Application Security Blog, Blog, LOGON Blog, SaaS Procurement and Management Blog, Software License Management Blog
Navigating Hong Kong’s New Cybersecurity Law (CI Bill): What to Do Next
LOGON BLOG
Navigating Hong Kong’s New Cybersecurity Law
What to Do Next?

Author: Jaqueline Fong, LOGON Software Asia
On March 19, 2025, Hong Kong took a significant step towards enhancing its cybersecurity landscape by passing the Protection of Critical Infrastructures (Computer Systems) Bill (the “CI Bill”). This landmark legislation aims to regulate operators of critical infrastructure to minimize disruptions caused by cybersecurity incidents.
Set to take effect on January 1, 2026, companies in Hong Kong must understand its implications and prepare accordingly.
Understanding the CI Bill
The CI Bill mandates that critical infrastructure operators strengthen their computer systems and report cybersecurity incidents promptly.

Key Provisions of the CI Bill
| Category 1 Obligations: (Organization of CI Operators) |
|
| Category 2 Obligations: (Prevention of Threats and Incidents) |
|
| Category 3 Obligations: (Incident Reporting and Response) |
|
Key Concerns for Hong Kong Companies
With the introduction of this law, companies must consider several crucial factors:
- Compliance Costs: Regular assessments and audits may increase operational costs, particularly for data centers and infrastructure operators.
- Investor Confidence: Amid increasing regulations, companies should proactively demonstrate their commitment to cybersecurity to maintain investor confidence.
- Risk of Non-Compliance: The potential fines for non-compliance can have substantial financial impacts. Companies must prioritize compliance to avoid these penalties.
What You Need to Do?
Step One: Assess Potential Status as CI Operators
- Determine if your organization qualifies as a critical infrastructure operator under the CI Bill. The Government plans to shortlist designated operators by June 2025.
- Engage legal experts to understand the criteria and obligations associated with CI operator status.
Step Two: Allocate Budget and Resources for Compliance
- If your organization is likely to qualify as a CI operator, allocate resources to implement the necessary organizational changes.
Step Three: Conduct a Gap Analysis
- Engage legal and cybersecurity experts to perform a thorough gap analysis to identify deficiencies in your current cybersecurity posture against the CI Bill’s requirements.
- Conduct security audits and penetration testing.
Step Four: Enhance Cyber Resilience
- Implement measures to comply with the CI Bill, including:
- Developing or updating security management and emergency response plans.
- Establishing clear incident reporting protocols.
- Conducting regular drills and training sessions.
- Reviewing system architecture to ensure compliance.

How LOGON Software Asia Can Assist
LOGON Software Asia is well-positioned to help companies navigate the complexities of the new cybersecurity law. Here’s how we can support your business:
- Customized Security Solutions: Tailored cybersecurity solutions designed to meet the specific needs of critical infrastructure operators. Our solutions include:
- Web & Mobile Pen Testing
- Software License Management
- SaaS Procurement and Management, and more
- Risk Assessment Services: Comprehensive security risk assessments to identify vulnerabilities and recommend mitigation strategies.
- Maintenance Support: Continuous monitoring and support services to maintain compliance and adapt to future regulatory changes.
Conclusion
The new cybersecurity law in Hong Kong represents a significant shift in the regulatory landscape for critical infrastructure operators. Companies must act proactively to ensure compliance and safeguard their operations.
LOGON Software Asia is here to guide you through this transition, providing the expertise and solutions for compliance and risk management.
For tailored advice on compliance and to understand the full implications of the CI Bill for your organization, contact our team today!


