The State Administration of Financial Supervision and Administration of China publicly solicits opinions on the draft Measures for the Administration of Cybersecurity in the Banking and Insurance Industry

Securities Daily Follow 2026-07-10 21:26

On July 10th, the State Administration for Financial Regulation (hereinafter referred to as the "State Administration for Financial Regulation") announced that in order to strengthen the supervision and management of network security in banking and insurance financial institutions, as well as financial holding companies, and standardize network security work, the State Administration for Financial Regulation has drafted the "Measures for the Administration of Network Security in Banking and Insurance Industry (Draft for Comments)" (hereinafter referred to as the "Measures"), which are now open for public comments.

The Measures implement the decisions and deployments of the Party Central Committee and the State Council on network security, adhere to coordinated development and security, promote the implementation of laws and regulations such as the Cybersecurity Law, the Data Security Law, the Personal Information Protection Law, and the Regulations on the Security Protection of Key Information Infrastructure, and provide support for the State Administration of Financial Regulation to better fulfill its responsibilities in regulating the network security and key information infrastructure of banking and insurance financial institutions, as well as financial holding companies. The content of the "Measures" is consistent with the "Financial Industry Network Security Management Measures (Draft for Comments)" that was publicly solicited for opinions on July 3.

The Measures consist of eight chapters and seventy-two articles, providing clear requirements in core areas such as network security governance, network security construction and operation management, network security risk monitoring, network security incident response and disposal, critical information infrastructure management, and supervision and management.

The drafting of the "Measures" mainly follows the following ideas: firstly, to implement the requirements of higher-level laws, ensure the effective implementation of relevant national laws and regulations in the banking and insurance industries, and clarify the implementation path. The second is to draw on practical experience, summarize the effectiveness of technology supervision work in recent years, transform practical experience into institutional achievements, and improve work mechanisms. The third is to fully consider the business characteristics of banking, insurance, and financial institutions, promote the implementation of network security protection responsibilities, embody the concept of big network security, and emphasize the network security governance concept of unified management, technology and business collaboration, and coordinated governance of the three lines of defense throughout the group. The fourth is to reflect hierarchical and classified management, and on the basis of proposing overall network security management requirements for banking, insurance, and financial institutions, higher requirements are proposed for key information infrastructure management.

Welcome valuable opinions from all sectors of society. The State Administration for Financial Regulation will carefully study the feedback from all parties, further revise and improve the Measures, and timely release and implement them.

(Editor Li Jiaqi)

Disclaimer: The views expressed in this article are for reference and communication only and do not constitute any advice.