Hong Kong’s SFC hints at inspections to evaluate compliance with cybersecurity requirements

Maria Nikolova

The Hong Kong regulator says it will conduct surveys and inspections of licensed entities to assess their compliance with the requirements soon.

How secure is your brokerage against cyber attacks?

More than a year has passed since the Hong Kong Securities and Futures Commission (SFC) posted its Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading. The rules require all licensed or registered entities engaged in online trading to implement 20 baseline requirements to enhance their cybersecurity and to minimize hacking risks.

Today, as the Hong Kong regulator published the latest “SFC Compliance Bulletin: Intermediaries“, it indicated it would check how companies comply with the new requirements.

To mitigate hacking risks, the SFC mandated two-factor authentication (2FA) along with 19 other baseline requirements for all Internet brokers, including companies that offer leveraged foreign exchange trading. Since April 27, 2018, logging into online trading systems requires authentication utilising two of the following factors: what you know (such as your login password), what you have (such as an SMS one-time password received via your mobile) and who you are (such as your fingerprint). Other baseline requirements came into effect in July 2018, including prompt notification to clients upon system login and timely patch management.

“To assess compliance, we will conduct surveys and inspections of LCs on a sample basis soon”, the SFC said.

The regulator did not specify how it would choose the companies to be subject to inspections.

Let’s recall that the rules concern data encryption of sensitive information such as client login credentials (ie, user ID and password) and trade data during transmission between internal networks and client devices.

Also, a licensed or registered person has to establish and implement effective policies and procedures to ensure that a client login password is generated and delivered to a client in a secure manner during the account activation and password reset processes. The entities must have in place stringent password policies and session timeout controls and should deploy a secure network infrastructure.

The rules also require from online trading companies to outline contingency plans for cyber incidents. The companies must make all reasonable efforts to cover possible cyber-attack scenarios such as DDoS attacks and total loss of business records and client data resulting from cyber-attacks (eg, ransomware) in the contingency plan and crisis management procedures.

Read this next

Metaverse Gaming NFT

Mon Protocol and Pixelverse Forge a Groundbreaking Partnership to Revolutionize Blockchain Gaming

Mon Protocol and Pixelverse make history in the annals of Blockchain gaming as they set up the architecture for the melding of their technologies.

Chainwire

Nimiq Pay Launch: A New Standard For Self-Custodial Crypto Payments

Nimiq, the blockchain ecosystem for payments that is designed to make cryptocurrency easy for everyone to use, has taken the first concrete steps towards its goal of becoming the world’s most widely-accepted digital asset for payments with the launch of Nimiq Pay.

Inside View, Interviews

Exclusive: GoMining’s Mark Zalan wants to democratize opportunities of Bitcoin halving

As the Bitcoin community counts down to the upcoming Bitcoin halving, Mark Zalan, CEO of GoMining, shared exclusive insights into how the company is gearing up for this pivotal event in the cryptocurrency world.

Digital Assets

Umoja Partners with Merlin Chain to Launch Revolutionary Bitcoin-Based Synthetic Dollar – USDb

Umoja, an innovative smart money protocol, has embarked on a strategic partnership with Merlin Chain, a leading Bitcoin Layer-2 network, to introduce USDb, the first Bitcoin-based, high-yield synthetic dollar.

Crypto Insider

Bybit Report Highlights Imminent Bitcoin Supply Shortage and Rising Scarcity Post-Halving

Bybit, recognized as one of the top three cryptocurrency exchanges globally in terms of trading volume, has recently published a comprehensive report highlighting the future supply constraints of Bitcoin.

blockdag

BlockDAG Outshines XRP Price Breakout and Uniswap Crypto Forecast with 20,000x ROI Potential and Teaser for Keynote on Moon

BlockDAG has become the latest sensation in the crypto world, which has taken the spotlight by storm, overshadowing even the most optimistic projections for XRP’s price breakout and Uniswap’s crypto forecast.

Digital Assets

Binance announces blockchain courses at European universities

“Education plays a pivotal role in advancing adoption and fostering opportunities as these technologies redefine our future and global economic landscape.”

Fintech, Uncategorized

Kepler Cheuvreux taps Adaptive for new execution equities platform

KCx, Kepler Cheuvreux’s execution division, has partnered with trading technology firm Adaptive Financial Consulting to create a new event-driven trading system based on Aeron and its own Hydra technology.

Chainwire

Bybit Livestream: Thought Leaders from Bybit, OKX and Wintermute on the 2024 Crypto Market Bull Run, April 19. Register and Secure Your Spot Now.

In a post-ETF and BTC halving world, a new era has opened as the infrastructure in the crypto industry has changed tremendously from the last bull run and halving cycle.

<