HONG KONG INSURANCE AUTHORITY
Guideline on Cybersecurity (GL20)
Validate that your cybersecurity controls meet GL20 and CRAF requirements. Continuously test control effectiveness and maintain audit-ready evidence for the Insurance Authority.
What Is GL20?
GL20 is the Insurance Authority's Guideline on Cybersecurity, issued under section 133 of the Insurance Ordinance. It sets the minimum cybersecurity standard for authorized insurers operating in Hong Kong, requiring them to protect business data, policyholder information, and operational continuity through resilient cybersecurity measures.
GL20 is backed by the Cyber Resilience Assessment Framework (CRAF), a structured assessment that measures both inherent cyber risk and the maturity of an insurer's cybersecurity controls against prescribed control principles across seven domains. CRAF assessments must be submitted to the IA, and gaps must be remediated within defined timelines.
Stay Compliant with GL20 and Prove Control Effectiveness with Continuous Validation
Why GL20 Compliance is Important
GL20 compliance requires more than documenting policies or deploying security tools. Insurers must demonstrate, with defensible evidence, that cybersecurity controls remain effective as environments and threats change.
Test whether cybersecurity controls actually block, detect, and respond to the attack techniques that CRAF evaluates.
Produce time-stamped, auditable evidence of control performance throughout the three-year assessment cycle, not just when assessments are due.
When controls fall short, get clear direction on what to fix specific to the security tools in the insurer's environment.
Validate defenses against realistic, multi-stage attack scenarios mapped to current threat intelligence, as CRAF Domain 5.5 requires.
A Practical Guide to GL20 Compliance Using Picus
Learn how to move GL20 compliance beyond documentation. This guide shows how validating security controls with real attack behavior delivers defensible, audit-ready evidence for CRAF assessments
Strengthen GL20 Compliance with Attack Simulation and Automated Penetration Testing
Breach and Attack Simulation (BAS) and Automated Penetration Testing close the gap between compliance requirements on paper and actual protection in practice.
Customer's Choice
2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation
What Our Customers Say
Picus is very good attack simulation tool in overall. It shows all security vulnerabilities and guides..
Sr. Information Security & Risk Officer
The implementation was very fast, the platform is easy to integrate and results quite intuitive to be analyzed.
CIO
A very successful platform where we can test the accuracy of our security investments and see their scores.
Manager, IT Security and Risk Management
Picus is one of the best BAS solution on the market today. The threat database it is constantly updated..
ICT Security Engineer
There is a very nice team from which I can get quick support. The application provides us with great convenience and confidence in our work.
Information Security Specialist
With the help of this product we can perform continuosly endpoint attack via latest tactics and techniques which are used by threat actors..
Manager, IT Security and Risk Management
.. It is possible to customise the campaign or schedule the assessment periodically, to test protection measure implemented on network, endpoint and email.
ICT Security Engineer
Picus is such a great product for organizations that are looking to have constant checks and validation on their security posture in the organization.
Cybersecuirty Pre-sales Engineer
Picus is a real safety measurement tool. Ever since we took Picus into our inventory, Security has helped significantly to increase our maturity level.
Cyber Defense Senior Specialist
It strengthened our security perspective and allowed us to follow trend attacks. We can test zeroday malicious threats very early because Picus could add them their attack database quickly.
Security Specialist
Picus for Compliance
See the
Picus Security Validation Platform
Request a Demo
Submit a request and we'll share answers to your top security validation and exposure management questions.
Get Threat-ready
Simulate real-world cyber threats in minutes and see a holistic view of your security effectiveness.
Frequently Asked Questions
GL20 is the Insurance Authority's Guideline on Cybersecurity, issued under section 133 of the Insurance Ordinance. It sets minimum cybersecurity standards for authorized insurers in Hong Kong and requires them to protect business data, policyholder information, and operational continuity.
GL20 applies to all authorized insurers in Hong Kong, except captive insurers and marine mutual insurers. CRAF applies more broadly, with additional exceptions including Lloyd's, special purpose insurers, and insurers in run-off.
CRAF is the Cyber Resilience Assessment Framework under GL20. It provides a structured method to assess inherent risk and cybersecurity maturity across seven domains. Assessments must be conducted regularly and submitted to the IA.
CRAF assessments must be conducted at least every three years. They may also be performed more frequently after major changes, and the IA may request ad hoc assessments.
TIBAS stands for Threat Intelligence Based Attack Simulation under CRAF Domain 5.5. It requires insurers with medium or high risk to simulate real-world attack scenarios based on threat intelligence, with at least three scenarios tested every three years.
The seven domains are Governance, Identification, Protection, Detection, Response and Recovery, Situational Awareness, and Third Party Risk Management. Each domain includes control principles across different maturity levels.
GL20 is not legally binding. However, non-compliance may affect the IA's assessment of the insurer's management and may be considered when evaluating actions that could impact policyholders.
.png?width=161&height=136&name=gartner-logo-2025%201%20(1).png)
