News update: SFC circular sets cybersecurity measures against AI-enabled cyberattacks

Aug 04 2026

In January 2024, the Securities and Futures Commission (SFC) set institutional resilience and operational efficiency as one of its four strategic priorities. Since then, the SFC has stepped up its focus on cyber resilience and security as a core regulatory expectation for licensed corporations (LCs), virtual asset service providers (VATPs) and associated entities. In this news update, Pádraig Walsh from our cybersecurity practice reviews a recent SFC circular that sets out the expected regulatory standards of the SFC to respond to the growing threat posed by AI-enabled cyberattacks.[1]

Developments in the risk environment

Cybersecurity incidents in Hong Kong have been trending upwards for a number of years. 2025 saw a significant uptick in that trend. According to the HKCERT, the number of cybersecurity incidents increased to 15,877 in 2025 from 12,536 in 2024, representing a 27% year-on-year increase. HKCERT identified AI-driven attacks and agentic AI risks at the top of its five cybersecurity risks for 2026, and included AI-related issues among three of that top five.

AI has marked a step change in the pace, sophistication and effectiveness of cyberattacks. The SFC highlighted in particular:

AI is increasing the sophistication, scale and frequency of cyberattacks: Frontier AI models can plan and execute more complex multi-step actions autonomously. The spread of AI-enabled tools lowers the technical barrier for threat actors to execute malicious activities. AI-enabled tools also enable the execution of those activities with a higher degree of sophistication. This is evident, for instance, in attack vectors such as phishing and deepfake impersonation. LCs and VATPs need to reassess existing prevention, detection, response and recovery measures.

Reduced response time for remediation: AI-enabled tools have led to the rapid identification and exploitation of new vulnerabilities. The period between disclosure of a vulnerability and active exploitation is also becoming shorter. LCs and VATPs must enhance patching and vulnerability management procedures.

Regulatory expectations

The SFC has made it clear that senior management remains ultimately responsible for cybersecurity risk management. This includes the Manager-in-Charge of Information Technology (MIC-IT). It is a core responsibility of the MIC-IT to review the cybersecurity framework of the firm in question, and to review, approve and properly implement cybersecurity enhancements. The key focus should be to ensure the firm’s cybersecurity frameworks remain appropriate and effective in preventing, detecting, responding to and recovering from evolving threats.

As a general foundational principle, the SFC expects firms to maintain robust and up-to-date security controls to protect systems, client information and client assets. Firms should maintain a comprehensive and dynamic inventory of technology assets, including hardware, software, databases, cloud services and network infrastructure. Firms should also identify which assets are externally exposed, business-critical or dependent on third-party components or providers.

The circular identifies five key areas for consideration:

Patching and vulnerability management: Firms should review and strengthen patch management processes. The processes should address known vulnerabilities promptly and implement procedures for urgent and critical patches outside normal maintenance cycles.

Access and privilege controls: Firms should adopt a “zero trust” mindset. This is a design principle under which network access is not implicitly trusted based solely on network location or user status. Firms should implement robust access and privilege controls and minimise attack surfaces. This means applying least-privilege access controls, enhanced firewall protection and stronger network segmentation, among other measures.

Detection and monitoring: Firms should strengthen threat detection, system monitoring and threat intelligence capabilities.

Supply chain risk management: Firms should strengthen their supply chain risk governance framework, enhance initial and ongoing assessments of third party service providers, and prioritise potential impact from third party service providers to critical operations and business critical components.

Incident response and recovery: The SFC expects firms to review and enhance incident response procedures and contingency plans. Firms should establish swifter adequate escalation and reporting procedures to take account of the swifter pace of AI-enable attacks. Firms should consider pre-planned containment strategies, including the ability to block malicious activities, isolate affected systems and restrict access rapidly. Firms should back up records, databases, and supporting documents on a regular basis, and ensure the swift availability of the backup copies when needed.

Firms should review incident handling procedures and response plans to ensure:

(a)     the roles and responsibilities for personnel involved in the incident response;

(b)     the escalation protocols to facilitate coordinated efforts across teams, including IT, risk management, compliance, and senior management;

(c)     the pre-authorised containment actions that should be immediately implemented;

(d)     the actions required for the recovery of the firm’s operations and business continuity; and

(e)     the communication strategies with stakeholders, including clients, third party service providers, law enforcement agencies, and the SFC.

The SFC has highlighted that firms must regularly test their incident handling procedures and contingency plans through tabletop exercises and simulated attacks to assess their effectiveness. This often requires the engagement of professionals with specialist knowledge and experience. This can supplement tabletop exercises or crisis simulations. Also, external expertise is often needed for the conduct of VAPT assessments and red team exercises.

LCs and VATPs are required to report immediately to the SFC upon any material failure, error, or defect in the operation or functioning of their trading, custody, accounting, clearing, or settlement platforms, systems or equipment. This includes any material cybersecurity incident. Firms need to be equipped and prepared to make accurate and appropriate notifications.

Final thoughts

Tremendous opportunities are being realised and developed from the use of AI and AI language models by LCs and VATPs. Just as those opportunities exist for firms and users that adopt responsible and safe use of AI, they also exist for criminals and dangerous threat actors in the cyber world. The SFC circular recognises that AI-enabled tools have now created a substantially more dangerous cyber risk environment.

The SFC circular substantially raises supervisory expectations regarding cyber resilience in an AI-driven threat environment. Licensed firms should not view AI risk solely as a governance or technology adoption issue. The SFC now clearly expects firms to take account of the enhanced threat AI-enabled tools represent in their cybersecurity frameworks and ongoing compliance.

This escalated concern is not a surprise. Financial services is a critical sector of the economy. Cyber resilience is a stated core target area for the SFC. The SFC is more regularly publishing guidance on cyber risk and AI risk. There is SFC 2024 circular on use of generative AI language models. Also, we recently reviewed the SFC circular on implementing authentication methods to mitigate hacking risks from phishing attacks and monitoring measures to identify suspicious activities (see our article on this link).

This is a circular of critical importance to MIC-ITs in LCs and VAPTs. Senior management and MIC-ITs are accountable for cybersecurity preparedness and implementation. Many firms will require additional budget to allocate sufficient resources to meet the expected regulatory standards. There will be a need to external support in training, awareness and readiness for incident response, and in reviewing incident response and business continuity plans to ensure they are fit for purpose.

Cyber resilience against AI-enabled cyber attacks is at the Board table.

Pádraig Walsh

If you want to know more about the content of this article, please contact:

Pádraig Walsh

Partner | Email

Disclaimer: This publication is general in nature and is not intended to constitute legal advice. You should seek professional advice before taking any action in relation to the matters dealt with in this publication. This article was published on [4 August 2026].

[1] SFC Circular, Enhanced cybersecurity measures to address evolving risks arising from artificial intelligence-enabled cyberattacks, 2 June 2026 [link]

Tags:

Legal Updates TMT

Featured Articles

Insights
News update: SFC circular sets cybersecurity measures against AI-enabled cyberattacks
Insights
Hong Kong Court’s first recognition of Bahamian liquidation after landmark case Re USUM
Insights
News update: No phishing here – The SFC raises cybersecurity expectations for internet brokers and virtual asset trading platforms
Insights
Shaping Arbitration in 2026: a Mid-year Review of Four Significant Hong Kong Court Decisions
Insights
Case Update – FCMC 4687/2023 – Legal Costs Provision, Financial Disclosure, and Adverse Inference in Hong Kong Family Law
Insights
No second bite of the cherry? Court of Appeal to rule on whether Cap. 597 precludes common law enforcement of qualifying Mainland judgments