Annex - Technical Note on Cross-Sectoral Cyber Mapping Exercise

Annex Email: HKMA E-mail Alert of 30 July 2026 (05:00 p.m. HKT)

Document Information

Title: Annex - Technical Note on Cross-Sectoral Cyber Mapping Exercise

Type: Annex

URL: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/20260729-2-EN

Email Received: 2026-07-30 19:12

Summary Created: 2026-07-30 14:01

English Summary
Quick section switch
Management Summary
  • Purpose / Background: The HKMA and other financial authorities (SFC, IA, MPFA) have developed a "Cyber Map" to identify cyber risk concentrations and interdependencies within the Hong Kong financial system. This inaugural exercise establishes a methodology to track systemic spillover pathways and third-party dependencies.
  • One-line conclusion: Authorities have formalized a three-layered data collection framework to visualize inter-connectedness between FIs and IT infrastructure, enabling more targeted supervision and systemic incident response.
  • Key Changes:
  • Implementation of a three-layered data structure: (1) Financial services, (2) Critical operations/supporting applications, and (3) Underlying IT infrastructure components.
  • Transition to dashboard-based network visualization using nodes and weighted lines to represent dependency materiality.
  • Standardization of data collection across 50 participating FIs from banking, securities, insurance, and MPF sectors.
  • Inclusion of customized filtering tools to facilitate granular scenario analysis.
  • Key Dates / Deadlines: Data collection for the inaugural map commenced in late 2025; publication of the technical note occurred on 29 July 2026.
  • Applicability / Impact scope: Initially applied to 50 systematically important or highly interconnected FIs across the banking, retail payment, securities, capital markets, MPF, and insurance sectors.
  • Recommended management actions:
  • Review internal dependency mapping against the three-layered structure defined in the note.
  • Ensure IT infrastructure documentation is granular enough to support future regulatory data calls.
  • Evaluate current third-party risk management (TPRM) frameworks to ensure they align with the "node" dependency visualization logic.
  • Prepare for potential iterative data reporting requirements as the Cyber Map evolves.
Detailed Summary

1) Document overview
This technical note details the development and methodology behind Hong Kong's inaugural Cyber Map. It is designed to help authorities visualize systemic risk, identify "hot spots" of dependency on specific ICT service providers, and enhance incident response capabilities.

2) Main requirements
The framework requires FIs to categorize their operational landscape using a three-layered model:

  • Layer 1: Financial services provided.
  • Layer 2: Critical operations and the applications that support them.
  • Layer 3: Underlying IT infrastructure components.

3) Key changes

  • Move from siloed supervisory reporting to a holistic network-based visualization.
  • Adoption of a "node and edge" mapping methodology where node size reflects reliance (degree of centrality) and line thickness reflects dependency materiality (e.g., system hosting or data transmission).

4) Important dates & transition

  • Late 2025: Commencement of data collection from initial cohort.
  • 29 July 2026: Official release of the technical note/methodology.

5) Impact and risks

  • Operational: Increased burden on FIs to accurately map complex dependencies between internal systems and third-party ICT providers.
  • Compliance: Risk of inconsistent reporting; data must be cleansed iteratively before integration into the dashboard.
  • Strategic: Improved ability for authorities to conduct systemic stress testing and contagion analysis.

6) Compliance action checklist

  • Audit current inventory of ICT service providers and inter-entity connections.
  • Map internal business services to critical applications and infrastructure per the three-layered model.
  • Participate in future data collection exercises with clean, validated relationship data.
  • Monitor for feedback loops where "node" importance might trigger closer regulatory scrutiny.

7) Appendices/attachments summary

  • Diagram 1 (Three-layered data methodology): Illustrates the hierarchy from financial services down to IT infrastructure, serving as the core schema for all future data submissions.
  • Diagram 2 (Network relationships example): Provides a visual guide on how relationship data (direction, thickness, color, and node size) is interpreted by authorities to identify systemic risk concentrations.
中文摘要
快速切換摘要區塊
管理層摘要
  • 目的/背景 金管局(HKMA)聯同其他監管機構建立首份「網絡地圖」(Cyber Map),旨在識別香港金融體系內的網絡風險集中度及機構間的相互依賴關係,以強化監管精確度及事故應變能力。
  • 一句話結論 本文件說明了監管機構如何透過三層架構蒐集逾 50 間機構的業務與科技關聯數據,繪製成視覺化儀表板,以模擬網絡攻擊在金融體系內的傳播路徑。
  • 關鍵變更
  1. 確立了三層數據蒐集架構(金融服務、關鍵營運/應用、底層 IT 基礎設施)。
  2. 採用網絡視覺化技術,以「節點」(Node)代表實體,「連線」(Line)代表依賴關係與關鍵程度。
  3. 實施動態風險監測,透過數據篩選功能進行情境分析(Scenario-based analysis)。
  • 重要日期
  • 數據收集啟動: 2025 年底。
  • 發布日期: 2026 年 7 月 29 日。
  • 適用對象 / 影響範圍 初期覆蓋銀行、零售支付、證券資本市場、強積金及保險業共約 50 間具系統重要性的金融機構。
  • 管理層建議行動
  1. 評估貴機構在該地圖中的「節點」重要性(Node size)及依賴路徑。
  2. 確保內部 IT 資產盤點(Asset Inventory)與監管機構定義的三層架構邏輯一致。
  3. 準備針對第三者服務供應商(ICT Service Provider)的關聯數據進行定期更新與申報。
  4. 運用網絡地圖觀點,優化機構內部的網絡事故演練情境。
詳細摘要

1) 文檔概述
本文檔為「跨行業網絡地圖(Cyber Map)練習」的技術說明,由香港金融管理局(HKMA)、證券及期貨事務監察委員會(SFC)、保險業監管局(IA)及強制性公積金計劃管理局(MPFA)共同制定。目的是透過數據建模,視覺化香港金融體系的互聯性,以防範系統性網絡風險。

2) 主要要求

  • 數據蒐集架構 採用三層模型,包含:
  • 第一層: 金融服務。
  • 第二層: 關鍵營運與支援應用。
  • 第三層: 底層 IT 基礎設施組件。
  • 視覺化呈現 利用儀表板技術,以節點大小表示依賴程度(受信任程度),連線粗細與顏色表示關聯屬性(如數據傳輸、系統託管),並區分參與金融機構與 ICT 服務供應商。

3) 關鍵變更

  • 從傳統「單一機構風險評估」轉向「系統互聯風險評估」。
  • 引入了基於業務與技術依賴關係的量化映射,取代過去較為定性的風險評估報告方式。

4) 重要日期與過渡安排

  • 2025 年底 啟動首次數據蒐集。
  • 2026 年 7 月 29 日 正式發布技術說明文件(標誌首份地圖繪製完成)。

5) 對機構的影響與風險

  • 營運 機構需持續更新與協力廠商(第三方)的技術連結資料。
  • 數據 需進行精細化的資料清理(Data cleansing),確保上報的依賴關係符合三層架構定義。
  • 合規 若被歸類為高集中度節點,未來可能面臨更嚴格的網絡安全審計或更頻繁的壓測要求。

6) 合規動作清單 (Checklist)

  • [ ] 盤點並確認與外部單位(供應商/其他 FI)的所有「關鍵營運」關聯。
  • [ ] 驗證內部數據分類是否對齊監管的三層架構要求。
  • [ ] 評估若主要 ICT 服務商中斷,本機構在「地圖」上的傳染路徑與影響範圍。
  • [ ] 確保內部網絡風險評估範疇包含監管地圖中的節點關聯性。

7) 附件/附錄摘要

  • Diagram 1 (數據收集 methodology) 詳細闡述三層架構的關聯邏輯,是機構填報數據的基礎準則。
  • Diagram 2 (網絡關係圖解) 展示節點標記、連線邏輯及篩選器功能,說明如何透過地圖執行情境分析,是理解監管層如何解讀機構數據的關鍵參考。