Hong Kong SFC: AI-Enabled Cyberattack Controls — Put MIC-IT-Led Resilience Evidence on the Table

The Hong Kong Securities and Futures Commission (SFC) expects licensed firms to reassess whether their cyber controls can withstand faster, more targeted AI-enabled attacks—and to be able to show the result, not merely say that the policy exists.

Bottom line

In its 2 June 2026 circular, the SFC asks licensed corporations (LCs), SFC-licensed virtual asset trading platforms (VATPs) and their associated entities to assess preparedness for AI-enabled cyberattacks, remediate vulnerabilities and enhance controls. Senior management, including the Manager-in-Charge of Information Technology (MIC-IT), remains ultimately responsible; the MIC-IT should ensure framework changes are reviewed, approved, and implemented properly and promptly.

This supervisory circular sharpens the SFC’s expectations under existing cyber-risk obligations and signals possible preparedness reviews or supervisory action. The SFC expressly restates existing obligations to promptly notify it of material cyber incidents and, for LCs engaged in electronic trading and VATPs, to back up specified records and data at least daily.

For asset managers, the practical priority is a documented, risk-based challenge of the technology estate, critical third parties and incident playbooks against the pace and techniques the SFC identifies: automated reconnaissance and exploitation, chained vulnerabilities, phishing, social engineering and deepfake impersonation.

Do today

Must — confirm reporting and backup baselines. Compliance and Technology must maintain an escalation route, decision-maker and evidence for prompt SFC notification of material cyber incidents. Electronic-trading LCs and VATPs must verify daily backup coverage and restoration availability for the records and data specified in the underlying requirements.

Should — commission an MIC-IT-led gap assessment. Technology Risk should map externally exposed, business-critical and third-party-dependent components; record the owner, remediation priority, compensating controls and approval for each material gap. The resulting inventory should support same-day prioritisation and containment when new vulnerability intelligence arrives.

Should — test the emergency patch lane. Security and Operations should evidence how an urgent or critical fix affecting a business-critical component can be assessed, approved, deployed and, where necessary, temporarily contained outside ordinary patch cycles. Confirm capacity for a surge in patches.

Should — run an AI-enabled attack exercise. The incident owner should table-top or simulate a compromise involving automated reconnaissance, a deepfake-led credential attack, or a chained vulnerability. Test pre-authorised isolation, access restriction, client and SFC communications, recovery targets and governance escalation.

Should — identify critical supplier dependencies. Procurement, Technology and Legal should identify suppliers supporting critical operations or business-critical components; risk-rate them and verify that contracts cover timely security-incident notification, vulnerability disclosure, exit and contingency arrangements.

Check

Patching and assets

Can the firm identify, on the same day, every externally exposed or business-critical affected asset, its data sensitivity, supplier dependency and accountable owner?

Do risk acceptance, patch deferral and end-of-life software decisions reflect the increased likelihood of rapid exploitation? Are compensating controls documented while a permanent fix is deployed?

Is patch prioritisation based on exploitability, exposure, data sensitivity and operational criticality—not just a generic vulnerability score? (Appendix, pp. 1–2.)

Access, AI and detection

Are least privilege, privileged-account safeguards, maker-checker controls and segmentation effective for business-critical components? Are external content and untrusted inputs prevented from directly changing system instructions or triggering privileged actions?

Where AI language models are used—whether internally built, group-provided, third-party or open-source—does the cyber framework and incident plan address adversarial attacks, data leakage and prompt override? For a proposed high-risk use case, has the firm checked the separate notification requirement referenced in the SFC’s November 2024 circular?

Do monitoring rules cover anomalous client trading activity as well as system activity? Are threat-intelligence feeds, code/system/network scanning and periodic red-team or resilience testing calibrated to emerging attack patterns?

Third parties, response and recovery

Does due diligence assess a critical supplier’s vulnerability management and patch-deployment capability against current AI-enabled threats? Is concentration risk understood, with credible alternatives if a critical service is interrupted?

Does the incident plan name Technology, Risk, Compliance and senior-management roles; specify pre-authorised containment; and align recovery actions with recovery-time and recovery-point objectives?

Keep an eye on

SFC follow-up. The SFC says it may issue further guidance, conduct preparedness and resilience reviews, or take supervisory action as risks evolve. Reassess the programme when the SFC publishes a further circular, begins a thematic review, or requests information.

High-risk AI adoption. The Circular points firms using AI language models in high-risk use cases to notification requirements under the Securities and Futures (Licensing and Registration) (Information) Rules. Reassess before moving an AI use case into that category; the Circular itself does not reproduce the underlying definition or notification mechanics.

Applicability of the Appendix. The Appendix says electronic-trading LCs (particularly large retail brokers), Type 13 depositaries of SFC-authorised collective investment schemes and VATPs are generally expected to implement all listed measures. Other licensed firms should consider them proportionately to their operations, dependencies and exposure. Reassess scope after a material technology, outsourcing or distribution-model change.

Why this matters

The SFC’s concern is that AI compresses the time from vulnerability discovery to exploitation and permits attackers to chain apparently lower-risk weaknesses into a material disruption. A conventional monthly patch report or post-incident review is not a substitute for evidence that the firm can prioritise, contain and recover quickly.

The Circular also places the accountability point where the SFC is likely to look first: senior management and MIC-IT oversight of the review, approval and implementation of cyber-control enhancements (para. 3). For managers, a concise board or relevant committee pack showing scope, material gaps, risk decisions, exercise results and remediation ownership is the sensible evidence trail.

Scope and timing

Jurisdiction/regulator: Hong Kong / SFC.
Document: supervisory circular SFO/IS/020/2026, dated 2 June 2026.
In scope: LCs, SFC-licensed VATPs and their associated entities.
Timing:
no separate transition period or implementation deadline is stated; the Circular calls for a review and enhancement now. The Appendix is expressly illustrative and non-exhaustive, subject to the heightened expectations and proportionality described above.

This guidance note does not constitute legal advice. Enforcement matters described involve allegations only; no findings of wrongdoing have been made by a court unless expressly stated. AI, under human supervision, has been used for research and drafting assistance. All content has been reviewed by a human prior to publication.

Ready for the next step?
See how our solutions can save time and money.
Get in touch
Get in touch