Search

Hongke's latest articles

HongKe

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

[Hongke Solutions] From Compliance Training to Personnel Risk Management: Defense Strategies for Hong Kong Companies to Combat Phishing and Data Breaches

For many Hong Kong companies,Phishing is by no means an unfamiliar topic. While most organizations have already implemented email filtering,,Endpoint Protection, Multi-Factor Authentication (MFA)up toTechnical safeguards such as network monitoring, and we arrange regular annual information security training for our employees. However, as hacker threats have evolved, attack methods no longer rely solely on technical vulnerabilities but frequently involve impersonating corporate executives, customers, financial institutions, logistics companies, suppliers, and even Microsoft 365 system notifications in business contexts. In this context, the traditional compliance training model—which focuses on “checking off attendance and completing courses”—is no longer sufficient to comprehensively defend against highly covert, real-world cyber risks.

QuoteAccording to official data released by the Hong Kong Computer Emergency Response Team (HKCERT), Hong Kong recorded a cumulative total of 15,877 cybersecurity incidents in 2025.According to the report, the figure surged significantly by 27% year-over-year, breaking the all-time high. Among them,Phishing AttacksAt 57%, it continues to rank as the top security threat to businesses. HKCERT issues a special warning that the widespread adoption of generative AI technology has greatly increased the realism of phishing emails and deceptive messages, making them significantly harder to detect. At the same time, the scope of phishing attacks has expanded significantly beyond traditional email to include instant messaging apps (such as WhatsApp, accounting for 34%) and cryptocurrency platforms (accounting for 18%).

On the other hand, the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong KongThe 2025 Work Report noted that a total of 246 cases were received throughout the yearReports of data breaches increased by 21% compared to 2024. Among all reported cases, 81 data breaches were caused by hacker intrusions, accounting for 33% of the total incidents; The remaining primary causes of data breaches included the loss of documents or portable devices, accidental disclosure of personal data via email or fax, employee violations of operating procedures, and system configuration errors. In addition, the Office received 1,163 inquiries related to suspected phishing of personal data during that year.

The statistics cited above clearly demonstrate that the security challenges companies face today have long since moved beyond the simple question of “whether employees will click on suspicious emails”; rather, they now extend to “how employee behavior comprehensively impacts corporate account security, personal data protection, payment processes, business continuity, and incident reporting mechanisms.”

Technical controls are the cornerstone of security, but they cannot completely replace human judgment regarding safety.

There is no denying that email security gateways can effectively block known malicious URLs, and endpoint protection solutionsIt can accurately detect malicious code, andMulti-factor authentication (MFA) can also significantly reduce the risk of account compromise resulting from a single password leak. The technical controls mentioned above remain an indispensable cornerstone of a robust corporate cybersecurity framework.

However, the core issue is that social engineering attacks are often highly concealed within a company’s routine, legitimate business processes.

For example: An attacker might impersonate a partner supplier to request that the finance department change the bank account for a wire transfer; pose as a senior executive to order an employee to urgently purchase gift cards; impersonate the Human Resources (HR) department to trick employees into logging back into the payroll system; or use generative AI technology to precisely mimic familiar communication styles, official document formats, and specific business details, thereby significantly increasing the credibility of the fraudulent messages.

In such highly customized scenarios, the phishing email itself often contains no malicious attachments at all, and the embedded URLs may point to newly registered domains, making it impossible for security systems to blacklist them immediately. Ultimately, whether an organization can successfully prevent damage depends entirely on whether frontline employees can proactively verify unusual requests, remain vigilant in identifying signs of social engineering, strictly adhere to established operational procedures, and report any incidents to the internal information security team immediately.

Based on this,Security awareness is by no means a fallback option intended to replace technical controls; rather, it must be deeply integrated into an organization’s overall cybersecurity defense system.a key line of defense.

Hong Kong Cybersecurity Regulatory Matrix: Compliance Goes Far Beyond Firewalls and Antivirus Software

In accordance with Hong Kong’s Personal Data (Privacy) Ordinance (PDPO)Standardized"Data Protection Principle 4 (Data Security)": Data users (organizations) must take all reasonable and practicable precautions to properly safeguard the personal data in their possession and prevent unauthorized or accidental access, processing, deletion, loss, or other unlawful use of personal data. If an organization outsources the processing of personal data to a data processor, it must also ensure, through contractual provisions or other binding mechanisms, that the data processor implements an appropriate level of data security safeguards.

The Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong has further specified that both new and current employees of companies should receive information security training at the start of their employment and on a regular basis thereafter. Although the regulatory provisions do not mandate that companies purchase security awareness training products from specific brands, nor do they explicitly require the comprehensive implementation of phishing simulation exercises; if the mishandling of data, the leakage of login credentials, or clicking on phishing links by employees constitutes an operational risk that the company could reasonably foresee, then employee training, internal operating procedures, access controls, simulation tests, and incident reporting mechanisms are all considered integral and legitimate components of the company’s overall data security measures.

In its past reviews of data security violation cases, the Office has repeatedly and explicitly required the organizations involved to comprehensively enhance employee training, effectively monitor the progress of implementing internal security policies, and develop specific training implementation plans. This means that it is simply not enough for companies to merely establish compliance policies; they must also provide concrete evidence confirming that these policies have been fully implemented and that all employees have developed the necessary awareness of data privacy protection.

Financial institutions face more specific and rigorous compliance and regulatory expectations

For banks, securities firms, insurance companies, and other regulated financial institutions, managing human risk has long gone beyond the scope of general best practices and has officially become one of the core review metrics within the financial regulatory framework.

In its *2023/24 Thematic Review Report on Cybersecurity for Licensed Corporations*, the Hong Kong Securities and Futures Commission (SFC) explicitly stated that licensed corporations should provide regular cybersecurity awareness training to all staff and identify phishing as one of the key training topics. The report also specifically emphasized that conducting regular phishing simulation exercises is an effective way to test staff vigilance and their ability to respond to such attacks, and can help organizations accurately determine whether additional follow-up training is needed.

Among the institutions participating in the SFC’s review, about half conduct quarterly simulation exercises, while about one-third do so once a year; many institutions also arrange follow-up remedial training for employees who fail the tests. The SFC also emphasized that,Staff Reports ImmediatelyandTechnical Security MeasuresThey are equally important and are both key methods for successfully identifying phishing attacks.

It is worth noting that the SFC has clearly stated that it will conduct another comprehensive review of the current cybersecurity requirements and expected standards in 2025, with a view to establishing a unified cybersecurity framework applicable to the entire industry. In addition, the SFC’s report disclosed that, between 2021 and 2024, licensed corporations reported a total of eight major cybersecurity incidents, some of which caused severe business disruptions, while others involved customer accounts being hacked—where fraudsters exploited security vulnerabilities to gain system access and execute unauthorized transactions. This indicates that regulatory requirements are continuing to tighten, and management at licensed corporations must clearly recognize that cybersecurity is an overarching responsibility at the organizational level and should not be left solely to the information technology (IT) department.

This highlights a key distinction:The completion rate only demonstrates that employees have opened or completed a course; it does not directly prove that they can make the correct defensive decisions when faced with a real cyberattack.

The metrics that companies truly need to closely monitor and evaluate include:

  • Will employees click on the simulated phishing link;

  • Would you enter your real login credentials on a simulated phishing page?;

  • Can you proactively report suspicious emails to the internal security team;

  • Does the same individual repeatedly engage in the same high-risk behaviors?;

  • After receiving additional targeted training, have their risky behaviors improved?

Only these behavioral indicators can truly reflect whether a company’s security awareness program is actually effective.

Critical Infrastructure Regulations Also Include Social Engineering in Incident Management

Hong Kong’s “Protection of Critical Infrastructure (Computer Systems) Ordinance” officially took effect on January 1, 2026, formally establishing a statutory framework to safeguard the security of critical infrastructure computer systems. It is important to note that the Ordinance does not apply to all local businesses in Hong Kong; only designated critical infrastructure operators and systems designated as critical computer systems are subject to the relevant statutory regulations.

However, the Ordinance and related codes of practice clearly reflect the direction of Hong Kong’s cybersecurity governance. The official incident reporting form has formally designated “phishing/social engineering” as a specific category of computer system security incidents; depending on the severity of the incident, designated operators must, within 12 hoursmaybe 48 hoursIssue a statutory notice. If the operator fails to fulfill its statutory obligations, it may be subject to a fine of up to 5 million Hong Kong dollars; in the case of a continuing offense, an additional penalty of HK$50,000 to HK$100,000a fine.

This also clearly demonstrates that whether employees can promptly identify and report suspicious activities is by no means merely an internal performance issue for the training department; rather, it directly impacts the company’s incident detection time, the speed of internal reporting, external regulatory reporting, and the overall efficiency of emergency response.

Why is annual training no longer sufficient?

Currently, many companies’ security awareness programs are still centered around annual training sessions: employees are asked to watch videos and complete online quizzes, the system automatically records their completion status, and then the process is repeated the following year.

While this traditional, one-time approach may meet the most basic compliance training requirements, it has several very obvious limitations in terms of risk mitigation:

  1. The training content is not up to date with the latest attack methods: Phishing templates, deepfakes, QR code phishing (quishing), OAuth authorization scams, and attacks on instant messaging platforms (such as WhatsApp and Telegram scams) are all rapidly evolving; course content from a year ago is simply not sufficient to address today’s threats.

  2. The risk profiles vary significantly across different positions.: Finance and procurement staff are more likely to encounter changes to payment instructions, invoice fraud, and bank account change scams; management is more likely to be targeted by business email compromise (BEC) and deepfakes; and IT administrators may face password reset attempts, multi-factor authentication (MFA) fatigue attacks, and phishing targeting privileged accounts.

  3. Applying the same curriculum indiscriminately is inefficient: Providing exactly the same training to all employees may not be the most effective approach. The level of training required and the frequency of delivery are clearly very different for employees who have never engaged in high-risk behavior compared to high-risk employees who have repeatedly clicked on simulated phishing links.

Shifting from “Course Completion” to a Continuous, Closed-Loop Approach to Personnel Risk Management

Compared to traditional training, which is conducted only once a year, mature companies generally adopt a continuous, closed-loop management framework:

Risk Assessment => Basic Training => Simulation Exercises => Behavioral Analysis => Targeted Remedial Training => Retest => Management Report

Companies should first conduct baseline testing to identify the implementation risk benchmarks for each department and position, and then tailor training courses and simulated phishing tests to specific business scenarios.

When it comes to evaluation metrics, the effectiveness of information security measures must not be limited to a single metric such as “click-through rate (CTR)”; rather, it should comprehensively incorporate the following diverse behavioral metrics:

  • Credential Submission Rate.;
  • Suspicious Email Self-Reporting Rate (Reporting Rate).;
  • Repeat Failure Rate.;
  • Time Required to Complete the Training and Test Scores.;
  • Differences in Risky Behaviors Between New Hires and Current Employees.;
  • Trends in Continuous Improvement in High-Risk Departments.;
  • Time-to-Report: The time from receiving a suspicious message to completing the internal reportThe

Companies should also implement risk grouping based on job functions. For example:

  • because ofFinance and Procurement DepartmentDesign scenarios such as changes to payment instructions by suppliers and invoice fraud;

  • Simulate job applications containing malicious attachments and employee data inquiries for the Human Resources (HR) department;

  • because ofManagementDesigning business email compromise (BEC) scams that impersonate senior executives or legal counsel, along with high-level targeted testing.

In terms of training models, organizations should adopt high-frequency, short-duration, flexible micro-learning approaches, such as new employee onboarding training, quarterly micro-courses, just-in-time coaching following clicks on phishing links, and supplemental training for high-risk personnel. This continuous, incremental approach can more effectively integrate security awareness judgment into employees’ daily work habits.

The Key Role of the KnowBe4 Platform in Enterprise Employee Risk Management

Although companies can attempt to set up these processes on their own using traditional email systems, learning management systems (LMS), surveys, or Excel spreadsheets, the administrative costs associated with manual maintenance will rise significantly as the company expands, operates across regions, faces multilingual requirements, and increases the frequency of training.

KnowBe4 Security Awareness Training Platform CanSecurity Training, Phishing Simulation Drills, Automated User Grouping, Risk Scoring, and Executive Management ReportsFully integrated into a single management process. Organizations can flexibly create dynamic groups based on department, function, geographic location, training progress, or drill performance, and precisely distribute the corresponding training materials and assessment tasks.

For example, when an employee fails a simulated phishing drill, the platform can automatically assign them to a dedicated supplemental training group based on preset rules; once they complete the supplemental training, the system will trigger a follow-up test to scientifically track whether high-risk behaviors have decreased.

At the same time, the platform consolidates training coverage, the results of phishing simulation exercises, dynamic risk scores, and overall trends into intuitive management reports, helping decision-makers clearly understand the distribution of high-risk departments, the effectiveness of internal cybersecurity defenses, and the trajectory of improvements in overall enterprise-wide personnel risk.

March 5, 2026, KnowBe4 has officially joined as a corporate memberHong Kong Cybersecurity Association (HKCNSA). Mr. Ye Qingyang, the Association’s Founding Chairman, noted that KnowBe4 possesses cutting-edge technology and extensive experience in the global fields of Human Risk Management and security awareness training. Its AI-driven, integrated defense platform will inject innovative defensive capabilities into the Association and comprehensively advance the security capabilities of Hong Kong enterprises. KnowBe4 has been deeply involved in the cybersecurity market for over 15 years, has been recognized as a Leader in Gartner®’s Email Security Magic Quadrant™, and currently serves more than 70,000 organizational clients worldwide.

KnowBe4’s core value goes far beyond simply “sending simulated phishing emails”; rather, it helps companiesTraining, Drills, Remedial Instruction, and Data ReportingSeamless integration forms a closed-loop management system that supports sustainable operations and self-iteration.

However, simply implementing platform tools does not automatically ensure full compliance with Hong Kong’s local laws or financial regulatory requirements. Companies must still develop corresponding internal information security policies, approval processes, and data governance mechanisms tailored to the specific characteristics of their industry, business model, data sensitivity, and risk level.

When conducting phishing drills, it is important to protect employees’ personal data privacy.

In implementingDuring phishing simulations, the system may record employees’ email addresses, website click behavior, sensitive data entries, incident reports, training quiz results, and risk scores.. Once the aforementioned data becomes capable of identifying specific employees, companies must rigorously assess the necessity of data collection, the scope of usage authorization, access control measures, retention periods, and information security procedures.

In accordance with the “Guidelines on Surveillance in the Workplace” issued by the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong, before implementing any monitoring measures involving the processing of employees’ personal data, employers should first assess the necessity of such measures from a compliance perspective, the specific operational risks faced by the organization, and the potential impact on employees’ data privacy. They should also establish open and transparent internal policies and clearly communicate them to all affected employees.

Therefore, when implementing a phishing defense program, organizations are advised to take the following specific measures:

  • Open and Transparent Communication: Clearly specify the procedures for conducting simulated security tests and their defensive purposes in the company’s information security policy, employee handbook, or a dedicated announcement;

  • Minimize Data Collection: Collect only the data elements necessary to achieve information security governance objectives;

  • Strict Access Control: Restrict access to individual practice test results to prevent data misuse;

  • Appropriate Retention and Deletion Mechanisms: Establish clear and legally compliant data retention and periodic destruction procedures;

  • Building a Positive Safety Culture: It is strictly prohibited to publicly name or humiliate employees who fail the test;

  • Replacing Punishment with Educational Guidance: Focus the drills on knowledge-based empowerment and risk mitigation, rather than purely administrative disciplinary measures;

  • Interdepartmental Joint Review: The appropriateness of highly sensitive exercise scenarios is jointly assessed by the information security, human resources (HR), legal compliance, and management teams.

In addition, if a company uses a cloud platform to process employees’ personal data, it must also carefully review the location where data is stored on cloud servers, cross-border data transfers, the management of third-party subcontractors’ access rights, access controls, and data deletion mechanisms. According to “Data Protection Principle 2” and “Principle 4” of the Personal Data (Privacy) Ordinance (PDPO), as data users, organizations must—when engaging data processors, whether domestic or overseas—ensure, through binding contractual terms or other legal mechanisms, that data security meets statutory standards and that personal data is not retained beyond the period reasonably necessary.

Conclusion: Building a Sustainable, Evolving Closed-Loop System for Personnel Risk Management

Overall, companies in Hong Kong and Southeast AsiaBuilding Information Security Awareness...is undergoing a profound paradigm shift—moving away from the traditional compliance training held only once a year in the past toward a comprehensive, routine, and data-driven Human Risk Management framework.

In the face of increasingly complex cyber threats, the core issue that corporate decision-makers truly need to assess has long gone beyond simply “how many employees have completed the training course”; instead, they must clearly answer:

  • Do companies have a clear understanding of which business roles (such as finance, HR, and IT administrators) are at higher risk of cyberattacks?

  • Do all employees have the awareness and ability to immediately identify and proactively report suspicious social engineering messages?

  • Once high-risk behaviors have been identified, does the company have a mechanism in place to provide immediate, targeted education and corrective measures?

  • Can management use dynamic dashboards to continuously monitor trends in personnel risk across the entire company?

  • In the event of a data breach or security incident, can a company provide regulatory authorities with sufficient evidence to confirm that it has implemented practical security measures commensurate with the risk?

for example KnowBe4 et al. (and other authors)Security Awareness Training and Phishing Simulation Platform...can effectively help organizations seamlessly integrate risk assessments, online training, hands-on drills, targeted remedial training, and executive-level reporting. However, technical tools are always just one component of the defense; the platform can never fully replace an organization’s own data governance, underlying technical defenses, internal compliance policies, and robust incident response mechanisms.

Other Articles

Hongke Case

[Hongke Insights] A Buyer’s Guide to Enterprise-Grade Smart Glasses: 8 Key Differences Between AR Glasses in Industrial and Medical Applications

Are you evaluating AR smart glasses for warehouse logistics, modern manufacturing, or telemedicine? This article provides an in-depth comparison of the eight key differences between consumer-grade and enterprise-grade smart glasses. Hongke offers professional AR solutions for businesses in Hong Kong and Southeast Asia that feature high security, support for MDM management, and reduced TCO. Read the buying guide now!

Read more
Hongke Dry Goods

[Hongke Insights] The Wave of Chinese Innovative Drugs Going Global: A Comprehensive Guide to Pharmaceutical Cold Chain Compliance and Temperature Monitoring During Transport

2026 will mark a boom period for the global expansion of China’s innovative drugs and biologics. How can you ensure that cross-border shipments comply with FDA 21 CFR Part 11 and EU GDP regulations? ELPRO LIBERO temperature recorders from Hongke offer a training-free, globally recognized pharmaceutical cold chain compliance solution, helping biotech companies successfully expand into global markets such as Hong Kong and Southeast Asia.

Read more
Hongke Dynamic

[Authoritative Recognition] Hongke MSR Named One of the World’s Top 15 Shock Data Logger Companies

Hongke’s MSR Data Logger has been ranked among the top 15 in the global shock data logger market! Designed specifically for precision instruments, semiconductor equipment, and cold-chain logistics, it provides high-precision three-axis shock, vibration, and temperature/humidity monitoring, comprehensively ensuring the safety of B2B cross-border logistics and supply chains. Learn more about our professional-grade transportation environment monitoring solutions today.

Read more

Contact Hongke to help you solve your problems.

Let's have a chat