Start with applicability

The Protection of Critical Infrastructures (Computer Systems) Ordinance came into operation on 1 January 2026. The Commissioner’s published FAQ describes how authorities approach organisations that may be designated. Do not assume that every Hong Kong business has the same duties; confirm designation and scope with the responsible authority or legal adviser.

Prepare a supplier incident handoff

In this operational example, a software supplier supports a customer whose system is under review. The supplier records facts and escalates through the agreed channel. The table does not assign legal status, reporting thresholds or statutory deadlines.

Prepare a supplier incident handoff
Handoff itemEvidence to prepare
Affected serviceSystem name, environment, customer contact and current impact
Known event timelineDetection time, observed changes and actions already taken
Access and recoveryAuthorised responders, preserved logs and tested recovery options

Separate an operator’s duties from vendor work

A software supplier may be asked to support a customer’s security, evidence or incident procedures. The contract should state which systems are covered, what access is permitted and how incidents are escalated. A vendor questionnaire does not by itself establish the supplier’s legal status under the regime.

Prepare an operational evidence trail

Use the applicable requirements to identify system owners, access records, changes, recovery procedures and incident contacts. Test how that information can be retrieved during a real problem. Reporting duties and deadlines require the current official materials and legal assessment, rather than a generic timer copied into an engineering plan.

Before you proceed

  • Confirm whether and how the organisation is within scope.
  • Read the current Code of Practice with the responsible adviser.
  • Align vendor access and incident responsibilities in writing.

Sources & further reading

Put this into practice