2026-07-29
Added · Updated
The Hong Kong Monetary Authority, Securities and Futures Commission, Insurance Authority, and Mandatory Provident Fund Schemes Authority advise financial institutions on the outcomes of the first cross-sectoral Cyber Mapping exercise. While no new systemic cyber risks were identified, the exercise revealed that certain third-party service providers, particularly in network infrastructure, cybersecurity solutions, payment processing, and customer communication, warrant increased supervisory attention due to widespread adoption patterns. The Authorities will integrate the Cyber Map into their supervisory work, especially for third-party risk and incident management, and plan to conduct the Cyber Mapping exercise on a recurring basis, with the next iteration expected in 2027/2028.
Search
Popup advanced search keywords
Advanced search
All of these words:
Any of these words:
The exact phrase:
None of these words:
Popup search form
Close
29 Jul 2026 Ref: HKMA/B1/15C SFO/IS/028/2026 INS/TEC/10/48 SU/CTR/2026/002
To: Chief Executives of all Authorized Institutions and Stored Value Facility Licensees
Chief Executive Officer of the Hong Kong Interbank Clearing Limited
Officers of all Designated Retail Payment Systems
Responsible Officers of all Licensed Corporations
Chief Executives of all Authorized Insurers
Chief Executives of all MPF Approved Trustees
Joint Circular on the Cross-Sectoral Cyber Mapping Exercise
The Hong Kong Monetary Authority (“HKMA”), the Securities and Futures Commission (“SFC”), the Insurance Authority (“IA”), and the Mandatory Provident Fund Schemes Authority (“MPFA”) (collectively referred to as “the Authorities”) issue this joint circular to advise the industry on the outcomes of the first production run of the cross-sectoral Cyber Mapping exercise.
Background
Against a backdrop of rapid digitalisation, the global financial system has become more interconnected. Financial institutions (“FIs”) now increasingly rely on a complex network of shared technologies, infrastructures and third-party service providers. While these developments support innovation and efficiency, they also raise the risks of a single point of failure and that a cyber incident targeting one common party (e.g. a technology service provider) could propagate across the broader financial system.
While the Authorities have continually driven cyber resilience enhancements in their respective sectors, the “borderless” nature of cyber threats required an ecosystem response. In light of this, the Authorities collaborated to take forward a Cyber Mapping exercise with the support of the Financial Services and the Treasury Bureau (“FSTB”). This initiative was aligned with the International Monetary Fund (“IMF”)’s analytic framework 1 , and informed by a recommendation given under the Financial Sector Assessment Program (“FSAP”), aiming to develop a Cyber Map to enhance the Authorities’ understanding of cyber risk concentration and interdependencies within the financial system in Hong Kong.
Key takeaways from first production run
The first production run of the Cyber Mapping exercise was completed in March 2026. It delivered a Cyber Map that allowed the Authorities to visualise, for the first time, how over 50 participating FIs across the banking, retail payment, securities and capital markets, mandatory provident fund and insurance sectors are connected at both business and technology levels.
The Authorities have drawn three key takeaways from the Cyber Map:
There are no new and major “unknown-unknown” sources of systemic cyber risk . Specifically, the Cyber Map reaffirmed that the largest nodes in the Hong Kong financial system are those FIs, financial market infrastructures, and major technology service providers (e.g. cloud service providers, data centre operators) and data service providers already known to support critical business and technology functions.
That said, a deeper analysis of specific business processes and information and communication technology (“ICT”) arrangements revealed that certain third-party service providers playing critical roles within their areas of expertise might warrant increased supervisory attention moving forward. In particular, similar adoption patterns were observed in participating FIs’ use of network infrastructure appliances and cybersecurity solutions that support security event monitoring and privileged access management. Certain recurring specialist vendors were also observed in select payment processing and customer communication workflows.
While this takeaway does not mean that the providers identified are unsafe, or that a systemic issue already exists, it does support the case for early, and forward-looking supervisory monitoring.
Cyber Mapping is a useful risk management tool for the Authorities and potentially FIs in the future.
In addition to enabling the visual depiction of potential systemic cyber risks, the dashboard-based design of the Cyber Map allows the Authorities to dynamically filter outcomes based on a scenario at hand and turn complex data sets into actionable insights. These capabilities are particularly useful in supporting more precise third-party risk supervision and triaging of and response to incidents. Building on this experience, there may be potential, in the future, to extend the Cyber Map’s dashboard capabilities to FIs (for data relevant to them) to support their own risk management and incident handling.
While the Cyber Map did not reveal any immediate sources of systemic cyber risk outside the Authorities’ current supervisory radar, it reaffirmed that the financial sector is highly interconnected, and that these connections are becoming increasingly complex as the technology landscape and role of third parties continues to evolve. This underscores the importance of the Authorities’ ongoing portfolios of work to enhance cyber resilience, including that focusing on strengthening FIs’ capabilities across the full cyber risk management lifecycle.
Going forward, the Authorities will adopt the Cyber Map to complement their day-to-day supervisory work, especially in the areas of third-party risk and incident management. Where warranted, the Authorities will also leverage relevant insights distilled from the Cyber Map and take forward additional cross-sectoral collaboration as needed, such as conducting drill exercises, thematic reviews, and developing additional contingency arrangements. For the technical details of the Cyber Map – including underlying data collection methodology – please see the Technical Note attached at Annex . The Authorities will, where appropriate, also share insights and supervisory feedback specific to the FIs that participated in the first production run on a bilateral and confidential basis.
Further work
Noting the Cyber Map’s strong value proposition, the Authorities intend to make the Cyber Mapping exercise a recurring fixture. Efforts are underway to consolidate the experience gained and feedback received throughout the first production run to enhance the exercise methodology, refine the data scope, expand the participant coverage, and develop permanent and sustainable infrastructure. During development, the Authorities will continue to be guided by the overarching principles applied to the first production run, including that of only collecting data necessary for producing an effective Cyber Map, and placing top priority on ensuring data security. Based on current estimates, the Authorities expect to commence the next Cyber Mapping exercise in 2027/2028. More details will be shared with the industry well in advance.
The Authorities are fully committed to strengthening the resilience of the financial system. We appreciate the support from FIs that participated in the first production run and look forward to continued collaboration with the broader industry.
Carmen Chu Eric Yip Executive Director Executive Director of Intermediaries (Banking Supervision) Securities and Futures Commission Hong Kong Monetary Authority
Clement Lau Kenneth Chan Executive Director Executive Director (Members and Supervision) Policy and Legislation Mandatory Provident Fund Schemes Authority Insurance Authority
1 Please see the IMF’s Paper on “Cybersecurity Risk Supervision” (24 September 2019) and “Good Practices in Cyber Risk Regulation and Supervision” (5 January 2026)
Click here to download the document Supplementary document Annex Page last updated : 29 Jul 2026