators or settlement institutions for designated clearing and settlement or retail payment systems. The primary focus of this article is on Authorized Institutions.

[2] CI Operators will also need to be aware of, and prepared for, the enforcement powers of the CI Commissioner. This is outside the scope of this article.

Tags:

Legal Updates TMT

Featured Articles

Insights
Another post-Re USUM decision: Hong Kong Court grants disclosure relief in aid of BVI liquidation
Insights
Cybersecurity for Banks after the Critical Infrastructure Ordinance: Same Same, But Different
Insights
News update: Hong Kong moves closer to a full virtual asset services regime
Insights
News update: SFC circular sets cybersecurity measures against AI-enabled cyberattacks
Insights
Hong Kong Court’s first recognition of Bahamian liquidation after landmark case Re USUM
Insights
News update: No phishing here – The SFC raises cybersecurity expectations for internet brokers and virtual asset trading platforms