Joint Circular on the Cross-Sectoral Cyber Mapping Exercise

Jul 29, 2026
Latest News SFC Joint Circular on the Cross-Sectoral Cyber Mapping Exercise

On July 29, 2026, the HKMA, SFC, IA, and MPFA issued a joint circular regarding the first production run of the cross-sectoral Cyber Mapping exercise. Completed in March 2026, the exercise involved over 50 participating FIs and found no new major unknown systemic cyber risks, though highlighted the need for increased supervisory attention on certain third-party service providers. The Authorities plan to make this exercise recurring, with the next run expected in 2027/2028.

This article was generated using SAMS, an AI technology by Timothy Loh LLP.

On July 29, 2026, the Hong Kong Monetary Authority ("HKMA"), the Securities and Futures Commission ("SFC"), the Insurance Authority ("IA"), and the Mandatory Provident Fund Schemes Authority ("MPFA") (collectively referred to as the Authorities) issued a joint circular ("Refs: HKMA/B1/15C, SFO/IS/028/2026, INS/TEC/10/48, SU/CTR/2026/002") to advise the industry on the outcomes of the first production run of the cross-sectoral Cyber Mapping exercise.

Regulatory Context and Strategic Alignment

Amidst rapid digitalisation and heightened global financial interconnectivity, Financial Institutions ("FIs") increasingly rely on complex networks of shared technologies and third-party service providers. While enhancing innovation, these developments introduce systemic risks where cyber incidents targeting common parties could propagate across the financial system. To address this borderless threat landscape, the Authorities collaborated with the Financial Services and the Treasury Bureau ("FSTB") to conduct a Cyber Mapping exercise, aligned with the International Monetary Fund ("IMF") analytic framework and Financial Sector Assessment Program ("FSAP") recommendations.

Key Findings from the March 2026 Production Run

Completed in March 2026, the exercise delivered a Cyber Map visualizing connections for over 50 participating FIs across banking, retail payment, securities, capital markets, mandatory provident fund, and insurance sectors. The Authorities derived three key takeaways: first, no new major unknown-unknown sources of systemic cyber risk exist, reaffirming that largest nodes are known FIs and infrastructure providers. Second, specific ICT analysis indicates certain third-party service providers warrant increased supervisory attention regarding adoption patterns in network infrastructure and cybersecurity solutions, without implying they are unsafe. Third, the dashboard-based design serves as a useful risk management tool, allowing dynamic filtering of complex data sets into actionable insights.

Future Supervisory Integration and Next Steps

While no immediate systemic risks outside current supervisory radar were identified, the high interconnectivity underscores the necessity for enhanced cyber resilience across the full risk management lifecycle. The Authorities will adopt the Cyber Map to complement day-to-day supervision, particularly in third-party risk and incident management, and will leverage insights for additional cross-sectoral collaboration such as drill exercises and thematic reviews. Technical details regarding data collection methodology are available in the attached Technical Note, while specific supervisory feedback will be shared bilaterally and confidentially with participating FIs.

Implementation Roadmap and Signatories

The Authorities intend to make the Cyber Mapping exercise a recurring fixture, consolidating experience to enhance methodology and expand participant coverage, with the next exercise expected in 2027/2028. Data collection will prioritize security and necessity. The circular was signed by Carmen Chu (Executive Director, Banking Supervision, HKMA), Eric Yip (Executive Director of Intermediaries, SFC), Clement Lau (Executive Director Policy and Legislation, IA), and Kenneth Chan (Executive Director (Members and Supervision), MPFA). Footnote 1 references the IMF's Paper on Cybersecurity Risk Supervision (24 September 2019) and Good Practices in Cyber Risk Regulation and Supervision (5 January 2026).

View the full article:Source

We use cookies to enhance your experience of our websites and to enable you to register when necessary. By continuing to use this website, you agree to the use of these cookies. For more information and to learn how you can change your cookie settings, please see our Cookie Policy and our Privacy Notice.