Hong Kong’s SFC hints at inspections to evaluate compliance with cybersecurity requirements

Maria Nikolova

The Hong Kong regulator says it will conduct surveys and inspections of licensed entities to assess their compliance with the requirements soon.

How secure is your brokerage against cyber attacks?

More than a year has passed since the Hong Kong Securities and Futures Commission (SFC) posted its Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading. The rules require all licensed or registered entities engaged in online trading to implement 20 baseline requirements to enhance their cybersecurity and to minimize hacking risks.

Today, as the Hong Kong regulator published the latest “SFC Compliance Bulletin: Intermediaries“, it indicated it would check how companies comply with the new requirements.

To mitigate hacking risks, the SFC mandated two-factor authentication (2FA) along with 19 other baseline requirements for all Internet brokers, including companies that offer leveraged foreign exchange trading. Since April 27, 2018, logging into online trading systems requires authentication utilising two of the following factors: what you know (such as your login password), what you have (such as an SMS one-time password received via your mobile) and who you are (such as your fingerprint). Other baseline requirements came into effect in July 2018, including prompt notification to clients upon system login and timely patch management.

“To assess compliance, we will conduct surveys and inspections of LCs on a sample basis soon”, the SFC said.

The regulator did not specify how it would choose the companies to be subject to inspections.

Let’s recall that the rules concern data encryption of sensitive information such as client login credentials (ie, user ID and password) and trade data during transmission between internal networks and client devices.

Also, a licensed or registered person has to establish and implement effective policies and procedures to ensure that a client login password is generated and delivered to a client in a secure manner during the account activation and password reset processes. The entities must have in place stringent password policies and session timeout controls and should deploy a secure network infrastructure.

The rules also require from online trading companies to outline contingency plans for cyber incidents. The companies must make all reasonable efforts to cover possible cyber-attack scenarios such as DDoS attacks and total loss of business records and client data resulting from cyber-attacks (eg, ransomware) in the contingency plan and crisis management procedures.

Read this next

Fintech

Sumsub adopts Europe’s new KYC standards for crypto

“Businesses are facing a rising regulatory tide where properly preparing for compliance is crucial. There is now a simple choice, whether to implement solutions that can deliver this, or instead risk significant financial and reputational damages.”

Chainwire

Bybit Web3 Launches Industry’s First Bitcoin Layer 2 Airdrop Campaign, Paving the Way for a New Bitcoin Era

Bybit, one of the world’s top three crypto exchanges by volume, is excited to announce that Bybit Web3 is launching the industry’s first Bitcoin Layer 2 Airdrop campaign through its Airdrop Arcade.

Retail FX

Vantage observes results of US$100,000 donation to UNHCR

Vantage’s US$100,000 donation has helped approximately 788 refugees, internally displaced persons (IDPs), and returnees in 2023 alone.

Executive Moves

Tradition hires Michel Everaert to integrate data science and AI

“I am excited about the potential this offers, and look forward to building relationships and working with teams across the global business.”

Retail FX

IBKR extends US Treasury bond trading to 22 hours per day

US Treasury bonds are highly sought after by investors seeking stability and security in their portfolios as these instruments are often considered one of the safest investment options. 

Market News

Navigating Yen Depreciation and Euro Resilience in Global Markets

Amidst the persistent depreciation of the Japanese yen against the US dollar, pressure mounts on Japanese policymakers to translate their verbal assurances into tangible actions.

Digital Assets

El Salvador refutes rumors of Bitcoin wallet hack

Chivo Wallet, El Salvador’s official cryptocurrency wallet, has dismissed reports of a hack involving its software source code and the data of over 5 million users associated with its KYC (Know Your Customer) procedures.

blockdag

Best Crypto to Buy: BlockDAG Presale Hits $20.1M Following Moon-Shot Keynote Teaser as Dogecoin & Shiba Inu Prices Plummet

This landmark achievement sets it apart in the cryptocurrency landscape, where traditional favorites like Dogecoin and Shiba Inu are witnessing a price decline.

Digital Assets

MetaMask developer sues SEC over regulatory overreach

Ethereum ecosystem developer Consensys Software has filed a lawsuit against the U.S. Securities and Exchange Commission (SEC), challenging the agency’s regulatory actions concerning Ethereum and its related services.

<