contingency plans for cybersecurity incidents and organize drills periodically. The departments responsible for protecting critical information infrastructure security shall formulate contingency plans for cybersecurity incidents for their respective industry or field, and periodically organize drills. In cybersecurity incident contingency plans, the cybersecurity incidents shall be classified on the basis of factors such as the degree of harm and the scope of influence after the incident occurs, and corresponding emergency disposal measures shall be prescribed. Article 54 When the probability of causing cybersecurity incidents increases, relevant departments of the people's governments at provincial level or above shall, in accordance with the authorization and procedures stipulated, adopt the following measures according to the characteristics of and possible harm from the cybersecurity risks. 1. Request the relevant departments, institutions and personnel to promptly collect and report relevant information, and strengthen the monitoring over cybersecurity risks; 2. Organize the relevant departments, institutions and professionals to analyze and assess cybersecurity risks information and predict the likelihood of the occurrence of, scope of influence of and degree of harm from the incidents; or 3. Release an early warning concerning cybersecurity risks to the public and take measures to prevent and mitigate any harm arising therefrom. Article 55 For the occurrence of cybersecurity incidents, it is necessary to activate contingency plans for cybersecurity incidents immediately, investigate and assess such incidents, require network operators to take technical measures and other necessary measures to eliminate potential security hazards, prevent expansion of the harm, and promptly issue warning information in relation to the public to society. Article 56 The relevant departments of the people's governments at provincial level or above may hold an interview with the legal representatives or principals of the network operators in accordance with prescribed authorizations and procedures upon discovery of relatively high security risks or security incidents on the network. Network operators shall take measures to effect rectification and eliminate hidden dangers as required. Article 57 Emergency incidents or work safety accidents caused by cybersecurity incidents shall be handled in accordance with the Emergency Response Law of the People's Republic of China, the Work Safety Law of the People's Republic of China and other relevant laws and administrative regulations. Article 58 In the case of demands to protect the national security and social public order, and respond to major social emergent security incidents, upon the decision or approval by the State Council, the competent departments may take restriction and other temporary measures on network communications within specific regions. Chapter VI Legal Liability Article 59 Network operators, who fail to perform the obligation of protecting cybersecurity as stipulated by Article 21 or Article 25 of this Law, shall be ordered to effect rectification and be warned by the relevant competent departments. Where they refuse to effect rectification, or such consequences as endangering cybersecurity are caused, a fine of no less than CNY10,000 but no more than CNY100,000 shall be imposed; as for the persons directly in charge, a fine of no less than CNY5,000 but no more than CNY50,000 shall be imposed. Operators of critical information infrastructure who fail to perform the obligation of cybersecurity protection as stipulated by Article 33, Article 34, Article 36 and Article 38 of this Law, shall be ordered to effect rectification and be given a warning. Where they refuse to effect rectification, or such consequences as 9

Select target paragraph3