// AI threat desk · 29 Sept 2026
Sample content · apart from the Arup deepfake case, every company, product and CVE ID is fictional
Home/CI Ordinance tracker

CI Ordinance tracker_

The Protection of Critical Infrastructures (Computer Systems) Ordinance took effect on 1 January 2026. This page tracks its main duties, deadlines and our coverage.

Key dates

DateEvent
2025-03-19LegCo passes the Ordinance
2026-01-01Ordinance takes effect; Commissioner's Office set up
From commencementThe Office designates CI operators and critical computer systems in batches
After designationOperators must file a security management plan and complete risk assessments and audits within set periods

Main duties for operators

  1. Set up a computer-system security management unit
  2. Keep a Hong Kong office and report changes of operator
  3. File and follow a computer-system security management plan
  4. Run regular risk assessments and independent audits
  5. Take part in the Office's drills
  6. Report serious incidents within 12 hours, others within 48 hours
  7. Fines of HK$300,000 to HK$5 million for breaches

The eight covered sectors

EnergyInformation technologyBanking and financial servicesLand transportAir transportMaritime transportHealthcareCommunications and broadcasting

Source: Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) and Security Bureau material.

Coverage

No stories match. Try the glossary or all stories.