{"id":34948,"date":"2026-08-04T02:59:29","date_gmt":"2026-08-04T02:59:29","guid":{"rendered":"https:\/\/www.tannerdewitt.com\/?post_type=insight-and-news&#038;p=34948"},"modified":"2026-08-06T02:00:23","modified_gmt":"2026-08-06T02:00:23","slug":"news-update-sfc-circular-sets-cybersecurity-measures-against-ai-enabled-cyberattacks","status":"publish","type":"insight-and-news","link":"https:\/\/www.tannerdewitt.com\/zh-hant\/insight-and-news\/news-update-sfc-circular-sets-cybersecurity-measures-against-ai-enabled-cyberattacks\/","title":{"rendered":"News update: SFC circular sets cybersecurity measures against AI-enabled cyberattacks"},"content":{"rendered":"\n    \n\n<div style=\"background-image:url('https:\/\/www.tannerdewitt.com\/wp-content\/themes\/tanner-de-witt\/images\/insightdetails.jpeg')\"\n    class=\"insight-news-detail-hero\" id=\"insight-news-detail-hero\">\n\n\t\t<div style=\"background-color:\" class=\"insight-news-detail-hero-overlay \"><\/div>\n            <div class=\"z-[0]\">\n                <div class=\"insight-news-breadcrumbs flex items-end practice-areas-featured-breadcrumbs \">\n                    <a class=\"page-link no-underline\" href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/\">\u9996\u9801<\/a>                <\/div>\n\n\n                <div class=\"hero-title\">\n                    <h1>\n                        News update: SFC circular sets cybersecurity measures against AI-enabled cyberattacks                    <\/h1>\n                <\/div>\n                \n                    <div style=\"\" class=\"hero-date \">\n\n                        <span class=\"month\">Aug<\/span>\n                        <span class=\"day\">04<\/span>\n                        <span class=\"year\">2026<\/span>\n                    <\/div>\n\n            <\/div>\n    \n\n    \n\n\n\n<\/div>\n\n\n\n<script >\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n\n            const breadCrumbsContainer = Array.from(document.querySelectorAll(\".practice-areas-featured-breadcrumbs\"));\n\n            breadCrumbsContainer.forEach(container => {\n                const breadCrumbLinks = Array.from(container.querySelectorAll('.page-link'));\n                const breadCrumbSeperators = Array.from(container.querySelectorAll('.separator'));\n\n                if (Array.from(breadCrumbLinks).length === 1) {\n                    const homeNode = breadCrumbLinks[0];\n\n                    if (!homeNode) {\n                        return\n                    }\n\n                    const postTypeNode = homeNode.cloneNode(true);\n                    postTypeNode.textContent = \"Insights and News\";\n                    container.insertAdjacentHTML('beforeend', `<span class=\"separator practice-areas-featured-breadcrumb-item-slash\">\/<\/span>`)\n                    container.insertAdjacentElement('beforeend', postTypeNode)\n                    breadCrumbLinks.push(postTypeNode);\n\n                    if (\"Insights\") {\n                        const categoryNode = homeNode.cloneNode(true);\n\n                        categoryNode.textContent = \"Insights\";\n                        container.insertAdjacentHTML('beforeend', `<span class=\"separator practice-areas-featured-breadcrumb-item-slash\">\/<\/span>`)\n                        container.insertAdjacentElement('beforeend', categoryNode)\n                        breadCrumbLinks.push(categoryNode);\n                    }\n\n\n                    const titleNode = homeNode.cloneNode(true);\n\n                    titleNode.textContent = \"News update: SFC circular sets cybersecurity measures against AI-enabled cyberattacks\";\n                    container.insertAdjacentHTML('beforeend', `<span class=\"separator practice-areas-featured-breadcrumb-item-slash\">\/<\/span>`)\n                    container.insertAdjacentElement('beforeend', titleNode)\n                    breadCrumbLinks.push(titleNode);\n\n\n\n\n                }\n\n                breadCrumbLinks.forEach((link, index) => {\n\n                    link.classList.add('practice-areas-featured-breadcrumb-item-name');\n                    const origin = window.location.origin;\n                    const href = window.location.href;\n\n                    const originSplitter = window.location.href.includes(\"insight-and-news\") ? \"insight-and-news\" : window.location.href.includes('insights-and-news') ? \"insights-and-news\" : \"\"\n\n                    const paths = href.split(originSplitter);\n                    const links = paths[1].split(\"\/\").filter(Boolean)\n\n\n                    const resolvedOrigin = originSplitter ? (href.split(originSplitter)[0] || \"\") : (origin + \"\/\")\n\n                    if (index === 0) {\n\n                        if (!originSplitter) {\n                            link.href = origin\n                        } else {\n                            link.href = resolvedOrigin;\n                        }\n\n\n                    } else if (index === 1) {\n                        link.href = resolvedOrigin + originSplitter\n\n                    }\n                    else if (index === 2) {\n                        console.log(links)\n                        link.href = resolvedOrigin + originSplitter + \"\/\" + (links[0] || \"\")\n                    }\n                    else if (index === 3) {\n\n                        link.href = resolvedOrigin + originSplitter + \"\/\" + (links[0] || \"\") + \"\/\" + (links[1] || \"\")\n\n                    }\n\n\n\n                    \/\/ const words = link.textContent.split(\" \")\n                    \/\/ if (words.length > 4) {\n                    \/\/     link.textContent = words.slice(0, 4).join(\" \") + \"...\"\n                    \/\/ }\n\n                })\n\n                breadCrumbSeperators.forEach(separator => {\n                    separator.textContent = \"\/\"\n                    separator.classList.add('practice-areas-featured-breadcrumb-item-slash')\n                });\n\n\n            })\n\n\n        })\n        removeDivTag()\n    })();\n\n    function removeDivTag() {\n        console.log(\"remasfljas\");\n        const editorContainer = document.querySelector(\".editor-wysiwyg\");\n        \/\/ editorContainer.innerText = editorContainer.innerText.replace(\"<\/div>\", \"\")\n        Array.from(editorContainer.childNodes).forEach(el => {\n            if (el.textContent.includes(\"<\/div>\")) {\n                el.textContent = \"\"\n            }\n        })\n    }\n<\/script>\n\n<div class=\"editor-wysiwyg my-[40px]\">\n<div class=\"single-section\">\n<div class=\"single-section\">\n<p>In January 2024, the Securities and Futures Commission (SFC) set institutional resilience and operational efficiency as one of its four strategic priorities. Since then, the SFC has stepped up its focus on cyber resilience and security as a core regulatory expectation for licensed corporations (LCs), virtual asset service providers (VATPs) and associated entities. In this news update, <a href=\"https:\/\/www.tannerdewitt.com\/our-people\/padraig-walsh\/\">P\u00e1draig Walsh<\/a> from our <a href=\"https:\/\/www.tannerdewitt.com\/practice-areas\/technology-media-and-telecommunications-tmt\/cybersecurity\/\">cybersecurity<\/a> practice reviews a recent SFC circular that sets out the expected regulatory standards of the SFC to respond to the growing threat posed by AI-enabled cyberattacks.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a><\/p>\n<p><strong>Developments in the risk environment<\/strong><\/p>\n<p>Cybersecurity incidents in Hong Kong have been trending upwards for a number of years. 2025 saw a significant uptick in that trend. According to the HKCERT, the number of cybersecurity incidents increased to 15,877 in 2025 from 12,536 in 2024, representing a 27% year-on-year increase. HKCERT identified AI-driven attacks and agentic AI risks at the top of its five cybersecurity risks for 2026, and included AI-related issues among three of that top five.<\/p>\n<p>AI has marked a step change in the pace, sophistication and effectiveness of cyberattacks. The SFC highlighted in particular:<\/p>\n<p><em>AI is increasing the sophistication, scale and frequency of cyberattacks<\/em>: Frontier AI models can plan and execute more complex multi-step actions autonomously. The spread of AI-enabled tools lowers the technical barrier for threat actors to execute malicious activities. AI-enabled tools also enable the execution of those activities with a higher degree of sophistication. This is evident, for instance, in attack vectors such as phishing and deepfake impersonation. LCs and VATPs need to reassess existing prevention, detection, response and recovery measures.<\/p>\n<p><em>Reduced response time for remediation<\/em>: AI-enabled tools have led to the rapid identification and exploitation of new vulnerabilities. The period between disclosure of a vulnerability and active exploitation is also becoming shorter. LCs and VATPs must enhance patching and vulnerability management procedures.<\/p>\n<p><strong>Regulatory expectations<\/strong><\/p>\n<p>The SFC has made it clear that senior management remains ultimately responsible for cybersecurity risk management. This includes the Manager-in-Charge of Information Technology (MIC-IT). It is a core responsibility of the MIC-IT to review the cybersecurity framework of the firm in question, and to review, approve and properly implement cybersecurity enhancements. The key focus should be to ensure the firm&#8217;s cybersecurity frameworks remain appropriate and effective in preventing, detecting, responding to and recovering from evolving threats.<\/p>\n<p>As a general foundational principle, the SFC expects firms to maintain robust and up-to-date security controls to protect systems, client information and client assets. Firms should maintain a comprehensive and dynamic inventory of technology assets, including hardware, software, databases, cloud services and network infrastructure. Firms should also identify which assets are externally exposed, business-critical or dependent on third-party components or providers.<\/p>\n<p>The circular identifies five key areas for consideration:<\/p>\n<p><em>Patching and vulnerability management<\/em>: Firms should review and strengthen patch management processes. The processes should address known vulnerabilities promptly and implement procedures for urgent and critical patches outside normal maintenance cycles.<\/p>\n<p><em>Access and privilege controls<\/em>: Firms should adopt a \u201czero trust\u201d mindset. This is a design principle under which network access is not implicitly trusted based solely on network location or user status. Firms should implement robust access and privilege controls and minimise attack surfaces. This means applying least-privilege access controls, enhanced firewall protection and stronger network segmentation, among other measures.<\/p>\n<p><em>Detection and monitoring<\/em>: Firms should strengthen threat detection, system monitoring and threat intelligence capabilities.<\/p>\n<p><em>Supply chain risk management<\/em>: Firms should strengthen their supply chain risk governance framework, enhance initial and ongoing assessments of third party service providers, and prioritise potential impact from third party service providers to critical operations and business critical components.<\/p>\n<p><em>Incident response and recovery<\/em>: The SFC expects firms to review and enhance incident response procedures and contingency plans. Firms should establish swifter adequate escalation and reporting procedures to take account of the swifter pace of AI-enable attacks. Firms should consider pre-planned containment strategies, including the ability to block malicious activities, isolate affected systems and restrict access rapidly. Firms should back up records, databases, and supporting documents on a regular basis, and ensure the swift availability of the backup copies when needed.<\/p>\n<p>Firms should review incident handling procedures and response plans to ensure:<\/p>\n<p>(a)\u00a0\u00a0\u00a0\u00a0 the roles and responsibilities for personnel involved in the incident response;<\/p>\n<p>(b)\u00a0\u00a0\u00a0\u00a0 the escalation protocols to facilitate coordinated efforts across teams, including IT, risk management, compliance, and senior management;<\/p>\n<p>(c)\u00a0\u00a0\u00a0\u00a0 the pre-authorised containment actions that should be immediately implemented;<\/p>\n<p>(d)\u00a0\u00a0\u00a0\u00a0 the actions required for the recovery of the firm\u2019s operations and business continuity; and<\/p>\n<p>(e)\u00a0\u00a0\u00a0\u00a0 the communication strategies with stakeholders, including clients, third party service providers, law enforcement agencies, and the SFC.<\/p>\n<p>The SFC has highlighted that firms must regularly test their incident handling procedures and contingency plans through tabletop exercises and simulated attacks to assess their effectiveness. This often requires the engagement of professionals with specialist knowledge and experience. This can supplement tabletop exercises or crisis simulations. Also, external expertise is often needed for the conduct of VAPT assessments and red team exercises.<\/p>\n<p>LCs and VATPs are required to report immediately to the SFC upon any material failure, error, or defect in the operation or functioning of their trading, custody, accounting, clearing, or settlement platforms, systems or equipment. This includes any material cybersecurity incident. Firms need to be equipped and prepared to make accurate and appropriate notifications.<\/p>\n<p><strong>Final thoughts<\/strong><\/p>\n<p>Tremendous opportunities are being realised and developed from the use of AI and AI language models by LCs and VATPs. Just as those opportunities exist for firms and users that adopt responsible and safe use of AI, they also exist for criminals and dangerous threat actors in the cyber world. The SFC circular recognises that AI-enabled tools have now created a substantially more dangerous cyber risk environment.<\/p>\n<p>The SFC circular substantially raises supervisory expectations regarding cyber resilience in an AI-driven threat environment. Licensed firms should not view AI risk solely as a governance or technology adoption issue. The SFC now clearly expects firms to take account of the enhanced threat AI-enabled tools represent in their cybersecurity frameworks and ongoing compliance.<\/p>\n<p>This escalated concern is not a surprise. Financial services is a critical sector of the economy. Cyber resilience is a stated core target area for the SFC. The SFC is more regularly publishing guidance on cyber risk and AI risk. There is SFC 2024 circular on use of generative AI language models. Also, we recently reviewed the SFC circular on implementing authentication methods to mitigate hacking risks from phishing attacks and monitoring measures to identify suspicious activities (see our article on this <a href=\"https:\/\/www.tannerdewitt.com\/insight-and-news\/news-update-no-phishing-here-the-sfc-raises-cybersecurity-expectations-for-internet-brokers-and-virtual-asset-trading-platforms\/\">link<\/a>).<\/p>\n<p>This is a circular of critical importance to MIC-ITs in LCs and VAPTs. Senior management and MIC-ITs are accountable for cybersecurity preparedness and implementation. Many firms will require additional budget to allocate sufficient resources to meet the expected regulatory standards. There will be a need to external support in training, awareness and readiness for incident response, and in reviewing incident response and business continuity plans to ensure they are fit for purpose.<\/p>\n<p>Cyber resilience against AI-enabled cyber attacks is at the Board table.<\/p>\n<p><em>P\u00e1draig Walsh<\/em><\/p>\n<p>If you want to know more about the content of this article, please contact:<\/p>\n<p><a href=\"https:\/\/www.tannerdewitt.com\/our-people\/padraig-walsh\/\">P\u00e1draig Walsh<\/a><\/p>\n<p>Partner | <a href=\"mailto:padraigwalsh@tannerdewitt.com\">Email<\/a><\/p>\n<p><em>Disclaimer: This publication is general in nature and is not intended to constitute legal advice. You should seek professional advice before taking any action in relation to the matters dealt with in this publication. This article was published on [4 August 2026].<\/em><\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> SFC Circular, Enhanced cybersecurity measures to address evolving risks arising from artificial intelligence-enabled cyberattacks, 2 June 2026 [<a href=\"https:\/\/apps.sfc.hk\/edistributionWeb\/gateway\/EN\/circular\/doc?refNo=26EC32\" target=\"_blank\" rel=\"noopener\">link<\/a>]<\/p>\n<\/div>\n<\/div>\n<\/div>\n\n\n    <div class=\"tdw-three-cols-two-rows-article\" id=\"\">\n        <div style=\"background:#FFFFFF\"\n            class=\"three-cols-two-rows    \" id=\"three-cols-two-rows\">\n\n            <div class=\"three-cols-two-rows-title-button\">\n                <div class=\"flex flex-row justify-between w-[100%] max-w-[1360px] mx-auto\">\n                    <h3 class=\"title no-underline\">Featured Articles<\/h3>\n                    <div>\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n\t\t\t\t\t\t\n                  \n\n                    <\/div>\n                <\/div>\n\n            <\/div>\n            <div class=\"three-cols-two-rows-container\">\n\n                                                                                        \n<a class=\"h-[100%] block no-underline group\" href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/insight-and-news\/another-post-re-usum-decision-hong-kong-court-grants-disclosure-relief-in-aid-of-bvi-liquidation\/\">\n    <div style=\"background:#F8F8F8\" class=\"h-[100%]  article-card\"\n        id=\"article-card\">\n        <div class=\"article-card-header\">\n                                                <span style=\"color:#781d7e\" class=\"article-caption\">Insights<\/span>\n                \n            \n            <div class=\"article-title no-underline group-hover:!underline line-clamp-3\">\n                Another post-Re USUM decision: Hong Kong Court grants disclosure relief in aid of BVI liquidation\n            <\/div>\n        <\/div>\n\n        <div class=\"article-author-and-date-container \">\n                            <span data-href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/our-people\/natalie-lam\/\"\n                    class=\"article-author cursor-pointer hover:underline\">\n                    \u6797\u5bb6\u5e0c<\/span>\n\n            \n                            <svg width=\"5\" height=\"5\" viewBox=\"0 0 5 5\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <path\n                        d=\"M0.680664 2.56641V2.20605C0.680664 1.70215 0.838867 1.28613 1.15527 0.958008C1.47754 0.629883 1.91406 0.46582 2.46484 0.46582C3.02148 0.46582 3.46094 0.629883 3.7832 0.958008C4.10547 1.28613 4.2666 1.70215 4.2666 2.20605V2.56641C4.2666 3.06445 4.10547 3.47754 3.7832 3.80566C3.4668 4.12793 3.03027 4.28906 2.47363 4.28906C1.92285 4.28906 1.48633 4.12793 1.16406 3.80566C0.841797 3.47754 0.680664 3.06445 0.680664 2.56641Z\"\n                        fill=\"#656363\" \/>\n                <\/svg>\n            \n            <span>14 September 2026<\/span>\n\n        <\/div>\n    <\/div>\n<\/a>\n\n<script>\n\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n            const author = document.querySelector(\".article-author\");\n\n            author.addEventListener('click', (e) => {\n                e.stopPropagation();\n\n                window.location = author.getAttribute('data-href')\n            });\n        });\n    })();\n\n<\/script>                        \n                                                                        \n<a class=\"h-[100%] block no-underline group\" href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/insight-and-news\/cybersecurity-for-banks-after-the-critical-infrastructure-ordinance-same-same-but-different\/\">\n    <div style=\"background:#F8F8F8\" class=\"h-[100%]  article-card\"\n        id=\"article-card\">\n        <div class=\"article-card-header\">\n                                                <span style=\"color:#781d7e\" class=\"article-caption\">Insights<\/span>\n                \n            \n            <div class=\"article-title no-underline group-hover:!underline line-clamp-3\">\n                Cybersecurity for Banks after the Critical Infrastructure Ordinance: Same Same, But Different\n            <\/div>\n        <\/div>\n\n        <div class=\"article-author-and-date-container \">\n                            <span data-href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/our-people\/padraig-walsh\/\"\n                    class=\"article-author cursor-pointer hover:underline\">\n                    P\u00e1draig Walsh<\/span>\n\n            \n                            <svg width=\"5\" height=\"5\" viewBox=\"0 0 5 5\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <path\n                        d=\"M0.680664 2.56641V2.20605C0.680664 1.70215 0.838867 1.28613 1.15527 0.958008C1.47754 0.629883 1.91406 0.46582 2.46484 0.46582C3.02148 0.46582 3.46094 0.629883 3.7832 0.958008C4.10547 1.28613 4.2666 1.70215 4.2666 2.20605V2.56641C4.2666 3.06445 4.10547 3.47754 3.7832 3.80566C3.4668 4.12793 3.03027 4.28906 2.47363 4.28906C1.92285 4.28906 1.48633 4.12793 1.16406 3.80566C0.841797 3.47754 0.680664 3.06445 0.680664 2.56641Z\"\n                        fill=\"#656363\" \/>\n                <\/svg>\n            \n            <span>14 September 2026<\/span>\n\n        <\/div>\n    <\/div>\n<\/a>\n\n<script>\n\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n            const author = document.querySelector(\".article-author\");\n\n            author.addEventListener('click', (e) => {\n                e.stopPropagation();\n\n                window.location = author.getAttribute('data-href')\n            });\n        });\n    })();\n\n<\/script>                        \n                                                                        \n<a class=\"h-[100%] block no-underline group\" href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/insight-and-news\/cybersecurity-for-banks-after-the-critical-infrastructure-ordinance-same-same-but-different\/\">\n    <div style=\"background:#F8F8F8\" class=\"h-[100%]  article-card\"\n        id=\"article-card\">\n        <div class=\"article-card-header\">\n                                                <span style=\"color:#781d7e\" class=\"article-caption\">Insights<\/span>\n                \n            \n            <div class=\"article-title no-underline group-hover:!underline line-clamp-3\">\n                Cybersecurity for Banks after the Critical Infrastructure Ordinance: Same Same, But Different\n            <\/div>\n        <\/div>\n\n        <div class=\"article-author-and-date-container \">\n                            <span data-href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/our-people\/padraig-walsh\/\"\n                    class=\"article-author cursor-pointer hover:underline\">\n                    P\u00e1draig Walsh<\/span>\n\n            \n                            <svg width=\"5\" height=\"5\" viewBox=\"0 0 5 5\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <path\n                        d=\"M0.680664 2.56641V2.20605C0.680664 1.70215 0.838867 1.28613 1.15527 0.958008C1.47754 0.629883 1.91406 0.46582 2.46484 0.46582C3.02148 0.46582 3.46094 0.629883 3.7832 0.958008C4.10547 1.28613 4.2666 1.70215 4.2666 2.20605V2.56641C4.2666 3.06445 4.10547 3.47754 3.7832 3.80566C3.4668 4.12793 3.03027 4.28906 2.47363 4.28906C1.92285 4.28906 1.48633 4.12793 1.16406 3.80566C0.841797 3.47754 0.680664 3.06445 0.680664 2.56641Z\"\n                        fill=\"#656363\" \/>\n                <\/svg>\n            \n            <span>14 September 2026<\/span>\n\n        <\/div>\n    <\/div>\n<\/a>\n\n<script>\n\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n            const author = document.querySelector(\".article-author\");\n\n            author.addEventListener('click', (e) => {\n                e.stopPropagation();\n\n                window.location = author.getAttribute('data-href')\n            });\n        });\n    })();\n\n<\/script>                        \n                                                                        \n<a class=\"h-[100%] block no-underline group\" href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/insight-and-news\/news-update-hong-kong-moves-closer-to-a-full-virtual-asset-services-regime\/\">\n    <div style=\"background:#F8F8F8\" class=\"h-[100%]  article-card\"\n        id=\"article-card\">\n        <div class=\"article-card-header\">\n                                                <span style=\"color:#781d7e\" class=\"article-caption\">Insights<\/span>\n                \n            \n            <div class=\"article-title no-underline group-hover:!underline line-clamp-3\">\n                News update: Hong Kong moves closer to a full virtual asset services regime\n            <\/div>\n        <\/div>\n\n        <div class=\"article-author-and-date-container \">\n                            <span data-href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/our-people\/evelyn-wong\/\"\n                    class=\"article-author cursor-pointer hover:underline\">\n                    \u9ec3\u8a60\u59f8<\/span>\n\n            \n                            <svg width=\"5\" height=\"5\" viewBox=\"0 0 5 5\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <path\n                        d=\"M0.680664 2.56641V2.20605C0.680664 1.70215 0.838867 1.28613 1.15527 0.958008C1.47754 0.629883 1.91406 0.46582 2.46484 0.46582C3.02148 0.46582 3.46094 0.629883 3.7832 0.958008C4.10547 1.28613 4.2666 1.70215 4.2666 2.20605V2.56641C4.2666 3.06445 4.10547 3.47754 3.7832 3.80566C3.4668 4.12793 3.03027 4.28906 2.47363 4.28906C1.92285 4.28906 1.48633 4.12793 1.16406 3.80566C0.841797 3.47754 0.680664 3.06445 0.680664 2.56641Z\"\n                        fill=\"#656363\" \/>\n                <\/svg>\n            \n            <span>06 August 2026<\/span>\n\n        <\/div>\n    <\/div>\n<\/a>\n\n<script>\n\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n            const author = document.querySelector(\".article-author\");\n\n            author.addEventListener('click', (e) => {\n                e.stopPropagation();\n\n                window.location = author.getAttribute('data-href')\n            });\n        });\n    })();\n\n<\/script>                        \n                                                                        \n<a class=\"h-[100%] block no-underline group\" href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/insight-and-news\/news-update-sfc-circular-sets-cybersecurity-measures-against-ai-enabled-cyberattacks\/\">\n    <div style=\"background:#F8F8F8\" class=\"h-[100%]  article-card\"\n        id=\"article-card\">\n        <div class=\"article-card-header\">\n                                                <span style=\"color:#781d7e\" class=\"article-caption\">Insights<\/span>\n                \n            \n            <div class=\"article-title no-underline group-hover:!underline line-clamp-3\">\n                News update: SFC circular sets cybersecurity measures against AI-enabled cyberattacks\n            <\/div>\n        <\/div>\n\n        <div class=\"article-author-and-date-container \">\n                            <span data-href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/our-people\/padraig-walsh\/\"\n                    class=\"article-author cursor-pointer hover:underline\">\n                    P\u00e1draig Walsh<\/span>\n\n            \n                            <svg width=\"5\" height=\"5\" viewBox=\"0 0 5 5\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <path\n                        d=\"M0.680664 2.56641V2.20605C0.680664 1.70215 0.838867 1.28613 1.15527 0.958008C1.47754 0.629883 1.91406 0.46582 2.46484 0.46582C3.02148 0.46582 3.46094 0.629883 3.7832 0.958008C4.10547 1.28613 4.2666 1.70215 4.2666 2.20605V2.56641C4.2666 3.06445 4.10547 3.47754 3.7832 3.80566C3.4668 4.12793 3.03027 4.28906 2.47363 4.28906C1.92285 4.28906 1.48633 4.12793 1.16406 3.80566C0.841797 3.47754 0.680664 3.06445 0.680664 2.56641Z\"\n                        fill=\"#656363\" \/>\n                <\/svg>\n            \n            <span>04 August 2026<\/span>\n\n        <\/div>\n    <\/div>\n<\/a>\n\n<script>\n\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n            const author = document.querySelector(\".article-author\");\n\n            author.addEventListener('click', (e) => {\n                e.stopPropagation();\n\n                window.location = author.getAttribute('data-href')\n            });\n        });\n    })();\n\n<\/script>                        \n                                                                        \n<a class=\"h-[100%] block no-underline group\" href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/insight-and-news\/hong-kong-courts-first-recognition-of-bahamian-liquidation-after-landmark-case-re-usum\/\">\n    <div style=\"background:#F8F8F8\" class=\"h-[100%]  article-card\"\n        id=\"article-card\">\n        <div class=\"article-card-header\">\n                                                <span style=\"color:#781d7e\" class=\"article-caption\">Insights<\/span>\n                \n            \n            <div class=\"article-title no-underline group-hover:!underline line-clamp-3\">\n                Hong Kong Court\u2019s first recognition of Bahamian liquidation after landmark case Re USUM\n            <\/div>\n        <\/div>\n\n        <div class=\"article-author-and-date-container \">\n                            <span data-href=\"https:\/\/www.tannerdewitt.com\/zh-hant\/our-people\/tim-au\/\"\n                    class=\"article-author cursor-pointer hover:underline\">\n                    \u5340\u4f83\u6f5b<\/span>\n\n            \n                            <svg width=\"5\" height=\"5\" viewBox=\"0 0 5 5\" fill=\"none\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                    <path\n                        d=\"M0.680664 2.56641V2.20605C0.680664 1.70215 0.838867 1.28613 1.15527 0.958008C1.47754 0.629883 1.91406 0.46582 2.46484 0.46582C3.02148 0.46582 3.46094 0.629883 3.7832 0.958008C4.10547 1.28613 4.2666 1.70215 4.2666 2.20605V2.56641C4.2666 3.06445 4.10547 3.47754 3.7832 3.80566C3.4668 4.12793 3.03027 4.28906 2.47363 4.28906C1.92285 4.28906 1.48633 4.12793 1.16406 3.80566C0.841797 3.47754 0.680664 3.06445 0.680664 2.56641Z\"\n                        fill=\"#656363\" \/>\n                <\/svg>\n            \n            <span>17 July 2026<\/span>\n\n        <\/div>\n    <\/div>\n<\/a>\n\n<script>\n\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n            const author = document.querySelector(\".article-author\");\n\n            author.addEventListener('click', (e) => {\n                e.stopPropagation();\n\n                window.location = author.getAttribute('data-href')\n            });\n        });\n    })();\n\n<\/script>                        \n                                    \n            <\/div>\n            <div class=\"mt-5 xl:mt-0\">\n\t\t\t\t\t\t\t\t\n         \n\n            <\/div>\n        <\/div>\n    <\/div>\n\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>In January 2024, the Securities and Futures Commission (SFC) set institutional resilience and operational efficiency as one of its four strategic priorities. Since then, the SFC has stepped up its focus on cyber resilience and security as a core regulatory expectation for licensed corporations (LCs), virtual asset service providers (VATPs) and associated entities. In this [&hellip;]<\/p>\n","protected":false},"author":25,"featured_media":34950,"parent":0,"menu_order":0,"template":"","meta":{"_acf_changed":false,"footnotes":""},"tags":[23,291],"insight-category":[1121],"insight-month":[1152],"insight-practice-area":[1146,1142],"insight-year":[1162],"class_list":["post-34948","insight-and-news","type-insight-and-news","status-publish","has-post-thumbnail","hentry","tag-legal-updates","tag-tmt","insight-category-legal-updates-and-insights","insight-month-august","insight-practice-area-cybersecurity","insight-practice-area-technology-media-and-telecommunications-tmt","insight-year-1162"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-and-news\/34948","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-and-news"}],"about":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/types\/insight-and-news"}],"author":[{"embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/users\/25"}],"version-history":[{"count":4,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-and-news\/34948\/revisions"}],"predecessor-version":[{"id":34965,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-and-news\/34948\/revisions\/34965"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/media\/34950"}],"wp:attachment":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/media?parent=34948"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/tags?post=34948"},{"taxonomy":"insight-category","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-category?post=34948"},{"taxonomy":"insight-month","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-month?post=34948"},{"taxonomy":"insight-practice-area","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-practice-area?post=34948"},{"taxonomy":"insight-year","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hant\/wp-json\/wp\/v2\/insight-year?post=34948"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}