ZeroHour
CyberScooppublished ()ingested @Bing_Chris

China's new law calls on private industry to hand over valuable cyberthreat data

criticalData breach exploited in the wildimportance 60
Tagsbreach
Full article1,025 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The new year marked the beginning of yet another Chinese cybersecurity regulation that may affect U.S. technology companies operating overseas.

The new year marked the beginning of yet another Chinese cybersecurity law that could have a big impact on U.S.-based technology companies.

Known as the “Public Internet Cybersecurity Threat Monitoring and Mitigation Measures,” the rules call on private companies conducting business in China to report and hand over cyberthreat information to the government’s Ministry of Industry and Information Technology (MIIT).

China founded the MIIT in 2008 in order to regulate the country’s burgeoning information technology industry.

The law instructs companies to turn over information regarding both cyberattacks they’ve faced and also any “cyberthreat intelligence” they own. Cyberthreat intelligence is typically collected by cybersecurity firms and software giants like Microsoft and used to strengthen security operations.

The regulation states: “after cybersecurity threats are discovered by relevant professional organizations, basic telecommunication enterprises, cybersecurity enterprises, Internet companies, domain name registration management and service organs … information shall be submitted to MIIT, provincial, autonomous region, and municipal communications authorities in a timely manner and in according with the content, indicators, and format of relevant regulations.”

This continuous stream of data would be fed into a centralized, national “cyberthreat database” partially managed by the Chinese Computer Emergency Response Technical Team/Coordination Center (CN-CERT), according to other recently uncovered Chinese policy documents.

It’s unclear how the Chinese government would use the database.

Impacted companies range from internet service providers to larger commercial technology platform developers. Those that fail to comply could find themselves subject to hefty fines or worse.

“Where a basic telecommunications companies, internet companies, domain name registration management and service organ, etc. fail to take measures to deal with cybersecurity threats in accordance with notified requirements … the telecommunications departments shall … arrange questioning, issue warnings, institute fines, and other administrative penalties,” the legislation notes.

Despite the deadline, experts believe there won’t be immediate enforcement in order to encourage some level of voluntary participation.

“So far the vast majority of enforcement actions on the cybersecurity law have focused on content violations—by domestic Chinese companies,” said Samm Sacks, a senior fellow in the Technology Policy Program at the Center for Strategic and International Studies. “I have not seen the government start to enforce parts of the cybersecurity law where there is still lack of internal consensus about scope/implementation.”

The overarching policy plan, if successful, could one day provide the Communist Party of China (CPC) with a wealth of active intelligence about hackers, data breaches, software vulnerabilities and other digital threats.

The policy is unlike anything currently in place between the U.S. government and private companies. While the U.S. government regularly cooperates cybersecurity firms and major technology companies to investigate cyber crimes, it does so without the same sort of leverage.

This “regulation is the latest example in a series of moves by the Chinese government designed to guard network infrastructure and private enterprises against large-scale cyberattacks,” explained Paul Triolo, head of the geo-technology practice at the Eurasia Group. “The fact that these regulations are published by the MIIT suggests that they are laying down a bureaucratic marker on their authority.”

The policy is companion legislation for China’s historic “Cybersecurity Law” that went into effect in June, experts say.

Although the law’s enactment concerned American business executives, it has been difficult to gauge whether its had an effect on companies’ bottom line.

Premier U.S. technology brands such as Facebook, Apple, Microsoft, Cisco and Google, each of whom currently do business in China,  could be impacted by the newly launched MIIT policy. All five companies did not respond to multiple requests for comment.

Read the law below.

[documentcloud url=”http://www.documentcloud.org/documents/4341736-MIIT-CybersecPlatformLaw.html” width=675 height=500]

More Scoops

Digital legal compliance and government regulation concept with security icons, creative graphic style, on blurred US flag background. 3D Rendering. ismagilov, istock/Getty Images Plus

Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

The administration set a target date of September for CISA to finalize the rule, but where the agency is headed remains a mystery to some.

WASHINGTON, DC – MARCH 20: Federal Communications Commission (FCC) Chairman Brendan Carr (R) speaks with Sen. Dan Sullivan (R-AK) after attending the presentation of the Commander-in-Chief trophy in the East Room of the White House March 20, 2026 in Washington, DC. U.S. President Donald Trump presented the Commander-in-Chief Trophy to the Navy Midshipmen football team, the winner of the 2025 Army-Navy football game. (Photo by Chip Somodevilla/Getty Images)

Critics call FCC router rule a ‘big swing’ that could create more supply chain uncertainty

Chairman of the House Committee on Homeland Security U.S. Rep. Andrew Garbarino, R-N.Y., talks to Secretary of Homeland Security Kristi Noem prior to a hearing in the Cannon House Office Building on Dec. 11, 2025. (Photo by Anna Moneymaker/Getty Images)

Key lawmaker says Congress likely to kick can down road on cyber information sharing law

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/china-cybersecurity-law-threat-intelligence/