Joint Circular on the Cross-Sectoral Cyber Mapping Exercise (2026-07-29)

Circulars Email: HKMA E-mail Alert of 30 July 2026 (05:00 p.m. HKT)

Document Information

Title: Joint Circular on the Cross-Sectoral Cyber Mapping Exercise (2026-07-29)

Type: Circulars

URL: https://brdr.hkma.gov.hk/eng/doc-ldg/current/20260729-1-EN

Email Received: 2026-07-30 19:12

Summary Created: 2026-07-30 14:00

English Summary
Quick section switch
Management Summary
  • Purpose / Background: The HKMA, SFC, IA, and MPFA (the Authorities) have completed the first cross-sectoral "Cyber Mapping" exercise to identify systemic cyber risk concentrations and interdependencies across Hong Kong's financial ecosystem, as recommended by the IMF Financial Sector Assessment Program (FSAP).
  • One-line conclusion: The exercise confirms no new "unknown" systemic risks but highlights high interconnectedness with third-party providers; the exercise will become a recurring, long-term supervisory tool.
  • Key Changes:
  • Established a cross-sectoral "Cyber Map" dashboard to visualize technology and business connections.
  • Identified specific focus areas for supervisory attention, particularly regarding recurring specialist vendors in network appliances, security monitoring, and privileged access management.
  • Transitioned Cyber Mapping from a pilot initiative to a recurring, permanent supervisory fixture.
  • Planned future exploration to provide FIs with access to their own relevant data within the map to aid internal risk management.
  • Increased emphasis on third-party risk supervision based on shared adoption patterns of ICT solutions.
  • Key Dates / Deadlines:
  • First production run completed: March 2026.
  • Next iteration expected: 2027/2028 (details to follow).
  • Applicability / Impact scope: All Authorized Institutions, SVF licensees, Hong Kong Interbank Clearing Limited, retail payment systems, licensed corporations, authorized insurers, and MPF trustees.
  • Recommended management actions:
  • Review internal third-party risk management frameworks to align with potential increased supervisory scrutiny on ICT service providers.
  • Monitor upcoming circulars regarding the 2027/2028 exercise cycle to ensure data readiness.
  • Engage in bilateral feedback sessions if notified by the Authorities regarding specific insights from the first production run.
  • Evaluate current dependency on "recurring specialist vendors" in cybersecurity/network infrastructure as identified in the mapping trends.
Detailed Summary
  1. Document overview: A joint circular from the four major financial regulators detailing the findings of the first cross-sectoral Cyber Mapping exercise. The purpose is to map business/technology interdependencies to proactively manage systemic risk and "single point of failure" risks stemming from shared third-party service providers.
  1. Main requirements:
  • Data Compliance: FIs are required to provide data as requested by the Authorities to maintain the Cyber Map, adhering to principles of data necessity and security.
  • Supervisory Cooperation: Participation in future exercises is expected as the initiative becomes a recurring fixture.
  • Risk Management: FIs must account for the Authorities’ heightened focus on ICT arrangements, specifically in network infrastructure, security event monitoring, and privileged access management.
  1. Key changes:
  • Implementation of a dynamic dashboard-based mapping tool for systemic monitoring.
  • Shift from sector-specific cyber supervision to a "borderless" ecosystem-wide approach.
  1. Important dates & transition:
  • March 2026: Successful completion of the initial production run.
  • 2027/2028: Targeted commencement of the next full exercise.
  1. Impact and risks:
  • Operational: Increased scrutiny on dependencies regarding third-party ICT providers.
  • Compliance: Potential for thematic reviews, drills, and additional contingency planning requirements following the mapping outputs.
  • Data: Continued requirement to provide accurate, up-to-date dependency information to regulators.
  1. Compliance action checklist:
  • Review current ICT vendor dependency list against the "recurring specialist vendors" categories mentioned (network appliances, security monitoring, privileged access management).
  • Prepare internal data governance teams for potential future data calls for the 2027/2028 cycle.
  • Await and review bilateral supervisory feedback if designated as a participant in the first production run.
  1. Appendices/attachments summary:
  • Technical Note (Annex): Provides the technical details and data collection methodology used to build the Cyber Map, serving as the foundation for the Authorities' analytical dashboard.
中文摘要
快速切換摘要區塊
管理層摘要
  • 目的/背景 為應對金融系統高度互連帶來的網絡風險(如單點故障及風險傳導),香港金融監管機構(HKMA、SFC、IA、MPFA)協同財庫局合作啟動「跨行業網絡映射(Cyber Mapping)計劃」,旨在提升對金融體系內網絡風險集中度及相互依存關係的認知。
  • 一句話結論 監管機構已完成首次「網絡映射」產出,未來將以此工具加強第三方風險監管,並計劃將其恆常化,預計 2027/2028 年啟動下一輪工作。
  • 關鍵變更
  1. 監管工具升級: 引入動態儀表板(Dashboard)以視覺化方式監控金融機構(FIs)間的業務及技術連結。
  2. 監管重點轉移: 識別出特定第三方服務提供商(如網絡基建、資安解決方案供應商)的採用具同質性,監管機構將加強對此類關鍵供應商的監管關注。
  3. 邁向恆常化: 網絡映射將成為監管日常工作的常設輔助工具。
  4. 未來展望: 研究在適當時機向金融機構開放 Dashboard 功能,以助機構自身風險管理。
  • 重要日期 / 截止日 首次產出已於 2026 年 3 月完成;下一輪演習預計於 2027/2028 年開始。
  • 適用對象 / 影響範圍 涵蓋銀行、儲值支付、證券、強積金及保險行業之金融機構。
  • 管理層建議行動
  1. 檢視第三方供應商風險: 評估內部使用的關鍵技術供應商(特別是資安監控與存取管理服務),確保具備足夠的退出機制或替代方案。
  2. 關注監管回饋: 參與首輪演習的機構應準備與監管機構進行雙邊交流,針對產出結果調整合規策略。
  3. 提升網絡韌性: 加強對網絡風險生命週期的全盤管理,特別是針對關鍵第三方依賴的應變規劃。
  4. 參與後續規劃: 密切留意 2027/2028 年下一輪演習的通知,並提前規劃數據收集與協作資源。
詳細摘要

1) 文檔概述
本文檔由香港四大金融監管機構共同發布,說明「跨行業網絡映射」首次產出結果。該計劃遵循國際貨幣基金組織(IMF)框架,旨在透過描繪金融體系內的技術互聯性,強化系統性網絡風險的早期預警與監督能力。

2) 主要要求與觀察

  • 風險集中度監控 監管機構確認大型金融機構、金融基礎設施及雲端/數據中心供應商為體系內的「最大節點」。
  • 強化第三方監督 發現多數機構在「網絡基礎設施」、「資安監控」及「特權存取管理」上有高度雷同的第三方供應商選擇,未來將對這些供應商實施前瞻性的監管監測。
  • 監管工具應用 監管機構將利用網絡映射儀表板,於處理網絡事件及規劃專題審查(Thematic Reviews)時,進行更精確的風險 triage(分流)。

3) 關鍵變更

  • 從「機構單點監督」轉向「跨行業生態系統監督」。
  • 將網絡映射納入日常監管工具包,並研議將數據儀表板延伸至受規管機構,以輔助行業自身的風險預判。

4) 重要日期與過渡安排

  • 2026 年 3 月 已完成首輪演習。
  • 2027/2028 年 預計啟動下一輪映射工作(細節將另行通知)。

5) 對機構的影響與風險

  • 營運/合規 機構需持續評估其對關鍵第三方服務商的依賴程度,預防單點故障風險。
  • 數據與報告 監管機構將持續採取數據收集,並確保收集範疇僅限於有效映射所需,且優先考慮數據安全。

6) 合規動作清單

  • [ ] 若為首輪參與機構,主動與監管機構聯繫進行雙邊回饋面談。
  • [ ] 對標首輪演習中的網絡依存性分析,檢視自身的第三方供應商關鍵度評估。
  • [ ] 配合監管機構關於資安監控與特權存取管理的最新指引進行內部自我核查。

7) 附件/附錄摘要

  • Technical Note (Annex) 此技術說明詳細闡述了網絡映射的數據收集方法論、演習運作邏輯及底層數據架構。該附件為監管機構進行 mapping 的技術指導文件,雖不直接增加合規門檻,但為機構理解數據範疇的重要參考。