contingency plans for cybersecurity incidents and organize drills periodically.
The departments responsible for protecting critical information infrastructure security shall formulate
contingency plans for cybersecurity incidents for their respective industry or field, and periodically organize
drills.
In cybersecurity incident contingency plans, the cybersecurity incidents shall be classified on the basis of
factors such as the degree of harm and the scope of influence after the incident occurs, and corresponding
emergency disposal measures shall be prescribed.
Article 54 When the probability of causing cybersecurity incidents increases, relevant departments of the
people's governments at provincial level or above shall, in accordance with the authorization and procedures
stipulated, adopt the following measures according to the characteristics of and possible harm from the
cybersecurity risks.
1. Request the relevant departments, institutions and personnel to promptly collect and report relevant
information, and strengthen the monitoring over cybersecurity risks;
2. Organize the relevant departments, institutions and professionals to analyze and assess cybersecurity risks
information and predict the likelihood of the occurrence of, scope of influence of and degree of harm from
the incidents; or
3. Release an early warning concerning cybersecurity risks to the public and take measures to prevent and
mitigate any harm arising therefrom.
Article 55 For the occurrence of cybersecurity incidents, it is necessary to activate contingency plans for
cybersecurity incidents immediately, investigate and assess such incidents, require network operators to take
technical measures and other necessary measures to eliminate potential security hazards, prevent expansion
of the harm, and promptly issue warning information in relation to the public to society.
Article 56 The relevant departments of the people's governments at provincial level or above may hold an
interview with the legal representatives or principals of the network operators in accordance with prescribed
authorizations and procedures upon discovery of relatively high security risks or security incidents on the
network. Network operators shall take measures to effect rectification and eliminate hidden dangers as
required.
Article 57 Emergency incidents or work safety accidents caused by cybersecurity incidents shall be handled in
accordance with the Emergency Response Law of the People's Republic of China, the Work Safety Law of the
People's Republic of China and other relevant laws and administrative regulations.
Article 58 In the case of demands to protect the national security and social public order, and respond to
major social emergent security incidents, upon the decision or approval by the State Council, the competent
departments may take restriction and other temporary measures on network communications within specific
regions.
Chapter VI Legal Liability
Article 59 Network operators, who fail to perform the obligation of protecting cybersecurity as stipulated by
Article 21 or Article 25 of this Law, shall be ordered to effect rectification and be warned by the relevant
competent departments. Where they refuse to effect rectification, or such consequences as endangering
cybersecurity are caused, a fine of no less than CNY10,000 but no more than CNY100,000 shall be imposed;
as for the persons directly in charge, a fine of no less than CNY5,000 but no more than CNY50,000 shall be
imposed.
Operators of critical information infrastructure who fail to perform the obligation of cybersecurity protection
as stipulated by Article 33, Article 34, Article 36 and Article 38 of this Law, shall be ordered to effect
rectification and be given a warning. Where they refuse to effect rectification, or such consequences as
9