Hong Kong Secures Key Facilities with New Cybersecurity Law
Hong Kong has passed a new cybersecurity law that aims to protect critical infrastructure across key sectors by mandating enhanced system security, regular audits, and quick incident reporting, with significant penalties for violations.
Published on March 28, 2025
Hong Kong has enacted a new cybersecurity law aimed at bolstering the defenses of its critical infrastructure. The law, which is set to take effect in 2026, targets eight key sectors including banking, IT, energy, healthcare, and communications. Operators in these sectors must enhance their systems, conduct annual risk assessments, and undergo biennial independent audits, with penalties of up to HK$5 million ($640,000) for non-compliance. Serious cybersecurity incidents must be reported within two hours.
The legislation builds on previous cybersecurity measures introduced in 2020 and 2024, and follows China’s cybersecurity law from 2016. While security chief Chris Tang assures that the law will not target personal or commercial data, some observers remain concerned that increased compliance costs could deter foreign investment. Additional provisions, such as empowering government actions under court warrant when needed, have also sparked debate regarding the balance between security and surveillance.