Chairman’s message

Dear Members, Industry Experts, and Colleagues,
The Cyberspace Administration of China's most recent Internet Development Report confirms that China's cybersecurity industry has moved decisively into a phase defined by "AI-driven innovation" and "compliance-led maturity". Since gaining full internet access in 1994, China has enacted over 150 cyberspace governance laws, with 2025 marking the final year of the 14th Five-Year Plan and a sharp intensification of digital oversight, including tightened rules on live streaming, online payments, and algorithmic manipulation. The industry is now valued at roughly RMB 135 billion with a 15% CAGR, propelled by "Xinchuang" domestic substitution, AI-native threat detection, and stricter Critical Infrastructure Protection regulations. Deepfake-enabled fraud and supply chain vulnerabilities remain the fastest-growing risk categories, reinforcing the need for adaptive, cross-border security frameworks.
Hong Kong's legislative landscape has advanced substantially since the Bill's passage. The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) officially came into operation on January 1, 2026, rather than merely being "set to take effect," and was accompanied by the establishment of the Office of the Commissioner of Critical Infrastructure (Computer-system Security), or OCCICS. In January 2026, OCCICS further issued a formal Code of Practice detailing statutory obligations for designated operators, giving the regime real enforcement teeth. Together with the National Security Law framework in force since 2023, these measures place Hong Kong among the most legally mature cybersecurity jurisdictions in the region.
Against this backdrop, HKCNSA has translated its founding vision into concrete action over the past year. In June 2026, the Association's flagship "HKCNSA Symposium," themed "Compliance vs. Achieving Business Objectives: From Data Privacy to AI Governance," gathering government, industry, and academic participants to Hong Kong to confront AI-era governance and critical infrastructure protection head-on. In March 2026, HKCNSA signed a Memorandum of Understanding with Hong Kong Metropolitan University to formalize long-term collaboration on cybersecurity talent development and education, directly delivering on the Association's talent-cultivation pledge. Membership has also grown, with SGS Hong Kong joining as a corporate member in April 2026 to advance digital trust assurance and international standards adoption, while the latest research partnership with Sia, "Cybersecurity Beyond the Tools: Investments, Vendor Selection, and Strategic Decision-Making in Hong Kong," uncovers where investment, governance, and talent strategies fall short.
HKCNSA remains steadfast in its mission to serve as the bridge connecting the cybersecurity communities of Mainland China, Hong Kong, and Macau. We believe that closing the gaps our research has uncovered is a journey no single organization can complete alone, and that is why we extend a heartfelt invitation to every enterprise, professional, and expert who shares our commitment to a safer digital Hong Kong: come stand with us, share your experience, and help shape the solutions our industry needs. Together, let us turn insight into action and build a cybersecurity future that is not only secure and trustworthy, but truly resilient for generations to come.
David Ip
Founding Chairman of the Hong Kong China Network Security Association

