Recent SFC disciplinary action highlights growing regulatory expectations regarding cybersecurity governance, operational resilience and incident preparedness.
Cybersecurity has traditionally been viewed as a technical function to be managed by information technology teams. Recent regulatory developments suggest that this perspective is no longer sufficient. The Securities and Futures Commission (“SFC“) is increasingly treating cyber resilience as a matter of governance, operational resilience and regulatory compliance, with clear expectations that senior management take active responsibility for managing cybersecurity risk.
The SFC’s recent disciplinary action against a licensed corporation following a ransomware attack provides a useful illustration of these expectations in practice. When considered together with the SFC’s broader cybersecurity initiatives and more recent guidance regarding AI-enabled cyberattacks, a clear regulatory trend emerges: firms will increasingly be judged not only on whether they suffer a cyber incident, but also on whether they have implemented adequate and effective cybersecurity controls, exercised appropriate oversight and demonstrated the resilience necessary to withstand and recover from cyber threats.
The lessons are relevant not only to licensed corporations, but also to asset managers, family offices and private wealth structures that increasingly rely on technology, remote access arrangements and third-party service providers.
A Recent Regulatory Reminder
The recent disciplinary action arose from a ransomware attack reported by a Hong Kong licensed corporation in September 2022. According to the SFC’s findings, a hacker exploited weaknesses in the firm’s remote access environment and disrupted the critical IT infrastructure, including file servers, email servers, domain controllers, trading application servers and accounting servers. Recovery took approximately three weeks.
During that period, clients were unable to access the firm’s internet platform and mobile trading application and could only place orders through account executives.
What makes the case particularly significant is what did not occur. The SFC expressly recorded that there was no evidence of unauthorised trading, client financial losses, misappropriation of client assets, leakage of client information or client complaints.
Nonetheless, the SFC publicly reprimanded the firm and imposed a financial penalty after concluding that its cybersecurity controls and governance arrangements were deficient and failed to comply with applicable regulatory requirements.
The case therefore demonstrates that disciplinary action may arise even where a cyber incident does not result in client loss. The regulator’s focus was on whether the firm had implemented and maintained adequate systems and controls and whether those deficiencies contributed to the firm’s inability to withstand and recover from the incident.
The SFC’s Focus on Resilience and Control Failures
A notable feature of the disciplinary action is that the SFC’s criticism was directed not simply at the occurrence of a ransomware attack, but at the firm’s lack of cyber resilience.
The investigation identified deficiencies in network security controls, user access and privileged account management, operating systems, antivirus protection, remote access arrangements, password management, cybersecurity awareness training and external device security.
The SFC found that these deficiencies contributed both to the firm’s inability to withstand the attack and to the severity of the resulting disruption. Particularly significant were the backup and recovery shortcomings. Daily backups were stored on external hard drives that were not consistently disconnected from the network, resulting in the backup files themselves being compromised during the incident. The firm’s business continuity plan also failed to adequately address ransomware and data-loss scenarios, significantly impeding recovery efforts.
The disciplinary action therefore sends a broader message: regulators are increasingly concerned with operational resilience and preparedness, not merely technical prevention.
Cyber Resilience Is an Increasing Supervisory Priority
The recent disciplinary action should not be viewed in isolation.
In September 2023, the SFC announced an industry-wide thematic cybersecurity review of selected licensed corporations, stating expressly that cybersecurity is a major focus of its supervision. The review examined cybersecurity governance, incident reporting, cloud security, remote access controls, technology lifecycle management and third-party technology vendor risks.
The SFC has consistently identified recurring weaknesses across the industry, including the use of end-of-life software, inadequate remote access controls, phishing vulnerabilities and weaknesses in third-party technology arrangements.
Notably, many of the deficiencies identified in the recent disciplinary action, including weaknesses relating to remote access, authentication controls, patch management and staff awareness, closely mirror risks highlighted by the SFC in its 2020 circular on remote working arrangements and 2025 thematic cybersecurity review report. This demonstrates that regulatory guidance may ultimately become the benchmark against which firms’ systems and controls are assessed.
More recently, the SFC has warned licensed firms about the growing risks posed by AI-enabled cyberattacks. According to the regulator, advances in AI are increasing both the sophistication and frequency of cyber threats while reducing the time available for firms to respond to vulnerabilities. In response, the SFC has, once again, emphasised patch management, access controls, monitoring, third-party oversight and incident response preparedness.
Viewed in this context, the recent disciplinary action appears less as an isolated enforcement case and more as part of a broader supervisory programme aimed at strengthening cyber resilience across the financial services industry.
Why This Matters Beyond the IT Department
A consistent theme across recent SFC publications is that cyber resilience is fundamentally a management responsibility.
The SFC’s 2017 guidelines on cybersecurity and related publications place responsibility on senior management for establishing cybersecurity frameworks, approving policies, allocating resources and overseeing contingency planning. The SFC has also expressly emphasised that senior management, including the Manager-in-Charge of Information Technology, bears ultimate responsibility for managing cybersecurity risks faced by licensed firms.
This reflects an increasingly common regulatory view that cyber resilience should be treated alongside operational risk, compliance and business continuity as a core governance issue.
Technical specialists remain essential. However, many of the matters highlighted by regulators extend beyond technology and into governance structures, management accountability, outsourcing arrangements, vendor contracts, incident reporting, escalation procedures, business continuity planning and regulatory compliance.
A recurring theme in recent SFC publications is the growing importance of third-party technology risk. Many firms rely heavily on cloud service providers, software vendors and managed service providers, yet outsourcing does not transfer regulatory responsibility. The SFC has repeatedly emphasised vendor due diligence, access controls, ongoing monitoring, concentration risk assessments and contractual incident-notification requirements.
An effective cyber resilience framework therefore requires coordination among management, compliance personnel, legal advisers and technical specialists.
What Family Offices Should Pay Attention To
Although family offices are generally not subject to the same regulatory framework as licensed corporations, many face similar risks. Industry publications suggest that family offices are increasingly targeted because they often hold substantial assets and sensitive information while operating with smaller teams and less formalised cybersecurity frameworks.
The threat landscape is also evolving beyond traditional hacking techniques. Family offices may be particularly vulnerable to business email compromise, payment instruction fraud, adviser impersonation, AI-enabled voice cloning and deepfake-enabled fraud.
Takeaways
The SFC’s recent cybersecurity enforcement action reinforces a broader regulatory message: cyber resilience is now fundamentally a governance issue. Technology controls remain important, but so do oversight, decision-making structures, incident preparedness and management accountability.
The disciplinary findings, viewed alongside the SFC’s remote working guidance, industry-wide cybersecurity reviews and more recent warnings concerning AI-enabled cyber threats, reveal an increasingly sophisticated supervisory framework focused on resilience, preparedness and accountability.
For licensed corporations, asset managers and family offices alike, the key question is no longer simply whether systems can prevent every cyber incident. Rather, it is whether the organisation can demonstrate that it has taken adequate and effective steps to manage cybersecurity risk, maintain resilience, respond effectively to incidents and recover in a manner consistent with emerging regulatory expectations.
This article discusses the SFC’s disciplinary action announced on 28 July 2026 concerning cybersecurity control deficiencies identified following a ransomware incident, together with related SFC cybersecurity guidance and supervisory publications. Readers may wish to review the original SFC materials for further details.
Further information: https://apps.sfc.hk/edistributionWeb/gateway/EN/news-and-announcements/news/doc?refNo=26PR118