Use this button to switch between dark and light mode.

Navigating the scope and targets of Cap 653

Hong Kong’s Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap 653) introduces a targeted cybersecurity framework for critical infrastructure computer systems. For lawyers advising organisations in affected sectors, the practical starting point is often one of scope: which infrastructure, operator or system is likely to attract attention under the Ordinance?

That question is not always straightforward. The Practice Note Navigating the scope and targets of the Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap 653) helps frame the issues practitioners may need to consider when assessing Critical Infrastructure, Critical Infrastructure Operators and Critical Computer Systems.

Produced in partnership with Chandy Ye of Hong Kong China Network Security Association, the Practice Note is part of the new Lexis+ Hong Kong Practical Guidance TMT Module.

Key issues highlighted in the Practice Note

Understanding the scope of Critical Infrastructure

The Practice Note explains that the Ordinance identifies two categories of Critical Infrastructure. One concerns infrastructures for the continuous provision of essential services in Hong Kong, including sectors such as energy, information technology, banking and financial services, transport, healthcare, telecommunications, and broadcasting. The other concerns infrastructures for maintaining critical societal or economic activities.

For practitioners, this creates a useful lens for assessing whether disruption, loss of functionality, or data leakage could materially affect Hong Kong’s public, societal, or economic functions.

Identifying the relevant operator

The Practice Note highlights that being present in a listed sector does not automatically mean an organisation is regulated. The Ordinance targets large-scale organisations and focuses on designated Critical Infrastructure Operators. Factors such as dependence on computer systems, sensitivity of digital data, and control over infrastructure operations are relevant to the designation analysis.

This is particularly important where infrastructure ownership and operational control do not sit with the same entity. Outsourcing, joint ventures, service level agreements, and operational control clauses may all become important when assessing which entity is more likely to be designated.

Scoping Critical Computer Systems

Identifying a CIO is only part of the analysis. The Practice Note explains that statutory obligations apply specifically to designated Critical Computer Systems. Scoping those systems may require practitioners to consider accessibility, materiality, operational dependency and data sensitivity.

The resource also takes a closer look at systems located outside Hong Kong but accessible in or from Hong Kong, as well as the relevance of operational technology, industrial control systems, physical security support systems, and IoT-connected devices.

Supplier and flow-down considerations

The Practice Note also considers the “flow-down” effect, where designated CIOs may need to ensure critical third-party suppliers meet statutory security standards through contractual terms. This may be relevant for cloud services providers, IT vendors, and other suppliers supporting critical infrastructure operations.

How Lexis+ Practical Guidance Hong Kong helps

The Lexis+ Hong Kong Practical Guidance TMT Module supports practitioners handling technology, data and digital issues across corporate and commercial work. It offers practical guidance across areas including cybersecurity and cybercrime, data protection and privacy, telecommunications, technology transactions, and data governance.

Complete the form below to download the full Practice Note, Navigating the scope and targets of the Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap 653).

Note: After completing the form, the whitepaper will appear on the same page. Please stay on the page after submission. If you do not see the whitepaper, contact us at marketing.hk@lexisnexis.com for assistance.

Complete the Form for Instant Access

Email: marketing.hk@lexisnexis.com
Telephone number:+852 2179-7888