HONG KONG INSURANCE AUTHORITY

Guideline on Cybersecurity (GL20)

Validate that your cybersecurity controls meet GL20 and CRAF requirements. Continuously test control effectiveness and maintain audit-ready evidence for the Insurance Authority.

 

What Is GL20?

GL20 is the Insurance Authority's Guideline on Cybersecurity, issued under section 133 of the Insurance Ordinance. It sets the minimum cybersecurity standard for authorized insurers operating in Hong Kong, requiring them to protect business data, policyholder information, and operational continuity through resilient cybersecurity measures.

GL20 is backed by the Cyber Resilience Assessment Framework (CRAF), a structured assessment that measures both inherent cyber risk and the maturity of an insurer's cybersecurity controls against prescribed control principles across seven domains. CRAF assessments must be submitted to the IA, and gaps must be remediated within defined timelines.

Stay Compliant with GL20 and Prove Control Effectiveness with Continuous Validation

Why It Matters

Why GL20 Compliance is Important

GL20 compliance requires more than documenting policies or deploying security tools. Insurers must demonstrate, with defensible evidence, that cybersecurity controls remain effective as environments and threats change.

Validate Control Effectiveness

Test whether cybersecurity controls actually block, detect, and respond to the attack techniques that CRAF evaluates.

Maintain Assessment-Ready Evidence

Produce time-stamped, auditable evidence of control performance throughout the three-year assessment cycle, not just when assessments are due.

Close Gaps with Vendor-Specific Guidance

When controls fall short, get clear direction on what to fix specific to the security tools in the insurer's environment.

Support TIBAS Requirements

Validate defenses against realistic, multi-stage attack scenarios mapped to current threat intelligence, as CRAF Domain 5.5 requires.

Requirements

What GL20 Compliance Requires

A breakdown of each GL20 and CRAF requirement and how Picus helps insurers demonstrate control effectiveness with evidence.

GL20 Section 4 Overview of CRAF
CRAF Chapter 3 Cybersecurity Maturity Assessment
CRAF Chapter 1 Assessment Approach
CRAF Chapter 2 Inherent Risk Rating Assessment
CRAF Domain 5.5 Threat Intelligence Based Attack Simulation (TIBAS)
GL20 Section 8 Continuous Monitoring
CRAF Domain 4 Detection
CRAF Domain 3 Protection
GL20 Section 7 Risk Identification, Assessment and Control
PRACTICAL GUIDE

A Practical Guide to GL20 Compliance Using Picus

Learn how to move GL20 compliance beyond documentation. This guide shows how validating security controls with real attack behavior delivers defensible, audit-ready evidence for CRAF assessments

VALIDATED & COMPLIANT
APPROACH

Strengthen GL20 Compliance with Attack Simulation and Automated Penetration Testing

Breach and Attack Simulation (BAS) and Automated Penetration Testing close the gap between compliance requirements on paper and actual protection in practice.

Validate security controls across all seven CRAF maturity domains by simulating the attack techniques those controls are designed to stop.
Test defenses against end-to-end attack scenarios mapped to current threat intelligence, supporting TIBAS requirements for medium and high risk insurers.
Identify detection blind spots, misconfigured rules, and protection gaps across hybrid infrastructure before they become assessment findings.
Produce auditable, time-stamped evidence of control performance that assessors and validators can reference when evaluating operating effectiveness.
mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

gartner-logo-2025 1 (1)

Customer's Choice

2025 Gartner Peer Insights Voice of the Customer for Adversarial Exposure Validation

mid-strip-gray-mobile mid-strip-gray
mid-strip-gray-mobile mid-strip-gray

G2-winter-badge-standart-size

BAS Category Leader

Ranked #1 by Users on G2

What Our Customers Say

resources

Picus for Compliance

Pattern-mobile Pattern(1)

See the
Picus Security Validation Platform

Request a Demo

Submit a request and we'll share answers to your top security validation and exposure management questions.

Get Threat-ready

Simulate real-world cyber threats in minutes and see a holistic view of your security effectiveness.

Frequently Asked Questions

GL20 is the Insurance Authority's Guideline on Cybersecurity, issued under section 133 of the Insurance Ordinance. It sets minimum cybersecurity standards for authorized insurers in Hong Kong and requires them to protect business data, policyholder information, and operational continuity.

GL20 applies to all authorized insurers in Hong Kong, except captive insurers and marine mutual insurers. CRAF applies more broadly, with additional exceptions including Lloyd's, special purpose insurers, and insurers in run-off.

CRAF is the Cyber Resilience Assessment Framework under GL20. It provides a structured method to assess inherent risk and cybersecurity maturity across seven domains. Assessments must be conducted regularly and submitted to the IA.

CRAF assessments must be conducted at least every three years. They may also be performed more frequently after major changes, and the IA may request ad hoc assessments.

TIBAS stands for Threat Intelligence Based Attack Simulation under CRAF Domain 5.5. It requires insurers with medium or high risk to simulate real-world attack scenarios based on threat intelligence, with at least three scenarios tested every three years.

The seven domains are Governance, Identification, Protection, Detection, Response and Recovery, Situational Awareness, and Third Party Risk Management. Each domain includes control principles across different maturity levels.

GL20 is not legally binding. However, non-compliance may affect the IA's assessment of the insurer's management and may be considered when evaluating actions that could impact policyholders.