- Purpose / Background: The HKMA and other financial authorities (SFC, IA, MPFA) have developed a "Cyber Map" to identify cyber risk concentrations and interdependencies within the Hong Kong financial system. This inaugural exercise establishes a methodology to track systemic spillover pathways and third-party dependencies.
- One-line conclusion: Authorities have formalized a three-layered data collection framework to visualize inter-connectedness between FIs and IT infrastructure, enabling more targeted supervision and systemic incident response.
- Key Changes:
- Implementation of a three-layered data structure: (1) Financial services, (2) Critical operations/supporting applications, and (3) Underlying IT infrastructure components.
- Transition to dashboard-based network visualization using nodes and weighted lines to represent dependency materiality.
- Standardization of data collection across 50 participating FIs from banking, securities, insurance, and MPF sectors.
- Inclusion of customized filtering tools to facilitate granular scenario analysis.
- Key Dates / Deadlines: Data collection for the inaugural map commenced in late 2025; publication of the technical note occurred on 29 July 2026.
- Applicability / Impact scope: Initially applied to 50 systematically important or highly interconnected FIs across the banking, retail payment, securities, capital markets, MPF, and insurance sectors.
- Recommended management actions:
- Review internal dependency mapping against the three-layered structure defined in the note.
- Ensure IT infrastructure documentation is granular enough to support future regulatory data calls.
- Evaluate current third-party risk management (TPRM) frameworks to ensure they align with the "node" dependency visualization logic.
- Prepare for potential iterative data reporting requirements as the Cyber Map evolves.
1) Document overview
This technical note details the development and methodology behind Hong Kong's inaugural Cyber Map. It is designed to help authorities visualize systemic risk, identify "hot spots" of dependency on specific ICT service providers, and enhance incident response capabilities.
2) Main requirements
The framework requires FIs to categorize their operational landscape using a three-layered model:
- Layer 1: Financial services provided.
- Layer 2: Critical operations and the applications that support them.
- Layer 3: Underlying IT infrastructure components.
3) Key changes
- Move from siloed supervisory reporting to a holistic network-based visualization.
- Adoption of a "node and edge" mapping methodology where node size reflects reliance (degree of centrality) and line thickness reflects dependency materiality (e.g., system hosting or data transmission).
4) Important dates & transition
- Late 2025: Commencement of data collection from initial cohort.
- 29 July 2026: Official release of the technical note/methodology.
5) Impact and risks
- Operational: Increased burden on FIs to accurately map complex dependencies between internal systems and third-party ICT providers.
- Compliance: Risk of inconsistent reporting; data must be cleansed iteratively before integration into the dashboard.
- Strategic: Improved ability for authorities to conduct systemic stress testing and contagion analysis.
6) Compliance action checklist
- Audit current inventory of ICT service providers and inter-entity connections.
- Map internal business services to critical applications and infrastructure per the three-layered model.
- Participate in future data collection exercises with clean, validated relationship data.
- Monitor for feedback loops where "node" importance might trigger closer regulatory scrutiny.
7) Appendices/attachments summary
- Diagram 1 (Three-layered data methodology): Illustrates the hierarchy from financial services down to IT infrastructure, serving as the core schema for all future data submissions.
- Diagram 2 (Network relationships example): Provides a visual guide on how relationship data (direction, thickness, color, and node size) is interpreted by authorities to identify systemic risk concentrations.