Hong Kong regulator outlines new cyber security requirements for online trading firms

Maria Nikolova

The measures proposed include two-factor authentication for clients, as well as stringent password policies, after study shows a steep rise in cyber security incidents.

Cyber security is one of the issues on the agenda of financial market regulators, with the latest example provided by the Hong Kong Securities and Futures Commission (SFC), which has earlier today published a Consultation Paper on enhanced cyber security requirements for Internet trading brokers. The proposed requirements concern securities dealers, futures dealers and/or leveraged foreign exchange traders, and seek to reduce hacking risks associated with Internet trading.

The baseline requirements, which include 20 cyber security control practices, concern three main areas:

  • Protection of clients’ Internet trading accounts;
  • Infrastructure security management;
  • Cyber security management and supervision.

For instance, brokers have to implement stringent password policies and session timeout controls in their internet trading systems. Also, they will have to introduce two-factor authentication for their clients, as well as rigid surveillance mechanisms to prevent unauthorized access to accounts.

Since hacking of Internet trading accounts, corporate websites and trading systems is the most serious cyber security risk faced by licensed corporations in Hong Kong, the SFC conducted a thematic review of the resilience to hacking risks of brokers engaged in Internet trading with the assistance of an external cyber security expert in late 2016. The review helped the regulator identify basic cyber security controls.

The consultation paper proposes to include these controls into guidelines to be issued under the Securities and Futures Ordinance (SFO).

Comments on the proposals are expected no later than July 7, 2017.

The proposals are released as data shows that the number of cyber security incidents handled by the Hong Kong Computer Emergency Response Team Coordination Centre of the Hong Kong Productivity Council reached 6,058 in 2016, up 23% from 2015. For the 18 months ended March 31, 2017, 12 licensed corporations (LCs) reported 27 cyber security incidents, with the bulk of them involving hackers getting access to customers’ Internet-based trading accounts with securities brokers. This unauthorized access has resulted in unauthorised trades totalling more than $110 million.

Read this next

Fintech

Bitcoin payments app Strike launches in Europe

Bitcoin blockchain-based payments app Strike launched in Europe on Wednesday, allowing users in the region to buy, sell, and withdraw bitcoin (BTC).

Chainwire

Bandit Network’s Points SDK and Brave Ads Power Astar zkEVM’s Quest Platform “Yoki Origins”

“Yoki Origins,” supported by Bandit Network and Brave Ads, introduces a gamified and rewarding experience for Astar zkEVM users, marking a significant milestone in Web3 adoption.

Digital Assets

Crypto ETFs to debut in Hong Kong next week

Hong Kong has authorized six cryptocurrency-based spot ETFs set to launch on April 30, according to Bloomberg.

blockdag

BlockDAG Among The Best New Crypto To Invest In Post 8 Billion Coins Sales; More On Bitcoin Cash Futures’ Launch & Solana Positive Predictions

Explore Solana’s ATH predictions to see whether it can rise after a $17B dip? BlockDAG sells 8 billion coins in presale as Bitcoin Cash Futures launch.

Fundamental Analysis, Market News, Tech and Fundamental

Global FX Market Summary:USD, FED, German IFO ,Gold April 24 ,2024

Mixed US economic data and Fed rate hike uncertainty are causing volatility in the EUR/USD pair, while the Eurozone and gold prices add another layer of complexity.

Market News, Tech and Fundamental, Technical Analysis

EURCHF Technical Analysis Report 24 April, 2024

EURCHF currency pair can be expected to rise further toward the next major resistance level 0.9840, which stopped the pervious waves C and B, as can be seen below.

Digital Assets

Binance’s CZ could stay in prison until 2027, wife begs for mercy

Changpeng “CZ” Zhao, the founder and former CEO of Binance, has apologized for his decisions and accepted “full responsibility” in a letter to U.S. District Judge Richard A. Jones.

Digital Assets

Monex Group expands crypto business with 3iQ takeover

Monex Group has completed the acquisition of a majority stake in 3iQ Digital Holdings, Inc., a Canadian digital asset investment fund manager, as part of its strategy to expand its crypto business.

Education, Fintech, Inside View

How to Get Into Fintech: Best Tips to Succeed

The Fintech sector is experiencing significant growth, with fresh opportunities emerging rapidly.  Innovations such as machine learning and cryptocurrency are revolutionising finance, leading to a need for trained experts.

<