• Skip to homepage
  • Skip to main content
  • Skip to main navigation
  • Skip to meta navigation
Zühlke - zur Startseite
  • Business
  • Careers
  • Events
  • About us

Language navigation. The current language is english

  • Expertise
    • AI implementation
    • Cloud
    • Cybersecurity
    • Data solutions
    • DevOps
    • Digital strategy
    • Experience design
    • Hardware engineering
    • Managed services
    • Software engineering
    • Sustainability transformation
    Explore our expertise

    Highlight Case Study

    Airport concept

    Zurich Airport transforms operations for a data-driven future

    Learn more
  • Industries
    • Banking
    • Insurance
    • Healthcare providers
    • MedTech
    • Pharma
    • Industrial sector
    • Commerce & retail
    • Energy & utilities
    • Government & public sector
    • Transport
    Explore our industries

    Subscribe to recieve the latest news, event invitations & more!

    Sign up here
  • Case studies

    Spotlight case studies

    • Global Research Platforms and Zühlke are fighting Alzheimer's disease
    • Brückner Maschinenbau leverages GenAI to optimise efficiency by improving master data management
    • UNIQA: AI chatbot increases efficiency – 95% accuracy with half the effort
    Explore more case studies

    Highlight Case Study

    Airport concept

    Zurich Airport transforms operations for a data-driven future

    Learn more
  • Insights

    Spotlight insights

    • How to apply low-code technologies in the insurance industry
    • Retail CTO playbook for managing the tech transformation
    • DeepSeek and the rise of open-source AI: A game-changer for businesses?
    Explore more insights

    Highlight Insight

    AI adoption: Rethinking time and purpose in the workplace

    Learn more
  • Academy
  • Contact
    • Austria
    • Bulgaria
    • Germany
    • Hong Kong
    • Portugal
    • Serbia
    • Singapore
    • Switzerland
    • United Kingdom
    • Vietnam

    Subscribe to recieve the latest news, event invitations & more!

    Sign up here
Zühlke - zur Startseite
  • Business
  • Careers
  • Events
  • About us
  • Expertise
    • AI implementation
    • Cloud
    • Cybersecurity
    • Data solutions
    • DevOps
    • Digital strategy
    • Experience design
    • Hardware engineering
    • Managed services
    • Software engineering
    • Sustainability transformation
    Explore our expertise

    Highlight Case Study

    Airport concept

    Zurich Airport transforms operations for a data-driven future

    Learn more
  • Industries
    • Banking
    • Insurance
    • Healthcare providers
    • MedTech
    • Pharma
    • Industrial sector
    • Commerce & retail
    • Energy & utilities
    • Government & public sector
    • Transport
    Explore our industries

    Subscribe to recieve the latest news, event invitations & more!

    Sign up here
  • Case studies

    Spotlight case studies

    • Global Research Platforms and Zühlke are fighting Alzheimer's disease
    • Brückner Maschinenbau leverages GenAI to optimise efficiency by improving master data management
    • UNIQA: AI chatbot increases efficiency – 95% accuracy with half the effort
    Explore more case studies

    Highlight Case Study

    Airport concept

    Zurich Airport transforms operations for a data-driven future

    Learn more
  • Insights

    Spotlight insights

    • How to apply low-code technologies in the insurance industry
    • Retail CTO playbook for managing the tech transformation
    • DeepSeek and the rise of open-source AI: A game-changer for businesses?
    Explore more insights

    Highlight Insight

    AI adoption: Rethinking time and purpose in the workplace

    Learn more
  • Academy
  • Contact
    • Austria
    • Bulgaria
    • Germany
    • Hong Kong
    • Portugal
    • Serbia
    • Singapore
    • Switzerland
    • United Kingdom
    • Vietnam

    Subscribe to recieve the latest news, event invitations & more!

    Sign up here

Language navigation. The current language is english

Homepage zuehlke.com

Banking

Hong Kong’s New Cybersecurity Bill: What does it mean for CIOs and CISOs?

Hong Kong’s new cybersecurity bill is targeting critical sectors like finance, energy, and telecom with tough cybersecurity mandates. What should CIOs and CISOs act on now with enforcement looming by 2026?

April 02, 20252 Minutes to Read
With insights from
Kunal Sehgal

Dr. Kunal Sehgal

Fromer Principal Cybersecurity Consultant

Hong Kong’s 'Protection of Critical Infrastructures (Computer Systems) Bill' introduces strict cybersecurity mandates for organisations in critical sectors. The law aims to strengthen cyber hygiene by enforcing a comprehensive set of security controls, including regular risk assessments, real-time system monitoring, penetration testing, and timely incident reporting.

Organisations must not only implement robust cybersecurity measures but also demonstrate their effectiveness in mitigating cyber threats. Non-compliance may result in severe penalties, making it essential for businesses to take proactive steps toward meeting these new obligations. Compliance is no longer optional; it’s a legal imperative and the stakes couldn’t be higher.

The challenge also lies in the law’s ambiguity: it does not clearly define which organisations fall under the classification of 'critical infrastructure'. While it broadly targets sectors such as finance, telecommunications, healthcare, energy, and transportation, the lack of qualifying criteria may leave some businesses in limbo, uncertain about the need for compliance.

The risk? Unintentional non-compliance could trigger penalties, audits, or worse, expose vulnerabilities during a cyber crisis. With enforcement looming as early as 2026, businesses need to be proactive and ensure they are not caught off guard given this uncertainty. 

A wake-up call for CIOs & CISOs of critical infrastructure operators

The Bill targets large organisations, especially those responsible for delivering essential services or maintaining vital societal and economic functions. Think CIOs of financial institutions, power grids, transport networks, and telecom providers, across sectors where a single cyber breach could paralyse business operations or disrupt daily life.

With enforcement set to begin on January 1, 2026, organisations must act now to ensure they are ready and meet the requirements within the time frame. We advise focusing on the following topics:

Submit and implement a computer-system security management plan

For protecting the computer-system security of their critical computer systems. This plan must be prepared following the requirements specified in Schedule 3.

Conduct computer-system security risk assessments

In respect of the risks relating to the computer-system security of their critical computer systems. The first assessment must be within 12 months of the designation date, and subsequent assessments at least once every 12 months thereafter. These assessments must cover all matters specified in Schedule 4.

Arrange to carry out computer-system security audits

In respect of the computer-system security of their critical computer systems. The first audit must be within 24 months of the designation date, and subsequent audits at least once every 24 months thereafter. These audits must cover the specified period, and all matters specified in Schedule 5 and must be carried out by an independent auditor.

Submit and implement an emergency response plan

Detailing the protocol for responding to computer-system security incidents in respect of their critical computer systems. This plan must be prepared following clause 27(3) and cover all matters specified in Part 2 of Schedule 3.

The Protection of Critical Infrastructures (Computer Systems) Bill is a game-changer, and the window to prepare is closing fast.

At Zühlke, we understand the complexity of this new regulatory landscape. As a global technology partner, we’ve helped organisations across industries like BitMEX and Justitia.Swiss, the Swiss justice system, to fortify their cybersecurity frameworks and navigate compliance challenges.

“The introduction of this new legislation couldn't be more timely. With cyberattacks surging by approximately 39% year-on-year, according to HKCERT, the threat landscape is growing more dangerous by the day. This serves as a wake-up call, urging organisations to strengthen their cybersecurity defences, before they become the next target.” “The introduction of this new legislation couldn't be more timely. With cyberattacks surging by approximately 39% year-on-year, according to HKCERT, the threat landscape is growing more dangerous by the day. This serves as a wake-up call, urging organisations to strengthen their cybersecurity defences, before they become the next target.”

Raphael Reischuk

Partner and Group Head Cybersecurity

Learn how you can safeguard your organisation with our global team of cybersecurity consultants

Learn more

Explore more Insights

All industries

Staying ahead of the race – Drivers for cybersecurity

Learn more
blue call to action button "fraud"
MedTech

Rust – secure software by design

Learn more
Rust - a promising alternative to C+?
All industries

Why low code doesn’t have to mean low security

Learn more
cutout of a keyboard
Discover all Insights

Get to know us

  • About us
  • Impact & commitments
  • Facts & figures
  • Careers
  • Event Hub
  • Insights Hub
  • News sign-up

Working with us

  • Our expertise
  • Our industries
  • Case studies
  • Partner ecosystem
  • Training Academy
  • Contact us

Legal

  • Privacy policy
  • Cookie policy
  • Legal notice
  • Modern slavery statement
  • Imprint

Request for proposal

We appreciate your interest in working with us. Please send us your request for proposal and we will contact you within 72 hours.

Request for proposal
© 2025 Zühlke Engineering AG

Follow us

  • External Link to Zühlke LinkedIn Page
  • External Link to Zühlke Facebook Page
  • External Link to Zühlke Instagram Page
  • External Link to Zühlke YouTube Page

Language navigation. The current language is english