circular

Circular to intermediaries Cybersecurity review of selected licensed corporations

ID 24951

The Securities and Futures Commission (SFC) has issued a circular addressed at financial market intermediaries to inform that it will launch a cybersecurity review of selected licensed corporations (LCs) to evaluate LCs‘ cybersecurity management, compliance, and information system resilience against cyber threats. This review aligns with the SFC’s emphasis on cybersecurity and follows a review of recent cybersecurity incidents and on-site inspections which revealed various security vulnerabilities such as the use of end-of-life software (the vendor no longer supports the product) or inadequate controls against remote access and phishing attacks.
Thus, to evaluate the industry’s readiness and resilience to cyber risks, particularly those firms using third-party providers and / or relying on cloud services, the SFC will conduct a cybersecurity review in September 2023. This review will include
1. a survey of selected LCs of various sizes and types, covering cybersecurity management, incident reporting, system and data integrity, cloud security, remote access controls, IT asset management, and third-party vendor risk management;
2. meetings with selected LCs „to understand their cybersecurity governance and controls“; and
3. on-site inspections of some LCs to assess their information technology controls, compliance with the SFC’s Cybersecurity Guidelines, and other standards.
The findings from this review will guide the SFC in providing further industry guidance and sharing observations with relevant stakeholders.

In this context, the SFC also reminds firms of their obligation to adhere to system security requirements outlined in the Code of Conduct. Those offering internet trading must also comply with baseline requirements specified in aforementioned Cybersecurity Guidelines, FAQs, and standards from the 2019-20 thematic cybersecurity review of internet brokers.

Other Features
assessment
broker
capital management companies
clearing
code of conduct
companies
compliance
cyber security
financial advisors
fund management
governance
investment firms
investors
regulatory
reporting
resilience
risk
securities
settlement
standard
surveys
trading
Date Published: 2023-09-15
Regulatory Framework: Securities and Futures Ordinance
Regulatory Type: circular

Circular to Management Companies of SFC-authorised Exchange Traded Funds (“ETFs”) – ...

ID 26594
The Securities and Futures Commission of Hong Kong (SFC) has issued a new circular address ...

Checklist for Application for Authorisation of Real Estate Investment Trusts

ID 26555
The Securities and Futures Commission of Hong Kong (SFC) has issued a revised version of i ...

Information Checklist for Application for Authorization of Dutch Funds under the ...

ID 26554
The Securities and Futures Commission of Hong Kong (SFC) has issued a revised version of i ...

On-Going Compliance Form for Filing of Pricing Errors

ID 26553
The Securities and Futures Commission of Hong Kong, SFC, has issued a revised form for the ...
  • Topic Filter

    Top Tag Search
    Top Tag Search
    Top Tag Search
    Top Tag Search
You are on the training version of RISP core with limited functions and data. Please subscribe to RISP core for professional or academic use. We supply free real time datasets for approved academic research; professional subscriptions start at 950€ plus VAT per annum.

Compare Listings