To strengthen Hong Kong’s resilience against the growing global threat of cyberattacks, the Protection of Critical Infrastructure (Computer Systems) Bill was passed by the Legislative Council on March 19, 2025, and will take effect on January 1, 2026. The legislation, developed jointly by the Security Bureau, the Digital Policy Office, and the Hong Kong Police Force, establishes statutory requirements for safeguarding Critical Computer Systems (CCS) across key infrastructure sectors.
This white paper helps critical infrastructure (CI) operators understand the new legal framework and how to prepare for compliance. It:
By bridging the legislative requirements with international best practices, the paper provides practical guidance for CI operators to implement robust, systematic cybersecurity management.