- Purpose / Background: The HKMA is addressing the heightened cyber threat landscape driven by "frontier" Artificial Intelligence (AI) models. These models enable faster, more frequent, and sophisticated attacks by automating the exploitation of zero-day vulnerabilities.
- One-line conclusion: AIs must transition from purely preventative cyber security models to resilience-based frameworks that prioritize rapid incident response, recovery, and third-party supply chain security.
- Key Changes:
- Shift in focus toward recovery and response capabilities alongside prevention.
- Enhanced expectations for third-party service provider cyber-risk assessments.
- Introduction of the Cyber Resilience Testing Framework (CRTF) for stress-testing "breach" scenarios.
- Implementation of the Protection of Critical Infrastructures (Computer Systems) Ordinance (PCICSO) Sectoral Code of Practice (CoP).
- Key Dates / Deadlines:
- 2 June 2026: PCICSO Sectoral Code of Practice (CoP) came into operation.
- Late 2026: Initial test run of the CRTF with selected institutions.
- Applicability / Impact scope: All Authorized Institutions (AIs), with specific regulatory obligations for those designated as Critical Infrastructure (CI) operators under the PCICSO.
- Recommended management actions:
- Conduct a gap analysis of existing "defense-in-depth" and "zero-trust" controls against AI-accelerated threats.
- Review and update incident response playbooks, ensuring third-party providers are integrated into recovery exercises.
- Evaluate the necessity of implementing or upgrading Secure Tertiary Data Backups (STDB).
- Designate CI operators must ensure alignment with the new PCICSO Sectoral CoP.
- Actively participate in the newly established HKMA Task Force on AI-Driven Cyber Risks to stay abreast of intelligence.
1) Document overview
The circular serves as a regulatory reminder and mandate for AIs to modernize their cyber defenses in response to the evolution of frontier AI models, which can identify zero-day vulnerabilities and reduce the need for human intervention in cyber-attacks.
2) Main requirements
- Defense Assessment: Review current defenses (zero trust, patching, etc.) assuming the increased speed and scale of AI-assisted attacks.
- Third-Party Risk: Extend risk management to include supply chain vulnerabilities and ensure third-party vendors are resourced for incident response.
- Incident Recovery: Critically review playbooks; conduct scenario testing specifically for "breach" situations.
- Data Resilience: Review the implementation of Secure Tertiary Data Backups (STDB) as a safeguard against destructive attacks.
3) Key changes
- Move toward a "response-and-recovery" centric framework rather than purely "detection-and-prevention."
- Formalized coordination with the Commissioner of Critical Infrastructure (Computer-system Security) regarding incident reporting and systemic compliance.
4) Important dates & transition
- 2 June 2026: PCICSO Sectoral CoP effective date.
- Late 2026: Target for initial test run of the new Cyber Resilience Testing Framework (CRTF).
5) Impact and risks
- Operations: Increased burden for stress-testing and incident simulations.
- Compliance: New statutory obligations for Designated AIs under PCICSO; potential for increased regulatory scrutiny on supply chain/third-party arrangements.
- IT: Potential need to invest in advanced data backup infrastructure (STDB).
6) Compliance action checklist
- [ ] Review and document the adequacy of current cyber-controls against AI-based threats.
- [ ] Evaluate current third-party contracts for incident response obligations and resource capability.
- [ ] Perform a feasibility/readiness check for STDB implementation.
- [ ] For Designated AIs: Map current organizational/preventive controls to the new PCICSO Sectoral CoP.
- [ ] Participate in upcoming industry briefings by the HKMA Task Force.
7) Appendices/attachments summary
- Memorandum of Understanding (MoU): Details the coordination framework between the HKMA and the Commissioner of Critical Infrastructure (Computer-system Security) to streamline compliance under the PCICSO.
- Sectoral Code of Practice (CoP): Provides technical/practical guidance for Designated AIs to fulfill category 1 and 2 obligations under the PCICSO, effective 2 June 2026.