Business Support

Technical Support

About Guangxun

About Ainopol

New Cybersecurity Rules Take Effect in 2026: All-Optical Networks Help Office Buildings and Industrial Parks Complete Network Self-Inspection and Rectification
2026-09-12 11:56:59 14

New Cybersecurity Rules Take Effect in 2026: All-Optical Networks Help Office Buildings and Industrial Parks Complete Network Self-Inspection and Rectification

Effective October 1, 2026, the Measures for Public Security Organs’ Supervision and Inspection of Cyberspace Security (Ministry of Public Security Order No.176) will be officially implemented, replacing Order No.151 issued in 2018. Compared with the previous version, the new measures expand the scope of supervision and inspection to cyberspace security fields including network security, data security and information security. It also specifies multiple inspection methods: online patrols, vulnerability scanning, remote detection and on-site examinations.

For office buildings and industrial parks, network security rectification is no longer merely about “having firewalls and written policies”. Office networks, guest networks, access control, surveillance, conference systems and networks operated by different enterprises within the building coexist for a long time. Uncontrolled terminal access, improperly configured permissions or ineffective security appliances can all become entry points for network risks.

Rather than rushing to patch vulnerabilities right before inspections, enterprises should conduct systematic network security self-inspections in advance. Check and remediate hidden risks in the campus network across network architecture, terminal admission, access permissions and security protection.

I. Network Self-Inspection for Office Buildings and Parks: Focus on Security Vulnerabilities, Not Just Hardware

  1. Is the network open for any connected device?
    Office buildings and industrial parks host diverse personnel. In addition to employee PCs, there are a large number of dumb terminals such as printers, cameras, access control units and conference endpoints. If the network adopts a simple plug-and-play port model, unknown devices can access the internal network once connected.

More critically, without clear access boundaries between different enterprises and departments, once one terminal is compromised, attackers may use the interconnected internal network for lateral scanning and expand the scope of impact.

Therefore, the first priority in self-inspection is to verify: whether terminals require identity authentication, whether device access is permission-controlled, and whether clear isolation boundaries exist between different business zones.

  1. Are internal network permissions easy to grant but hard to revoke?
    Staff turnover, job transfers and temporary project collaboration occur frequently in enterprises. Traditional networks often suffer from shared accounts, permanently retained privileges and delayed deletion of accounts for resigned employees.

These seemingly administrative issues can easily turn into cybersecurity vulnerabilities.

Self-inspections should cover not only “who can access the internet”, but also “what resources each user can access”. Office staff should not be able to freely access sensitive systems for finance, R&D and HR simply by connecting to the campus network. Guest terminals should also be segregated from the enterprise core network.

  1. Even with perimeter security appliances, can real attacks be blocked?
    Deploying a firewall at the network boundary does not equal full security. Attack vectors including web server vulnerabilities, malicious files, abnormal access and virus propagation keep evolving. Without intrusion prevention, web attack defense and malware detection, campus networks still have significant exposed attack surfaces.

In particular, systems commonly deployed in office parks such as OA, ERP and enterprise portals require thorough inspection of their defense capabilities and the ability to detect and block abnormal access promptly once exposed online.

  1. Can a complete chain of evidence be preserved when network incidents happen?
    Network security self-inspection goes beyond identifying existing problems. It must also ensure traceability after security incidents occur.

Records of who connected to the network, connection time, accessed resources and response measures taken after anomalies are essential. Without centralized logging, security incidents often lead to situations where “no evidence can be found and facts cannot be clarified”.

As such, network logs, access records, security events and related audit information form key components of campus network self-inspections.

II. All-Optical Networks Embed Security Capabilities Into Network Architecture to Close the Rectification Loop

Faced with increasingly stringent cybersecurity inspection requirements, simply adding more security hardware cannot resolve all network issues for parks. A more sensible approach is to redefine security boundaries at the underlying network layer and build a full closed loop covering access, isolation, permission control, protection and auditing.

  1. Build on all-optical architecture to segregate different networks
    Zhihui Guangxun’s enterprise all-optical network can divide network zones based on campus business requirements. Logical isolation is deployed for office, R&D, finance, HR, guest and security monitoring services, mitigating lateral movement risks found in traditional flat networks where everything is interconnected.

On this foundation, terminal identity and access permission controls are enforced, so users can only access authorized business systems instead of gaining excessive network access after connecting.

For multi-tenant office buildings, this architecture further enables network isolation between tenants and prevents unnecessary cross-enterprise network communication.

  1. Upgrade from “plug-and-play port access” to “identity-based admission”
    All-optical networks handle not only data transmission but also integrate access control at the network edge.

Through identity authentication, MAC address whitelisting and port binding, terminals including employee PCs, printers, cameras and access control devices are managed by category. Unauthorized unknown terminals cannot freely join the internal network. Fixed devices can be bound to corresponding ports and identities to reduce security risks brought by unauthorized device access or device tampering.

Under this model, the campus security perimeter is no longer limited to a single firewall at the egress. The defense line starts right at terminal access.

  1. Front-load IPS, WAF and other capabilities to block external attacks promptly
    For business systems such as OA, ERP and web portals in office parks, Zhihui Guangxun builds more complete security boundaries with integrated cybersecurity capabilities.

IPS identifies and blocks network attacks, while WAF defends against web application-layer attacks. Combined with malware detection, it delivers multi-layer defense against external intrusions, malicious access and abnormal traffic.

The paradigm shifts from “patching vulnerabilities after discovery” to “blocking attacks before they penetrate”, enabling campus network security to evolve from passive rectification to active protection.

  1. All-optical network + Zero Trust + Converged Connectivity & Security: Elevate security from isolation to trust
    For scenarios involving cross-regional data transmission, core business access and high data confidentiality requirements, network isolation alone is insufficient.

Zhihui Guangxun embeds Zero Trust principles into all-optical networks. User and terminal identities are verified before access is granted, and access is approved only according to business permissions. Least-privilege rules and behavior auditing reduce internal privilege escalation risks.

For data transmission security, the converged connectivity-security framework can be adopted to jointly design communication networks and cryptographic security capabilities. Network construction focuses not only on stable data delivery but also effective protection of data in transit, delivering comprehensive safeguards for critical campus business data.

  1. Unified management: turn one-off self-inspection into continuous O&M
    The real challenge of cybersecurity rectification is not discovering vulnerabilities, but sustaining improvements after remediation.

Zhihui Guangxun all-optical networks leverage a unified management platform to centrally manage network devices, terminals, policies and services, consolidating network configurations and security rules previously scattered across separate hardware.

When staff changes, new devices are added or network permissions adjusted, policy updates can be completed quickly. For abnormal terminals or network faults, the unified platform and log data support rapid localization, easing manual device-by-device troubleshooting workloads.

In 2026, cybersecurity supervision expands to cover broader cyberspace security. Self-inspections for office buildings and industrial parks should no longer stop at checking hardware deployment. Inspectors must verify whether the network is manageable, controllable, isolable, traceable and protected.

For parks undergoing network renovation or security rectification, continuously stacking hardware on legacy architectures is less ideal than redesigning from the network foundation. Built upon all-optical infrastructure, integrating terminal admission, service isolation, Zero Trust, security defense, log auditing and converged connectivity & security enables campus networks to progress beyond mere inspection compliance toward persistent security.

Completing cybersecurity self-inspections before the new rules officially take effect, and closing the loop for risk detection, remediation and long-term operation, is a more reliable approach for office buildings and industrial parks to meet the new round of cybersecurity requirements.

FAQ

Q: What impacts will Order No.176 bring to office buildings and industrial parks?
A: Regulated entities expand from two original categories to eight. Operators of office buildings and industrial parks act simultaneously as network operators, data processors and personal information processors. Inspection items are extended to data security and algorithm security, with new remote vulnerability scanning and penetration testing added to inspection methods.

Q: What standards apply to log retention?
A: User registration and internet access logs must be recorded and retained in accordance with the law, typically for no less than 6 months (180 days). Log fields must include real-name information, IP address, MAC address, login/logout timestamps and visited URLs. The Mengxiang series gateways from Zhihui Guangxun feature built-in local storage and support one-click export of compliance reports.