Most organisations still picture cybersecurity as something that happens at the edge of their own network. That mental model stopped being accurate years ago. Your payroll runs on a SaaS platform. Your customer data sits with a cloud provider. Your infrastructure is maintained by a managed service partner with privileged remote access, and your software product ships with dozens of open-source components you did not write and cannot fully see.

Every one of those relationships is a path into your environment. And in Hong Kong, as of 2026, managing those paths is no longer just good practice — for a growing number of organisations, it is a legal obligation with financial consequences attached. A comprehensive approach to Information Security Management Systems is now required to address these expanding digital footprints and maintain regulatory compliance.

Two men are sitting in front of computers, looking at analyses.
Loading...

The regulatory floor has moved — and it has moved onto your suppliers

Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) came into force on 1 January 2026, accompanied by a Code of Practice issued by the newly established Office of the Commissioner of Critical Infrastructure (Computer-system Security). It applies to designated critical infrastructure operators across eight sectors, including banking and financial services, healthcare, energy, telecommunications, transport and information technology.

The detail that matters most to the wider market is this: designated operators are required to adopt measures ensuring their third-party service providers meet the relevant obligations, and the Code of Practice goes as far as providing model contract clauses for use with external service providers. Contractors are made answerable for the conduct of their own personnel and their subcontractors.

The practical consequence is a flow-down effect. Throughout 2026, designated operators have been renegotiating supplier contracts to push statutory obligations down the chain. If you supply software, analytics, logistics, cloud services or professional services to a designated operator, the Ordinance reaches you contractually even though it does not name you directly. The assumption that this regime only concerns a handful of large designated entities is the most expensive misreading available.

The pattern is not unique to Hong Kong. Under the EU's NIS2 Directive, supply chain security sits explicitly within the required risk-management measures, and responsibility for approving and overseeing those measures rests with management bodies personally. Our white paper mapping NIS2 Article 21 requirements against ISO 27001 sets out that comparison in detail. Across jurisdictions, the direction of travel is the same: regulators have stopped accepting "our vendor was breached" as an explanation.

Landingpage Header MAtriX App 1800 x 800 V2
Loading...

Where third-party risk management actually breaks down

Nearly every organisation with a third-party risk management programme runs annual security questionnaires. Nearly every organisation with a serious breach in its supplier chain also ran them. The gap between those two facts is where the real work lies.

The questionnaire measures the wrong thing

A security questionnaire is typically completed by a sales or compliance contact, not by the engineers who run the environment. It captures a documented intention at a single moment. The breach happens in the eleven months between assessments, in a system nobody asked about, configured by someone who never saw the questionnaire.

Onboarding rigour decays

Scrutiny is highest before a contract is signed and lowest afterwards — precisely inverted from where the risk actually sits. Access granted for a three-week integration project is still live three years later.

Fourth parties are invisible

Your vendor's subprocessors, their cloud region, their offshore support desk. Hong Kong's Code of Practice addresses this directly by making contractors responsible for their subcontractors, which tells you regulators have noticed the same blind spot.

Procurement has left the building

Business units subscribe to SaaS tools on a corporate card without an IT or security review. This shadow procurement is now, in many organisations, the single largest category of unmanaged third-party exposure.

IT measurement
Loading...

Not all third parties carry the same risk — stop treating them as if they do

A single generic assessment process applied to every supplier produces the worst of both worlds: heavy administrative burden and weak assurance. Segment by the mechanism of exposure, not by contract value.

Data-processing relationships

SaaS platforms, outsourced customer service, analytics providers. The controlling questions concern data flows, retention, cross-border transfer and subprocessor disclosure. Under Hong Kong's Personal Data (Privacy) Ordinance, a data user engaging a processor is expected to use contractual or other means to prevent unauthorised access, retention beyond necessity, or loss — the accountability does not transfer with the data.

System-access relationships

Managed service providers, remote support vendors, integrators. Here the questions are about privilege, credential management, network segmentation and lateral movement. A compromised support account with standing administrative rights is not a vendor problem; it is your incident. Where the third party is a cloud provider, CSA STAR assessment offers cloud-specific assurance that a generic questionnaire cannot.

Product-embedded relationships

Software components, OEM modules, embedded firmware. The questions concern software bills of materials, vulnerability disclosure practices and patch cadence. You inherit every weakness in the code you ship, whoever wrote it.

Different mechanisms, different controls. Applying cloud-vendor questions to a firmware supplier produces documentation, not security.

Data Center dark blue
Loading...

Contract clauses that survive contact with a real incident

Two clauses deserve far more attention than they usually receive.

Notification timing

"Notify within 72 hours of a breach" is close to meaningless without defining the trigger. Seventy-two hours from what — occurrence, detection, or internal confirmation? Vendors often learn of their own compromise from a fourth party, which pushes your notification well past your own regulatory clock. Under the Hong Kong Ordinance, serious incidents affecting critical computer systems must be reported to the Commissioner within a matter of hours; a supplier clause measured in days cannot support that obligation. Specify: within 24 hours of becoming aware of any incident that may affect our data or systems, whether or not investigation is complete. Preliminary notification beats confirmed notification.

Audit and evidence rights

A right to audit that requires ninety days' notice and mutual agreement on scope is decorative. More useful in practice: a right to receive the vendor's most recent independent assessment reports, penetration test summaries, and certification documentation on request, within a defined window — plus notification of any material change to certification status.

Checklist Automotive
Loading...

What certification does and does not tell you

Certification is one of the strongest signals available in vendor risk assessment— but only if you read it correctly, and this is where a great deal of assurance is lost.

An ISO 27001 certificate is not a blanket guarantee. It confirms that an information security management system has been assessed against the standard within a defined scope, documented in the organisation's Statement of Applicability. That scope may cover a head-office function and exclude the very business line, data centre or product team that serves you. The first question to ask a certified supplier is not "are you certified?" but "what is your certified scope, and does it include the service we are buying?"

Read correctly, though, ISO 27001 is genuinely informative. Its supplier-relationship controls require the certified organisation to manage security in its own supply chain — meaning a properly scoped certificate gives you visibility one layer deeper than a questionnaire ever will. It also evidences something a point-in-time assessment cannot: an operating management system, subject to surveillance audits, with defined ownership and continual improvement.

Where personal data is central to the relationship, ISO 27701 extends the management system into privacy information management, addressing exactly the controller–processor accountability that the PDPO and GDPR both impose.

For automotive supply chains, TISAX® solves a different and very practical problem. Its value is mutual recognition: an assessment result can be shared with multiple participating partners, replacing repeated bilateral audits of the same supplier. For suppliers, that means one rigorous assessment rather than a dozen inconsistent ones. For manufacturers, it means comparable, standardised assurance across a fragmented supplier base.

And where the third party supplies AI capability — an increasingly common and poorly governed category — ISO/IEC 42001 provides management-system requirements specific to AI, covering the governance questions that information security standards alone were never designed to answer.

Frequently asked questions

What is third-party risk management?

Third-party risk management is the process of identifying, assessing, monitoring and controlling the risks an organisation inherits from suppliers, service providers and other external parties with access to its data, systems or operations. It covers the full relationship lifecycle — from due diligence before contracting, through contractual controls and ongoing monitoring, to secure offboarding when the relationship ends.

 

Does ISO 27001 certification mean a supplier is secure?

Not automatically. ISO 27001 certification confirms that an information security management system has been independently assessed within a defined scope. If that scope excludes the service you are purchasing, the certificate provides limited assurance for your specific relationship. Always request the certificate together with the Statement of Applicability and confirm the scope covers the relevant service, location and business unit.

 

Are suppliers covered by Hong Kong's critical infrastructure cybersecurity law?

The Ordinance imposes obligations directly on designated critical infrastructure operators, not on suppliers generally. However, operators are required to take measures ensuring their third-party service providers meet the relevant requirements, and the Code of Practice supplies model contract clauses for that purpose. Suppliers to designated operators are therefore bound contractually, and non-designated organisations are encouraged to treat the Code as a benchmark for good practice.

 

How often should vendors be reassessed?

Frequency should follow risk tier rather than a single organisation-wide schedule. Suppliers with privileged system access or large volumes of sensitive data warrant annual reassessment supported by continuous external monitoring; lower-risk suppliers may be reviewed every two to three years. More important than the interval are event-driven triggers: a change of ownership, a publicly reported incident, a material change in the service, or a lapse in certification status should each prompt immediate review.

 

Contact Us

Reviewing your supplier assurance approach, or preparing for scrutiny from a customer who is? Talk to our experts about certification scope, audit readiness and supply chain assurance.

Talk to our experts
Author

DQS Hong Kong

DQS Hong Kong specialises in certification auditing and training services across core disciplines including Information Security (ISO 27001), Quality Management (ISO 9001), and the Automotive Industry (IATF 16949). Our auditors bring deep sector-specific expertise, working closely with clients' operational realities to deliver actionable management insights and lasting commercial value — well beyond the boundaries of compliance alone.

Loading...

You Might Also Enjoy These Reads

Discover more articles that dive deep into related themes and ideas.
Blog
Loading...

Certification, Always. Cybersecurity Today: The New Gatekeeper for Chinese Medical Device Exports

Blog
Loading...

EU AI Grace Period Extended by 16 Months: How Businesses Can Cut the Red Tape and Balance Governance with Speed

Blog
Loading...

SRAA vs ISO 27001 Certification