AI vs Finance: Securing Hong Kong’s new cyber-risk landscape
Introduction: The intersection of AI and cybersecurity
The intersection of finance and technology has always been a prime target for malicious actors, but the rapid proliferation of artificial intelligence (“AI”) has fundamentally altered the threat landscape. Recognising this shift, the Securities and Futures Commission (the “SFC”) issued a circular on 2 June 2026, urgently calling upon licensed corporations, SFC-licensed virtual asset service providers, and their associated entities to fortify their cybersecurity frameworks.
The SFC’s latest intervention follows a sharp 27% increase in local cybersecurity incidents in 2025. More importantly, these guidelines are part of a wider regulatory shift. When read together with the Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap 653), it is clear that Hong Kong regulators are closing the net, shifting toward mandatory and enforceable cybersecurity standards for all essential operators
The evolving threat landscape
Recent advancements in frontier AI models have significantly reduced the technical barriers, cost, and time required to execute devastating cyberattacks. The traditional model of human-driven hacking is being replaced by AI-enabled tools that offer unprecedented speed and scale. Key developments include:
Hyper-accelerated exploitation: AI models are now capable of accelerating the identification and chaining together of system vulnerabilities, including those previously considered lower-risk, to orchestrate large-scale network compromises.
Advanced social engineering: The widespread availability of AI tools has democratised malicious activities such as deepfake impersonation, sophisticated phishing, and reconnaissance. Financial institutions must now defend against highly targeted, AI-generated communications that flawlessly mimic executives or trusted clients.
Shrinking remediation windows: Because AI allows for the rapid identification of new vulnerabilities, the time interval between a flaw being disclosed and being exploited is rapidly diminishing, overwhelming traditional patching cycles. This shrinking window necessitates a move away from periodic patch management toward real-time vulnerability intelligence, a shift that SFC expects senior management to actively oversee.
Five pillars of cyber resilience for licensed firms
The SFC’s circular applies to all licensed corporations, SFC-licensed virtual asset service providers, and their associated entities (collectively referred to as “licensed firms”). The SFC specifically noted that internet brokers and virtual asset trading platforms should be particularly vigilant in upgrading their safeguards. To protect client assets and prevent the unauthorised disclosure of confidential information, the SFC expects licensed firms to build upon a foundation of accurate, up-to-date technology asset inventories. The regulatory expectations can be categorised into five strategic pillars:
Agile vulnerability management: Routine patching cycles are no longer sufficient. Firms must develop rapid-response capabilities for critical fixes and allocate sufficient resources to handle sudden surges in patching demands dictated by AI-driven vulnerability discoveries.
Zero-trust architecture and privilege controls: Operating under the assumption that any user or device may already be compromised, firms must enforce least-privilege access, implement micro network segmentation, and apply stringent maker-checker controls for high-impact actions.
Detection and monitoring measures: Firms are expected to upgrade their intelligence gathering and monitor anomalies in system activities and client trading patterns. Traditional rule-based monitoring may need to be supplemented with behavioural analytics and AI-enhanced defensive tools to detect anomalies indicative of automated or AI-coordinated attacks.
Securing the third-party supply chain: Cyber risks often permeate through external vendors. Licensed firms must enhance their initial and ongoing assessments of third-party service providers, specifically evaluating their resilience against AI-enabled threats. From a legal perspective, this necessitates a thorough review of vendor contracts to ensure adequate liability allocation, strict cybersecurity covenants, and mandatory incident reporting clauses.
Dynamic incident response: AI-enabled attacks unfold too quickly for standard escalation channels. Firms must establish pre-planned containment strategies (such as automated network isolation), conduct regular tabletop exercises, and ensure resilient database backups. Furthermore, firms must strictly adhere to the SFC’s mandatory notification requirements for material incidents.
Collectively, these five pillars represent a shift from a “comply-or-explain” mindset to a ”demonstrably-effective” standard. However, defence is only one side of the coin. The SFC has simultaneously turned the spotlight inward, scrutinising how firms’ own use of AI might inadvertently create new entry points for attackers.
The double-edged sword: Internal AI adoption
While defending against external threats, firms must also scrutinise their internal adoption of technology. The SFC explicitly warned that utilising AI language models internally – whether open-source, proprietary, or vendor-provided – can amplify existing vulnerabilities. Risks such as data leakage, adversarial attacks, and system prompt overrides must be systematically addressed within the firm’s overarching cybersecurity framework. Firms deploying AI in high-risk use cases must also remember their statutory obligations to notify the SFC.
Practical implications for organisations
The message from the regulators is unequivocal: senior management, particularly the Manager-in-Charge of Information Technology (MIC-IT), bears the ultimate responsibility for gatekeeping a firm’s cyber resilience.
As the SFC plans to conduct thematic reviews and take supervisory actions based on these evolving risks, a proactive approach is essential. Organisations should immediately map their technology ecosystems, assess their incident response readiness, and renegotiate critical vendor agreements. Crucially, given the overlaps with the broader Protection of Critical Infrastructures (Computer Systems) Ordinance, we advise clients to adopt a unified compliance strategy that addresses both regimes simultaneously.
For enquiries, please feel free to contact us at: |
|
E: technology@onc.hk T: (852) 2810 1212 19th Floor, Three Exchange Square, 8 Connaught Place, Central, Hong Kong |
|
Important: The law and procedure on this subject are very specialised and complicated. This article is just a very general outline for reference and cannot be relied upon as legal advice in any individual case. If any advice or assistance is needed, please contact our solicitors. |
|
Published by ONC Lawyers © 2026 |




