Threat intelligence vendors
Technical feeds deliver indicators of compromise. We deliver the direction of cybersecurity policy, with the analytical edge a board meeting needs.
The current developments in Chinese cybersecurity, analyzed from the perspective of foreign companies and without false alarm.
The China Cyber Update is a monthly briefing on Chinese cybersecurity, data regulation and AI policy. Original reports from new laws and regulations are weighed and analyzed in their political context, without which they often remain unintelligible. With an enforcement radar. Written for CIOs, CISOs, CEOs and boards. Published without interruption since August 2021, now in its sixth year.
The current month in geopolitics, cyber and data regulation, reported and placed in context, briefly.
Plus a chapter written for each subscriber every month. Regulatory changes and enforcement with a direct effect on your company.
Every significant development since 2021, summarized briefly. Arrive mid-year and still get the whole picture.
Subscribers are mostly CIOs, CISOs, risk officers and general counsel at multinationals with important China operations.
Technical feeds deliver indicators of compromise. We deliver the direction of cybersecurity policy, with the analytical edge a board meeting needs.
An alert arrives once the new law or regulation is final. We give the important warnings months earlier.
Expensive one-off studies deliver temporary snapshots. We deliver continuity.
We work from Chinese primary sources. Notices from the Cyberspace Administration of China (CAC), ministry announcements, draft and final national standards, court records and Chinese business media.
The work runs by the rules of a newsroom. Every claim is evidenced, every number checked against the original document, official Chinese claims double-checked.
Three national laws, one State Council regulation and a large body of technical standards. Current as of August 2026. We provide orientation, not legal advice.
In force since 1 June 2017. An amendment took effect on 1 January 2026. It writes state support for artificial intelligence into the law, reaches conduct outside China that endangers Chinese network security.
In force since 1 September 2021. It grades data by importance to the state and raises obligations with the grade. The category of important data comes from here.
In force since 1 November 2021. China’s counterpart to the European GDPR, governing consent, processing and the export of personal information.
In force since 1 January 2025. The first State Council regulation implementing all three laws together.
The Ministry of Public Security grades systems one to five. Obligations tighten sharply from level three. The standards behind MLPS 2.0 apply since 1 December 2019 and reach cloud platforms, industrial control systems and the internet of things.
Three routes. A security assessment by the Cyberspace Administration of China, since 1 September 2022. A standard contract, since 1 June 2023. Certification, since 1 January 2026. Provisions of 22 March 2024 exempted non-sensitive data on fewer than 100,000 people a year, and transfers needed for trade, cross-border HR and contract performance.
The Interim Measures for the Management of Generative AI Services apply since 15 August 2023. Labelling of AI-generated content, visibly and in file metadata, since 1 September 2025.
The central internet regulator. It leads rulemaking and enforcement under all three laws, runs cybersecurity reviews and approves cross-border data transfers.
Administers the Multi-Level Protection Scheme and carries the police powers behind cybersecurity enforcement.
The national technical committee for cybersecurity standards. Its GB/T standards are formally voluntary and supply the detail regulators judge compliance by, so foreign companies treat them as binding.
What matters to a board is the sequence. A standard is drafted, a consultation opens, a rule follows, enforcement arrives later. Read the first step and you have time. Wait for the alert and you do not.
Prices on request, tiered by the degree of customization for each company. Single and enterprise licenses are available.
Yes. The sample is a real edition with client-specific detail and the cumulative report removed, so the reporting, the sourcing and the judgment stay visible.
A threat feed reports indicators of compromise. We report which direction Chinese policy is taking and what it means for a foreign company.
Usually in English, and in other languages on request.