Hong Kong regulator tells online trading firms to implement two-factor authentication by April 2018

Maria Nikolova

New guidelines require all licensed or registered entities engaged in online trading to implement 20 baseline requirements to boost their cybersecurity.

stealing leads

Hong Kong’s Securities and Futures Commission (SFC) is apparently taking cybersecurity seriously. Today, the regulatory posted its Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading. The new rules require all licensed or registered entities engaged in online trading to implement 20 baseline requirements to enhance their cybersecurity and to minimize hacking risks.

These Guidelines apply to entities that are engaged in online trading and are licensed by, or registered with, the SFC for:

  • Type 1 regulated activity (dealing in securities);
  • Type 2 regulated activity (dealing in futures contracts);
  • Type 3 regulated activity (leveraged foreign exchange trading);
  • Type 9 regulated activity (asset management).

A key requirement is to implement two-factor authentication for login to clients’ online trading accounts. In addition, the entity should implement monitoring and surveillance mechanisms to detect unauthorised access to clients’ Internet trading accounts. Other requirements concern data encryption of sensitive information such as client login credentials (ie, user ID and password) and trade data during transmission between internal networks and client devices.

A licensed or registered person should also establish and implement effective policies and procedures to ensure that a client login password is generated and delivered to a client in a secure manner during the account activation and password reset processes. The entities should have in place stringent password policies and session timeout controls and should deploy a secure network infrastructure.

The rules also require from online trading companies to outline contingency plans for cyber incidents. The companies should make all reasonable efforts to cover possible cyber-attack scenarios such as DDoS attacks and total loss of business records and client data resulting from cyber-attacks (eg, ransomware) in the contingency plan and crisis management procedures.

Also, the licensed entity should make sure that the officer(s) or executive officer(s) responsible for the overall management and supervision of the online trading system define a cybersecurity risk management framework, and set out key roles and responsibilities. Examples of such responsibilities include reviewing and approving cybersecurity risk management policies and procedures, as well as reviewing and approving the budget and spending on resources for cybersecurity risk management.

The guidelines also stipulate that licensed and/or registered entities should take all reasonable steps to remind clients about and alert them to cybersecurity risks and recommended preventive and protection measures when using the trading system.

The deadline for the implementation of two-factor authentication is April 27, 2018, while all other requirements will take effect on July 27, 2018.

Although the Guidelines do not have the force of law, a failure to follow their spirit may reflect adversely on the person’s fitness and properness.

Read this next

blockdag

BlockDAG’s Explosive Presale Hits $20.3M In April Swaying Investors From XRP’s Price Trends Upward, & Polygon’s NFT Market

Learn about BlockDAG’s impressive $20.3M presale results, XRP’s price increase prospects, and the booming NFT market on Polygon among the top 10 cryptocurrencies.

Retail FX

Financial Commission warns of Eplanet Brokers

The Financial Commission, a self-regulatory compliance specialist for the financial services industry, is ramping up its scrutiny of unregulated brokerage firms. Today, the independent association warned against a company called Eplanet Brokers.

Retail FX

Dubai crypto exchange steps into prop trading

Dubai-based cryptocurrency trading platform, CoinW Exchange, marked its sixth anniversary by announcing a rebranding initiative and launching a proprietary trading product.

Fintech

Bitcoin payments app Strike launches in Europe

Bitcoin blockchain-based payments app Strike launched in Europe on Wednesday, allowing users in the region to buy, sell, and withdraw bitcoin (BTC).

Chainwire

Bandit Network’s Points SDK and Brave Ads Power Astar zkEVM’s Quest Platform “Yoki Origins”

“Yoki Origins,” supported by Bandit Network and Brave Ads, introduces a gamified and rewarding experience for Astar zkEVM users, marking a significant milestone in Web3 adoption.

Digital Assets

Crypto ETFs to debut in Hong Kong next week

Hong Kong has authorized six cryptocurrency-based spot ETFs set to launch on April 30, according to Bloomberg.

blockdag

BlockDAG Among The Best New Crypto To Invest In Post 8 Billion Coins Sales; More On Bitcoin Cash Futures’ Launch & Solana Positive Predictions

Explore Solana’s ATH predictions to see whether it can rise after a $17B dip? BlockDAG sells 8 billion coins in presale as Bitcoin Cash Futures launch.

Fundamental Analysis, Market News, Tech and Fundamental

Global FX Market Summary:USD, FED, German IFO ,Gold April 24 ,2024

Mixed US economic data and Fed rate hike uncertainty are causing volatility in the EUR/USD pair, while the Eurozone and gold prices add another layer of complexity.

Market News, Tech and Fundamental, Technical Analysis

EURCHF Technical Analysis Report 24 April, 2024

EURCHF currency pair can be expected to rise further toward the next major resistance level 0.9840, which stopped the pervious waves C and B, as can be seen below.

<