top of page

Critical Infrastructure Cybersecurity Law: Why SMEs Should Still Pay Attention

  • Aug 5
  • 11 min read

With the Protection of Critical Infrastructure (Computer Systems) Ordinance now in effect, the requirements for enterprises' supply chains, outsourced IT, and incident response may gradually change.


New cybersecurity regulations for critical infrastructure in Hong Kong and their impact on SMEs

Your company may not be a bank, power company, telecommunications provider, or hospital, and you may not have received any designation notice from the government.


So, is the Protection of Critical Infrastructure (Computer Systems) Ordinance, which officially came into effect on January 1, 2026 , completely irrelevant to ordinary SMEs?


From a legal perspective, the ordinance primarily regulates designated critical infrastructure operators and critical computer systems. The government has also clearly stated in its official legislative purpose and principles that the regulated entities are mainly large institutions, while SMEs and ordinary citizens are not directly affected.


However, this does not mean that SMEs do not need to pay attention at all.


As banks, healthcare institutions, telecommunications companies, transportation operators, and other large organizations begin to strengthen their network security management, they may also re-examine the security measures of outsourced IT companies, software vendors, cloud service providers, and other partners.


Even if your company is not directly regulated by the ordinance, the relevant requirements may still gradually reach other businesses through supplier vetting, tender documents, customer questionnaires, and contract terms.


Although the critical infrastructure cybersecurity law mainly regulates designated operators and critical computer systems, its requirements may also affect SMEs through vendor assessments, contract terms and supply-chain expectations.


What exactly does this ordinance protect?


Key infrastructure refers to facilities that are essential for maintaining the normal operation of society and the lives of citizens.


If the computer systems of these facilities are attacked, it may not only affect the daily operations of a single company, but could also trigger a chain reaction, impacting public services, economic activities, people's livelihoods, and even public safety.


According to the scope and targets of regulation announced by the Commissioner's Office, the ordinance covers two major categories of key infrastructure.


The first category is infrastructure that continues to provide essential services in Hong Kong, involving eight sectors:

  • energy

  • Information Technology

  • Banking and financial services

  • Air transport

  • land transportation

  • sea transport

  • Healthcare services

  • Telecommunications and Broadcasting Services


The second category is infrastructure that sustains important social or economic activities, such as large sports stadiums, large performance venues, and research parks.


However, not all companies belonging to the above categories, nor all computer systems within those companies, will automatically be subject to the regulations.

Only "critical infrastructure operators" officially designated by the regulatory authorities, and "critical computer systems" designated by them, are directly regulated by the ordinance.


For example, a power company's power supply, fuel transportation, or monitoring system, if it stops operating, could directly affect power services and thus could be designated as a critical computer system; however, a general attendance or recruitment system within the same organization may not fall under the scope of regulation.


The focus of the ordinance is not to bring all IT systems within a large organization under regulation, but rather to centrally protect systems that are directly related to the core functions of critical services.



What responsibilities do regulated institutions bear?


The three categories of statutory responsibilities under the regulations can be summarized in three directions: establishing a management framework, preventing cyberattacks, and responding quickly when an incident occurs.


Category 1: Structural Responsibility


Regulated operators need to establish a clear computer system security management framework, including setting up a computer system security management unit and appointing employees with sufficient professional knowledge as supervisors.


Simply put, cybersecurity can no longer be simply "handled down to the IT department," but requires clear responsible persons, duties, and management structures.


Category Two: Prevention Responsibility


Operators need to identify and manage network security risks in advance, including:

  • Develop and implement a computer system security management plan;

  • Regularly conduct computer system security risk assessments;

  • Conduct security vulnerability assessments and penetration tests;

  • Conduct independent security audits regularly;

  • Significant changes in managing critical computer systems.


The relevant management plan also needs to cover areas such as asset management, account and access control, change management, remote access, network security, cloud security, and supply chain management.


Category 3: Accident Reporting and Response Responsibilities


Operators are required to develop emergency plans for computer system security incidents, participate in security drills, and notify the authorities within the specified timeframes when an incident occurs.


An incident is considered a serious incident if it has already interfered with, is currently interfering with, or is highly likely to interfere with the core functions of critical infrastructure, and the authorities must be notified within 12 hours of becoming aware of the incident.


Other incidents that have a real adverse impact on the security of critical computer systems generally require notification within 48 hours of becoming aware of the incident, and a written report must be submitted within 14 days of becoming aware of the incident.


It must be emphasized that the above reporting deadlines apply to operators and critical computer systems specified in the Ordinance, and are not statutory deadlines that all Hong Kong SMEs are required to comply with.


But these requirements also reflect an important shift:


Cybersecurity is no longer just about installing antivirus software; it requires someone to be responsible, there must be documentation, records, drills, and recovery capabilities.


Why should SMEs still be cautious under the new regulations on cybersecurity for critical infrastructure?


Imagine the following situation:


Your company has been working with a large enterprise for many years and is preparing to renew its contract; or you have just received a tender document from a government agency, public institution, or large group.


The regulations on key infrastructure directly regulate and indirectly affect the supply chains of SMEs.

In addition to price, scope of services, and company experience, the document suddenly included a detailed "Supplier Network Security Questionnaire," requiring you to explain your situation in a short period of time.


  • Which employees are allowed to log in to the customer system?

  • Whether remote support uses multi-factor authentication;

  • Back up when the most recent successful restore was performed;

  • How long after a safety incident will customers be notified?

  • Will the work be subcontracted to other suppliers?

  • Can the company provide relevant policies, system records, and proof of implementation?


The problem may not be that the company has no security measures at all, but that someone has been handling it in the past, but it has not been documented, with responsibilities clearly defined and records available for submission.


When it comes to contract renewal or bidding, companies often find that they may not be able to answer customers' questions before the deadline.


This is the indirect impact that the regulations may have on ordinary SMEs: they may not be directly regulated by the government, but large customers may gradually increase their requirements for suppliers.


Many critical infrastructure operators rely on external suppliers to help maintain daily operations, for example:


  • IT support and managed service provider;

  • Software and system developers;

  • Cloud and data center service providers;

  • Network and telecommunications providers;

  • CCTV, access control and IoT system contractor;

  • Hardware repair and technical support company;

  • Other partners can access the system remotely or on-site.


The Commissioner's Office's official FAQ clearly states that operators can outsource work, but they cannot outsource statutory responsibilities as well.


Operators still need to ensure they comply with the regulations and can, through contractual terms, require third-party service providers to assist in fulfilling their responsibilities.


Therefore, although SMEs may not receive direct regulatory notices from the government, if the company is a supplier to large institutions or critical infrastructure operators, it may still face more stringent customer requirements.



What supply chain requirements might arise?


In the past, when companies chose IT providers, they might have mainly considered price, technical capabilities, and response speed.


When large organizations need to demonstrate that their critical systems are adequately protected, they may also begin to focus on the following:


  • Access permissions: Which employees, contractors, or suppliers have access to the customer's system?

  • Identity verification: Is multi-factor authentication (MFA) mandatory for remote login?

  • Account Management: How do administrators create, approve, inspect, and cancel accounts?

  • Resignation Procedure: How long does it take for system privileges to be removed after an employee leaves the company?

  • Operation Records: How long are system logs and administrative operation records retained?

  • Incident Notification: How long after a safety incident is discovered will the supplier notify the customer?

  • Subcontractor Management: Does the service involve other subcontractors or third-party technicians?

  • Backup protection: Is the backup system isolated from the main system to prevent simultaneous attacks?

  • Recovery test: Has the company actually tested whether the backup can be successfully restored?

  • Division of responsibilities: In the event of an accident, who is responsible for investigation, reporting, and restoration of services?


The official FAQ also points out that when regulatory authorities are investigating potential operators and their key computer systems, they may request network architecture diagrams, hardware and software information, third-party IT or telecommunications service information, backup plans, and technical information on system design and operation.


In order to collate and verify this information, large organizations may also require their suppliers to provide corresponding documents.


In the future, some IT contracts, supplier registrations, and tender documents may include additional clauses related to the following:


  • Cybersecurity responsibility;

  • Time limit for accident notification;

  • Preservation of logs and evidence;

  • Subcontractor and supply chain management;

  • System and data access control;

  • In conjunction with safety audits and risk assessments;

  • Arrangements for account cancellation and data return after contract termination.


These may not be legal responsibilities directly imposed on ordinary SMEs by the regulations, but they may gradually become part of business cooperation and supplier management.



What can a typical business prepare now?


Small and medium-sized enterprises do not need to immediately adopt the entire set of compliance systems of large critical infrastructure operators.


A more practical approach is to first establish basic IT management and incident response capabilities.


Six IT Management Preparations for SMEs to Meet Cybersecurity Requirements

1. Organize IT assets and major systems.


First, businesses need to know what they have:


  • Equipment list: Organize servers, computers, network equipment, and storage devices;

  • Software services: Records software, cloud platforms, and subscription services in use;

  • System importance: Identify which systems would impact core business operations if they were to stop functioning;

  • Supplier Information: Stores information on key technology suppliers and their contacts;

  • Lifecycle: Identify hardware and software that are no longer supported by the manufacturer.


If a company is unaware of its key systems, it will be difficult to assess risks and even more difficult to respond quickly when an incident occurs.


2. Establish network architecture and access control records.


Enterprises should retain a basic network architecture diagram and record it clearly:


  • Management authority: Who has the highest system authority?

  • Remote login: Which vendors can access the system from outside;

  • Identity protection: Does remote login use multi-factor authentication?

  • Shared Accounts: Are multiple people still sharing the same administrator account?

  • Changes in permissions: How to adjust permissions when an employee joins, changes jobs, or leaves the company.


This data not only helps with daily management, but also allows for a more systematic answer to questions when customers conduct supplier reviews.


3. Clarify the responsibilities of the enterprise and the IT supplier.


Businesses should not simply stop at "calling IT companies whenever there is a problem".


Both parties should be clearly aware that:


  • System monitoring: Who is responsible for monitoring the status of the system and equipment?

  • Security Updates: Who is responsible for installing and checking critical updates?

  • Backup check: Who is responsible for confirming whether the backup was successful?

  • Incident decision-making: Who has the authority to decide to interrupt the network or shut down the system?

  • Notification deadline: How long after a supplier discovers an incident must they notify the customer;

  • Scope of services: What tasks are included in the daily services;

  • Professional support: In what situations should a cybersecurity expert be hired?


Work can be outsourced, but a company's management responsibilities and decision-making cannot be completely handed over to suppliers.


4. Establish basic accident response procedures.


Businesses should at least decide in advance:


  • Internal notification: Who should be notified immediately upon discovering suspicious emails, ransomware messages, or abnormal logins?

  • Immediate action: Should employees immediately shut down their devices or disconnect from the network?

  • Evidence preservation: How to retain system logs, emails, and related records;

  • Stakeholder notification: Which management, customers, or partners need to be notified;

  • External assistance: When to call the police, notify the insurance company, or seek professional help;

  • Recovery Confirmation: How to confirm that the risks are under control after the system is restored.


Finding contacts, passwords, and backup locations only after an incident has occurred is usually too late.


5. Not only should you back up your data, but you should also test and restore it.


A successful backup system result does not guarantee that the business will be able to resume operations smoothly.


Businesses also need to confirm:


  • Backup time: When was the last successful backup?

  • Separation and protection: Is the backup system appropriately separated from the primary system?

  • Ransomware risk: Can ransomware encrypt the existing system and backups simultaneously?

  • Restoration test: Has the data been actually tested and restored?

  • Recovery time: How long will it take to restore critical systems?

  • Continuous Operations: How does the company maintain basic operations while the system is unavailable?


What truly matters is not just whether there are backups, but whether recovery can be achieved within a reasonable timeframe after an accident.


6. Save execution records


When customers conduct security audits in the future, they may not only ask:


"Did you do it?"


They are more likely to ask:


"What records do you have to prove you did it?"


Therefore, businesses should gradually preserve:


  • System and software update history;

  • Backup and restore test results;

  • Account and permission check records;

  • Changes to firewall and security settings;

  • Risk and vulnerability improvement record;

  • Accident reporting and follow-up actions;

  • Supplier services and inspection reports.


Documentation, dates, and a responsible person are necessary to prove that safety measures are not just verbal promises.



From "the system is usable" to "the risk is managed"


The Protection of Critical Infrastructure (Computer Systems) Ordinance primarily regulates officially designated critical infrastructure operators and critical computer systems, not all Hong Kong companies.


However, the ordinance also reflects a significant shift in enterprise IT management.


In the past, businesses might only need to prove that the system was currently functioning properly.


Now, more and more large clients may also be concerned about:


  • Does the company know what its important systems are?

  • Who is responsible for cybersecurity?

  • Which systems can suppliers access?

  • Is there a clear procedure in case of an accident?

  • Can a backup truly restore the data?

  • Does the company have records proving that the relevant measures were ever implemented?


For SMEs, it may not be necessary to invest a lot of resources in establishing complex compliance systems now.


More importantly, we should first understand the current IT environment, identify the most important systems and risks, and then gradually improve asset management, account permissions, backup and recovery, supplier management, and incident response capabilities in order of priority.


When customers raise more stringent network security requirements, businesses don't need to start from scratch; and when a real security incident occurs, it can reduce chaos and business interruption.



Are you unsure if the company is adequately prepared?


If your customers start asking you to fill out cybersecurity questionnaires, provide backup records, explain remote access arrangements, or include incident reporting requirements in the contract, your business may not need to immediately launch a large compliance project.


You can contact i-Success first and briefly explain your current IT environment, customer requirements, and the documents that need to be submitted.


We will assist in determining the most suitable next step:


  • Organize existing IT assets and network data;

  • Review backup and recovery arrangements;

  • Clarify account permissions and remote access;

  • Prepare the necessary information for the supplier's network security questionnaire;

  • Alternatively, a more comprehensive IT Health Review could be arranged.


Understanding the actual gaps before deciding on the order of improvement and budget is usually more practical than buying a large quantity of security products all at once.


Feel free to contact the i-Success team via the website or WhatsApp.



This article is intended to provide general information and reference for enterprise IT management, and does not constitute legal advice. If an enterprise has been designated as a critical infrastructure operator, or needs to determine specific legal liabilities, it should refer to the ordinance, the official Code of Practice, and seek professional legal advice.


References


1. Hong Kong Special Administrative Region Government Press Release: The Protection of Critical Infrastructure (Computer Systems) Ordinance will come into effect on 1 January 2026.


2. Office of the Commissioner for Critical Infrastructure (Computer Systems Security): Legislative Purpose and Principles


3. Office of the Specialist for Critical Infrastructure (Computer System Security): Scope and Targets of Regulation


4. Office of the Special Commissioner for Critical Infrastructure (Computer System Security): Three Types of Statutory Responsibilities


5. Critical Infrastructure (Computer System Security) Specialist's Office: Frequently Asked Questions


6. General Code of Practice for the Protection of Critical Infrastructure (Computer Systems) Ordinance

Contact i-Success via WhatsApp for IT support, cybersecurity consultation and enquiry
Contact i-Success via WhatsApp for IT support, cybersecurity consultation and enquiry

PROFESSIONAL & RELIABLE 

香港九龍荔枝角光昌街3號鴻昌工廠大廈2樓D2室

Unit D2 , 2/F , Hung Cheong Factory Building, 3 Kwong Cheung Street, Lai Chi Kok, Kowloon, Hong Kong

TEL : 852-3997 0301

Office Hours : 9am - 6pm

Copyright © 2025 i-Success Technology (HK) Limited. All Rights Reserved.

 
  • White Facebook Icon
  • Google Places - White Circle
  • v2 web-11
bottom of page