Last week, Ringus, as part of the Hantec Group,
๐ ๐ช๐ต๐ผ ๐๐ ๐๐ป๐๐ผ๐น๐๐ฒ๐ฑ ๐ถ๐ป ๐๐ผ๐ป๐ด ๐๐ผ๐ป๐ดโ๐ ๐ก๐ฒ๐ ๐๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐๐๐ฏ๐ฒ๐ฟ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ฎ๐?
Since ๐ญ ๐๐ฎ๐ป๐๐ฎ๐ฟ๐ ๐ฎ๐ฌ๐ฎ๐ฒ, the ๐๐ณ๐ฐ๐ต๐ฆ๐ค๐ต๐ช๐ฐ๐ฏ ๐ฐ๐ง ๐๐ณ๐ช๐ต๐ช๐ค๐ข๐ญ ๐๐ฏ๐ง๐ณ๐ข๐ด๐ต๐ณ๐ถ๐ค๐ต๐ถ๐ณ๐ฆ๐ด (๐๐ฐ๐ฎ๐ฑ๐ถ๐ต๐ฆ๐ณ ๐๐บ๐ด๐ต๐ฆ๐ฎ๐ด) ๐๐ณ๐ฅ๐ช๐ฏ๐ข๐ฏ๐ค๐ฆ (๐๐ข๐ฑ. 653) has come into force. The law establishes a comprehensive framework to protect essential services from cyber threats.
Under Cap. 653, designated ๐๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ (๐๐) ๐ข๐ฝ๐ฒ๐ฟ๐ฎ๐๐ผ๐ฟ๐ are organizations whose computer systems are essential to maintaining critical societal or economic activities in Hong Kong.
๐ ๐ฆ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฒ๐ณ๐ถ๐ป๐ฒ๐ฑ ๐ฎ๐ ๐๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐๐ป๐ฐ๐น๐๐ฑ๐ฒ:
1. Energyโก
2. Information Technology๐ป
3. Banking & Financial Services๐ฆ
4. Air Transportโ
5. Land Transport๐
6. Maritime Transportโ
7. Healthcare Services๐ฅ
8. Telecommunications & Broadcasting๐ก
In addition, any other infrastructure the damage, loss of functionality or data leakage of which may hinder or otherwise substantially affect the maintenance of critical societal or economic activities in Hong Kong may also fall within scope.
These operators are now legally required to establish cybersecurity governance frameworks โ from maintaining dedicated computer-system security management units to reporting incidents, conducting periodic risk assessments and audits, etc.
Besides the CI Operator, there are ๐๐ผ๐บ๐ฒ ๐ผ๐๐ต๐ฒ๐ฟ ๐๐ฒ๐ ๐ฅ๐ผ๐น๐ฒ๐ ๐๐ป๐ฑ๐ฒ๐ฟ ๐๐ฎ๐ฝ. ๐ฒ๐ฑ๐ฏ:๐ฅ
๐น ๐๐ผ๐บ๐ฝ๐๐๐ฒ๐ฟ-๐๐๐๐๐ฒ๐บ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐บ๐ฒ๐ป๐ ๐จ๐ป๐ถ๐
Responsible for managing and safeguarding critical computer systems and ensuring compliance with the Ordinance.
๐น ๐ฆ๐๐ฝ๐ฒ๐ฟ๐๐ถ๐๐ผ๐ฟ ๐ผ๐ณ ๐๐ต๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐บ๐ฒ๐ป๐ ๐จ๐ป๐ถ๐
An appointed employee with sufficient cybersecurity expertise, responsible for supervising the unit and notifying the regulating authority of the appointment.
๐ก ๐๐ฎ๐ฝ. ๐ฒ๐ฑ๐ฏ ๐บ๐ฎ๐ฟ๐ธ๐ ๐ฎ ๐๐ถ๐ด๐ป๐ถ๐ณ๐ถ๐ฐ๐ฎ๐ป๐ ๐๐ต๐ถ๐ณ๐ ๐ณ๐ฟ๐ผ๐บ ๐ฏ๐ฒ๐๐ ๐ฝ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฒ ๐๐ผ ๐น๐ฒ๐ด๐ฎ๐น ๐ผ๐ฏ๐น๐ถ๐ด๐ฎ๐๐ถ๐ผ๐ป.
If your organization operates within a potentially designated sector, early preparation is essential.