With ever increasing numbers of cyberattack incidents in Hong Kong and the heightened risk posed by frontier artificial intelligence (AI) models, the SFC issued a Circular to Licensed Corporations, SFC-licensed Virtual Asset Service Providers and Associated Entities: Enhanced Cybersecurity Measures to Address Evolving Risks Arising From Artificial Intelligence-enabled Cyberattacks requiring SFC-licensed corporations and virtual asset service providers (VATPs) and their associated entities (together, SFC-licensed firms) to review and improve their cybersecurity measures to meet evolving threats. The circular, issued on 2 June 2026, highlights the responsibility of SFC-licensed firms’ senior management, including the Manager-in-Charge of Information Technology, for managing firms’ cybersecurity risks and requires Managers-in-Charge of Information Technology to ensure the review, approval and implementation of improvements to firms’ cybersecurity measures to safeguard their operations and protect clients’ interests. Where necessary, firms are expected to appoint IT security expects to advise them.
The circular’s Appendix sets out illustrative examples of suggested controls and procedures for each of the cybersecurity areas covered in the circular. Licensed firms conducting electronic trading, particularly large retail brokers, depositaries of SFC-authorised collective investment schemes (i.e. corporations licensed for Type 13 regulated activity) and VATPs are expected to implement all the measures set out in the Appendix, whereas other SFC-licensed firms are expected to take them into consideration depending on the nature, scale and complexity of their businesses, their dependency on technology and exposure to cybersecurity risks.