
Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) came into force on 1 January 2026. For designated operators, cybersecurity is now a defined operating obligation with clear ownership, recurring assessment and incident-response requirements. That change is increasing demand for professionals who can connect technical security work with governance, documentation and communication.
The Ordinance was passed by the Legislative Council on 19 March 2025. It covers eight essential-service sectors: energy, information technology, banking and financial services, maritime, land transport, air transport, healthcare, and communications and broadcasting. It also applies to infrastructure that sustains major social and economic activities, including major sports and performance venues and technology parks.
The Commissioner's Office under the Security Bureau oversees the regime, with designated authorities such as the Hong Kong Monetary Authority and the Communications Authority responsible for specified sectors. Designated operators must maintain an office in Hong Kong and establish a computer-system security management unit supervised by an appointed employee.
Their duties also include notifying material changes to critical computer systems, implementing a security management plan, conducting annual risk assessments and regular audits, participating in security drills, maintaining an emergency response plan and reporting incidents within the required timeframe. Depending on the offence, maximum fines range from HK$500,000 to HK$5 million.
The legislation creates work across several disciplines. Employers need people who understand security controls, but they also need professionals who can turn those controls into policies, evidence, reporting and practical action across the business.
Technical certifications and audit experience can strengthen a candidate's profile, but employers should also look for clear writing, stakeholder management and the ability to explain risk to non-technical decision-makers.
Before opening a vacancy, HR and the security function should agree whether the role owns governance, hands-on operations, assurance, vendor oversight or a combination of these responsibilities. A broad title without clear authority can attract the wrong applicants and make it difficult to assess the experience that matters most.
The JD should state the systems and business areas in scope, reporting line, incident responsibilities, audit exposure and expected interaction with regulators or designated authorities. Employers should also distinguish between work that must remain under the supervision of an appointed employee and specialist support that may be obtained from external providers.
Organisations outside the designated sectors should still expect stronger competition for cybersecurity talent. The same candidates are often considered by banks, technology companies, healthcare organisations, transport operators and professional-services firms, so a credible career path and realistic role scope matter.
Candidates should show how their work affected business risk, compliance readiness or incident outcomes. A list of tools is less useful than evidence of what you assessed, what decision you recommended, how you worked with stakeholders and what changed as a result.
Cybersecurity hiring was already competitive. The new statutory framework gives designated operators a clearer reason to build permanent capability, which is likely to increase demand for professionals who can combine technical knowledge with governance and sound judgement.
For employers, the priority is to define the security mandate before going to market. For candidates, the strongest position is a record of practical delivery supported by clear evidence. If you are building a cybersecurity team or considering your next move, contact the iTalent team for a confidential discussion. You can also review our latest opportunities.
Copyright© iTalent Company 2026. All Rights Reserved.