Strengthening Cyber Resilience amid Artificial Intelligence-Empowered Cyber Threats (2026-06-02)

Circulars Email: HKMA E-mail Alert of 03 June 2026 (05:00 p.m. HKT)

Document Information

Title: Strengthening Cyber Resilience amid Artificial Intelligence-Empowered Cyber Threats (2026-06-02)

Type: Circulars

URL: https://brdr.hkma.gov.hk/eng/doc-ldg/current/20260529-8-EN

Email Received: 2026-06-03 19:11

Summary Created: 2026-06-03 14:00

English Summary
Quick section switch
Management Summary
  • Purpose / Background: The HKMA is addressing the heightened cyber threat landscape driven by "frontier" Artificial Intelligence (AI) models. These models enable faster, more frequent, and sophisticated attacks by automating the exploitation of zero-day vulnerabilities.
  • One-line conclusion: AIs must transition from purely preventative cyber security models to resilience-based frameworks that prioritize rapid incident response, recovery, and third-party supply chain security.
  • Key Changes:
  • Shift in focus toward recovery and response capabilities alongside prevention.
  • Enhanced expectations for third-party service provider cyber-risk assessments.
  • Introduction of the Cyber Resilience Testing Framework (CRTF) for stress-testing "breach" scenarios.
  • Implementation of the Protection of Critical Infrastructures (Computer Systems) Ordinance (PCICSO) Sectoral Code of Practice (CoP).
  • Key Dates / Deadlines:
  • 2 June 2026: PCICSO Sectoral Code of Practice (CoP) came into operation.
  • Late 2026: Initial test run of the CRTF with selected institutions.
  • Applicability / Impact scope: All Authorized Institutions (AIs), with specific regulatory obligations for those designated as Critical Infrastructure (CI) operators under the PCICSO.
  • Recommended management actions:
  • Conduct a gap analysis of existing "defense-in-depth" and "zero-trust" controls against AI-accelerated threats.
  • Review and update incident response playbooks, ensuring third-party providers are integrated into recovery exercises.
  • Evaluate the necessity of implementing or upgrading Secure Tertiary Data Backups (STDB).
  • Designate CI operators must ensure alignment with the new PCICSO Sectoral CoP.
  • Actively participate in the newly established HKMA Task Force on AI-Driven Cyber Risks to stay abreast of intelligence.
Detailed Summary

1) Document overview
The circular serves as a regulatory reminder and mandate for AIs to modernize their cyber defenses in response to the evolution of frontier AI models, which can identify zero-day vulnerabilities and reduce the need for human intervention in cyber-attacks.

2) Main requirements

  • Defense Assessment: Review current defenses (zero trust, patching, etc.) assuming the increased speed and scale of AI-assisted attacks.
  • Third-Party Risk: Extend risk management to include supply chain vulnerabilities and ensure third-party vendors are resourced for incident response.
  • Incident Recovery: Critically review playbooks; conduct scenario testing specifically for "breach" situations.
  • Data Resilience: Review the implementation of Secure Tertiary Data Backups (STDB) as a safeguard against destructive attacks.

3) Key changes

  • Move toward a "response-and-recovery" centric framework rather than purely "detection-and-prevention."
  • Formalized coordination with the Commissioner of Critical Infrastructure (Computer-system Security) regarding incident reporting and systemic compliance.

4) Important dates & transition

  • 2 June 2026: PCICSO Sectoral CoP effective date.
  • Late 2026: Target for initial test run of the new Cyber Resilience Testing Framework (CRTF).

5) Impact and risks

  • Operations: Increased burden for stress-testing and incident simulations.
  • Compliance: New statutory obligations for Designated AIs under PCICSO; potential for increased regulatory scrutiny on supply chain/third-party arrangements.
  • IT: Potential need to invest in advanced data backup infrastructure (STDB).

6) Compliance action checklist

  • [ ] Review and document the adequacy of current cyber-controls against AI-based threats.
  • [ ] Evaluate current third-party contracts for incident response obligations and resource capability.
  • [ ] Perform a feasibility/readiness check for STDB implementation.
  • [ ] For Designated AIs: Map current organizational/preventive controls to the new PCICSO Sectoral CoP.
  • [ ] Participate in upcoming industry briefings by the HKMA Task Force.

7) Appendices/attachments summary

  • Memorandum of Understanding (MoU): Details the coordination framework between the HKMA and the Commissioner of Critical Infrastructure (Computer-system Security) to streamline compliance under the PCICSO.
  • Sectoral Code of Practice (CoP): Provides technical/practical guidance for Designated AIs to fulfill category 1 and 2 obligations under the PCICSO, effective 2 June 2026.
中文摘要
快速切換摘要區塊
管理層摘要
  • 目的/背景 針對前沿人工智能(A.I.)技術帶來的網絡威脅(如自動化識別零日漏洞、降低攻擊門檻),金管局提醒認可機構(AIs)必須加強網絡韌性,以應對更快速、高頻及複雜的攻擊。
  • 一句話結論 認可機構需立即重新審視現有防禦、復原與備份機制,並配合金管局新推出的韌性測試框架及《關鍵基礎設施(電腦系統)條例》(PCICSO)要求進行合規升級。
  • 關鍵變更
  1. 擴大防禦評估範疇至供應鏈與第三方服務提供商。
  2. 加強事故應變與復原程序的壓力測試(特別是針對嚴重破壞性攻擊)。
  3. 重新考慮部署「安全三級數據備份」(STDB)。
  4. 引入「網絡韌性測試框架(CRTF)」,由預防導向轉向包含復原導向的測試。
  5. 實施針對金融業的《關鍵基礎設施(電腦系統)條例》行業守則(CoP)。
  • 重要日期 / 截止日
  • 2026年6月2日: 行業守則(CoP)正式生效。
  • 2026年下半年: 網絡韌性測試框架(CRTF)開展初期試行(Pilot Test)。
  • 適用對象 / 影響範圍 全體香港認可機構(AIs),特別是已被指定為關鍵基礎設施營運商的機構。
  • 管理層建議行動
  1. 審視防禦控管 評估現有防禦機制(如零信任架構)在A.I.加速攻擊下的有效性。
  2. 強化供應鏈管理 審計第三方服務提供商的韌性能力。
  3. 更新應變劇本 針對重大網絡事故進行實戰演練與流程優化。
  4. 提升數據韌性 未實施STDB的機構應重新評估其必要性。
  5. 參與生態協作 密切關注「人工智能驅動網絡風險工作小組」發佈的情報。
詳細摘要

1) 文檔概述
本文檔為金管局就人工智能驅動的網絡威脅發出的指引,旨在提升金融體系的防禦與復原能力,並明確關鍵基礎設施相關的法規要求。

2) 主要要求

  • 防禦控管審視 要求機構檢討防禦縱深與零信任架構,特別評估在A.I.協助下大規模、高速攻擊的適應性。
  • 事故應變與復原 需批判性檢討應變劇本,並將第三方服務提供商的復原能力納入考量。
  • 數據韌性 強調部署「安全三級數據備份(STDB)」以對抗破壞性攻擊,並建議未部署的機構重新決策。

3) 關鍵變更

  • 框架重心轉移 從傳統的「預防/偵測」轉向包含「復原/重建」的全面韌性能力。
  • 合規範疇調整 明確納入PCICSO條例下的Category 1(組織)及Category 2(預防)法定義務。

4) 重要日期與過渡安排

  • 2026年6月2日: PCICSO行業守則(CoP)正式生效。
  • 2026年下旬: 目標對特定機構進行CRTF測試框架的首次試行。

5) 對機構的影響與風險

  • 營運 機構需投入資源進行更頻繁的壓力測試及應變演練。
  • 合規 被指定為關鍵基礎設施營運商(Designated AIs)的機構,面臨更高的法定合規申報壓力。
  • IT 需確保第三方節點的安全性,防止供應鏈攻擊擴散至核心系統。

6) 合規動作清單(Checklist)

  • [ ] 執行現有網絡防禦機制與供應鏈風險評估。
  • [ ] 針對「破壞性攻擊」場景修訂並測試事故應變劇本。
  • [ ] 評估並確認是否需要實施STDB。
  • [ ] 確認機構是否屬PCICSO規管對象,並參考CoP進行合規對照。
  • [ ] 建立或指派專責窗口,對接金管局即將成立的A.I.風險工作小組。

7) 附件/附錄摘要

  • 《關鍵基礎設施(電腦系統)條例》行業守則 (CoP) 於2026年6月2日生效,旨在為指定機構提供合規指引,優先簡化業界合規負擔,詳細說明了Category 1及Category 2義務的履行方式。
  • 金管局與專員備忘錄 (MoU) 明確金管局與關鍵基礎設施專員之間的分工協調,以確保監管資源的一致性,減少業界重複合規壓力。