Search

Hongke's latest articles

HongKe

Add your title text here

I. Introduction: Strategic Changes at the Data Layer under the Critical Infrastructure Legislation

[Hongke Solutions] Human-Centric Security Measures for Hong Kong Businesses: Compliance, Training, and AI-Powered Phishing Response

A payment email that appears to be from management, a WhatsApp message asking you to log back into your account, or an extremely realistic video conference invitation—any of these could be the starting point for hackers to infiltrate a corporate network. Generative AI has significantly lowered the barrier to entry for social engineering and phishing attacks. Attackers can quickly mimic the written language commonly used in Hong Kong, brand tones, and internal communication habits, and precisely target employees via email, text messages (SMS), social media platforms, and instant messaging apps. Even if a company has deployed firewalls,Endpoint Detection and Response (EDR) and Email Security Gateway...it remains difficult to completely prevent phishing and social engineering attacks that exploit interpersonal trust, a sense of urgency, and authorization approval processes.

Therefore, corporate management and IT security teams must address not just the question of “whether employees have completed training,” but three more critical and substantive issues:

  • Threat Response Capabilities: When employees encounter suspicious requests or unusual messages, can they promptly identify them and take the appropriate steps to report and defend against them?
  • Risk-Based Management: Which departments, specific positions, or individual employees are facing higher information security risks?
  • Quantitative Proof Mechanism: Can management use objective data and reports to demonstrate that security awareness training and simulation exercises have indeed improved employees' information security practices?

KnowBe4 Security Awareness Training Platform...It helps companies integrate cybersecurity training, phishing simulations, employee reporting, risk assessments, and real-time alerts into a continuous, self-improving cycle.

Latest Cybersecurity Situation in Hong Kong: Phishing Remains the Primary Threat

As of the first half of 2026, the Hong Kong Computer Emergency Response Team (HKCERT) had received a total of 8,358 reports of cybersecurity incidents, among which 5,305 incidents involving phishing, accounting for approximately 63% of the total incidents...representing a significant increase of approximately 25% compared to the same period in 2025. These official figures clearly demonstrate that phishing attacks have not disappeared despite increased corporate investment in technical defenses; rather, they continue to infiltrate corporate users through an increasingly diverse range of channels.

In addition, Verizon’s *2026 Data Breach Investigations Report* also notes that, among confirmed data breaches in the financial and insurance sectors,65%: Involves the Human Element; Common initial attack vectors include exploiting system vulnerabilities, phishing, and stolen login credentials. This is more in line with the latest market conditions and industry realities in 2026 than the "74%" figure cited earlier.

For businesses in Hong Kong and Southeast Asia, the following common attack scenarios warrant particular vigilance:

Business Email Compromise (BEC) and CEO Impersonation

Attackers impersonate a company’s CEO, CFO, a partner supplier, or a professional consultant to instruct finance or administrative staff to change the bank account used for receiving payments, process urgent foreign currency transfers, or hand over sensitive transaction and customer data. Such fraudulent messages typically employ a sense of urgency—such as “strictly confidential,” “specifically approved by management,” or “must be completed today”—to coerce employees into bypassing standard internal review procedures.

Account and Credential Theft (Credential Theft)

Attackers forge login notifications from banks, logistics and courier services, cloud service platforms, Microsoft 365, or other tools commonly used by enterprises to trick employees into entering their corporate account passwords, multi-factor authentication (MFA) codes, or one-time passwords (OTPs). Once hackers gain control of an account, they use the legitimate corporate email account to send fraudulent messages, further defrauding internal colleagues, customers, and supplier partners.

In a circular on phishing defense issued in 2025, the Hong Kong Securities and Futures Commission (SFC) specifically highlighted that some customers had received phishing text messages impersonating licensed corporations, and that after entering their login credentials on fake websites, their accounts were subject to unauthorized access and illegal transactions.

Omnichannel Social Engineering

Cyberattacks are no longer limited to traditional email. Attackers often begin by gathering information on a target company’s organizational structure and reporting relationships on professional social networking platforms such as LinkedIn, and then build trust through WhatsApp, voice calls, text messages (SMS), and even video conferences. If employees have only received training on “how to identify phishing emails,” they are highly likely to overlook the same risk signals when faced with cross-channel social engineering traps.

Misuse of Generative AI (Generative AI Governance Risks)

If employees directly input customer personal information, business contracts, financial data, system code, or internal confidential documents into unauthorized public AI tools, this can easily lead to compliance risks related to data governance, trade secrets, and personal privacy. Addressing this issue cannot be achieved simply by advocating a “ban on AI use”; companies must establish clear policies on the scope of AI use, data classification guidelines, and a list of approved tools, complemented by information security training tailored to real-world work scenarios.

The key to compliance is not simply “having taken a class,” but whether the controls are commensurate with the risks.

There is no uniform law in Hong Kong that applies to all businesses and requires every employee to complete a fixed number of hours of cybersecurity training. The actual requirements depend on the industry in which the business operates, its licensing status, the types of data it handles, its business risks, and relevant regulatory requirements.

Therefore, companies should avoid making general statements on their official websites or in compliance documents claiming that all Hong Kong companies are legally required to conduct periodic phishing simulation tests. A more accurate statement would be: Companies must, in accordance with their legal and regulatory obligations, implement personnel, process, and technical safeguards commensurate with the risk, and maintain adequate records to demonstrate that these measures have been effectively implemented.

The Personal Data (Privacy) Ordinance (PDPO)

Under Data Protection Principle 4 of the Personal Data (Privacy) Ordinance, data users must take all reasonably practicable steps to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use.

The Ordinance itself does not specify that companies must procure a particular type of training platform, but the guidelines issued by the Office of the Privacy Commissioner for Personal Data (PCPDO) in Hong Kong recommend that organizations establish comprehensive data processing policies and procedures and regularly remind employees to comply with them. In other words, security awareness training is part of an overall data security control framework; completing a single course does not automatically demonstrate compliance.

Hong Kong Monetary Authority (HKMA)

Hong Kong Monetary AuthorityImplemented Cybersecurity Fortification Initiative 2.0 (CFI 2.0) With network resilience assessment, professional development, and threat intelligence sharing as its three core pillars, this applies to authorized institutions. In 2026, the HKMA also issued a circular on strengthening cyber resilience in response to AI-enhanced cyber threats, reflecting the banking sector’s need to continuously assess whether existing controls can effectively address this new generation of attacks.

It is important to clarify that the Cybersecurity Professional Qualifications Framework (ECF-C) is primarily intended for professionals performing designated cybersecurity functions at recognized institutions; it is not a general security awareness training requirement for all bank employees, and the ECF-C itself is not a mandatory licensing system.

Hong Kong Securities and Futures Commission (SFC)

The SFC requires licensed corporations to maintain internal controls commensurate with their size, business, and risks. With regard to remote work arrangements, the SFC explicitly states that appropriate cybersecurity training should be provided to users of internal systems, and regular reminders regarding phishing, ransomware, and secure remote connections should be issued.

For licensed corporations, training records, simulation exercise results, and follow-up improvement measures can serve as evidence of the ongoing operation of internal controls; however, the ultimate determination of whether these meet regulatory requirements must still be assessed by the institution based on its own business operations and applicable regulations.

Why Are Traditional Annual Training Programs Often Insufficient?

Many companies have already scheduled annual cybersecurity training sessions, but similar incidents continue to occur on a daily basis. The problem usually isn't a complete lack of training, but rather a disconnect between the training and actual risks.

The content is out of touch with real-world work situations

General training courses may simply advise participants to “avoid clicking on links from unknown sources,” but they often fail to cover specific scenarios such as the finance department receiving a request to change a bank account, the human resources department receiving a resume with a malicious attachment, or customer service representatives being asked to disclose a one-time password (OTP).

Effective training should tailor its content to employees’ job functions. For example, finance and procurement teams need to focus on recognizing payment fraud and vendor email account compromise (VEC); management and administrative assistants, on the other hand, need to practice handling business email compromise (BEC), confidentiality requirements, and urgent directives.

Focusing only on completion rates, without measuring behavior

"98% Employee Course Completion" only serves as proof that the course was accessed and completed; it does not indicate how an employee would respond to a real attack.

Companies should also monitor the failure rate of simulated phishing tests, the rate of suspicious message reports, instances of repeated errors, risk variations across different departments, and improvement trends following training.

Lack of follow-up and feedback after issues are identified

If employees exhibit high-risk behavior during simulation exercises or in their daily work, traditional training lacks immediate, context-specific reminders and follow-up guidance. An effective system should be able to provide one-on-one just-in-time training the moment an incident occurs and automatically incorporate high-risk users into an intensive training process.

How Does KnowBe4 Establish a Continuous Human-Factor Risk Management Cycle?

1. Provide training and simulated fishing experiences in different languages

We provide a wide range of professional courses and phishing simulation templates, including Traditional Chinese (tailored to the Hong Kong context and multiple Southeast Asian languages), to ensure that the training content aligns closely with the language and cultural context of the company’s daily operations.

2. Verify actual responses through simulated attacks

Supports scheduled and automated phishing simulations to measure employees’ awareness of real social engineering threats in real time and accurately identify vulnerabilities in the organization’s defenses.

3. Use SmartRisk™ to Identify Risk Discrepancies

Through decentralization and big data analytics, the system calculates a Human Risk Score for different departments, roles, and individuals, helping IT and information security teams prioritize the allocation of defensive resources to the highest-risk nodes.

4. Make Employees Part of the Proactive Defense Strategy

With the one-click reporting plugin (Phish Alert Button), employees can report suspicious emails directly from Outlook, Gmail, or their mobile devices, transforming the notion that “employees are the biggest vulnerability” into “employees are the first line of defense.”

5. Reduce Repetitive Administrative Work with AI (AIDA)

By using AI-powered intelligent navigation (AIDA) to automatically analyze training results and assign personalized training courses to employees based on their risk levels, the system significantly reduces operational and administrative costs for IT and HR teams.

6. Provide records required for management and auditing purposes

Automatically generate detailed reports that meet the requirements of the board of directors, external auditors, and regulatory bodies (such as the HKMA, SFC, and PCPDO), clearly demonstrating the company’s effectiveness in mitigating human-related risks and ensuring compliance.

How can Hong Kong businesses get started?

  1. Assessment of Existing Human Factors Risk Criteria: Conduct an unannounced phishing simulation to determine your organization’s current actual phishing click-through rate and reporting rate.
  2. Develop a Tiered Training Plan: Based on departmental functions and risk levels, provide context-specific Traditional Chinese training courses and automated simulation exercises.
  3. Implement a One-Click Reporting System: Promote the suspicious email reporting tool (Phish Alert Button) to encourage employees to develop the habit of taking proactive defensive measures and reporting incidents.
  4. Regularly Review and Optimize Reports: Submit quantitative analysis reports to management and regulatory authorities to continuously optimize information security defense strategies.

Conclusion: What really needs to be managed is behavior, not just completion rates.

In an environment where generative AI is making social engineering attacks increasingly sophisticated, cybersecurity is no longer merely a technical issue for the IT department, but rather a behavioral management challenge for all employees across the company. Only by establishing a continuous human-factor risk management cycle can we effectively safeguard the company’s digital assets and business trust.

Other Articles

Hongke Dry Goods

[Hongke Insights] Did You Receive an Urgent Email from the CEO Asking for a Wire Transfer? It Might Be a Scam: How Companies Can Protect Themselves Against Business Email Compromise Scams

An urgent email from the CEO requesting a wire transfer could be a Business Email Compromise (BEC) scam! Scammers impersonate the CEO, CFO, or a supplier and use their positional authority, along with urgent and confidential language, to trick employees into making wire transfers, changing bank accounts, or disclosing sensitive information. This article breaks down common CEO fraud tactics and shares prevention strategies for businesses, including KnowBe4-style security awareness training, simulation exercises, one-click reporting, independent payment verification, and dual approval processes—all designed to help organizations thwart these scams.

Read more
Hongke Dry Goods

[Hongke Insights] The Hong Kong Monetary Authority’s Anti-Fraud Checklist Reveals Corporate Blind Spots: Why the Financial Industry Needs KnowBe4-Style Cybersecurity Awareness Training

The Hong Kong Monetary Authority’s “Beware of Scammers!” anti-fraud checklist is continuously updated, exposing scammers who impersonate banks and create fake websites, emails, and apps. Phishing attacks are becoming increasingly industrialized, and nearly all of Hong Kong’s major banks have been targeted by imposters. Relying solely on firewalls and email gateways makes it difficult to block social engineering attacks that bypass technical checks; what scammers truly exploit is people’s sense of urgency and trust. KnowBe4-style cybersecurity awareness training employs a closed-loop “assessment, training, simulation, feedback” approach. Through simulated phishing attacks, microlearning, real-time coaching, and quantifiable reports, it continuously enhances employee vigilance, transforming employees from the weakest link into the first line of defense.

Read more
Hongke Dry Goods

[Hongke Insights] Behind the $135.6 Billion Overseas Expansion Bonanza, a Single Data Breach Could Undo All Efforts

The global cross-border e-commerce market is valued at a staggering $135.6 billion! However, when it comes to exporting fresh produce, pharmaceuticals, and sensitive, high-value products, gaps in environmental monitoring and data compliance are becoming a critical vulnerability for businesses. A single data interruption or temperature deviation could result in the destruction of an entire shipment and exorbitant fines. This article provides an in-depth analysis of the three major data risks in the cross-border supply chain and introduces Hongke ELPRO’s enterprise-grade data logging and cold chain monitoring solutions.

Read more

Contact Hongke to help you solve your problems.

Let's have a chat