Search

Hongke's latest articles

HongKe

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

[Hongke Solutions] Cybersecurity Training for Hong Kong’s Financial Industry: From Compliance Records to Human-Factors Risk Management

Financial institutions in Hong Kong—including banks, securities firms, fund and asset management companies, authorized insurers, and Mandatory Provident Fund (MPF) service providers—handle a vast volume of financial transactions, customer personal data, investment records, and cross-border payment instructions every day. Beyond defending against system intrusions, these organizations face a core challenge related to their day-to-day operations: Can front-line and back-office staff accurately identify anomalous threats at critical moments and strictly follow the correct procedures to respond immediately?

A business email compromise (BEC) scam impersonating management with payment instructions, a phishing website designed to trick customers into entering one-time passwords (OTPs), a social engineering message posing as internal IT support, and even a video conference using deepfake technology to realistically mimic a senior executive—all of these are highly likely to turn a company’s daily workflows into entry points for cyberattacks.

In light of this, cybersecurity awareness training must not be limited to a routine annual online course, nor should “course completion rates” be the sole metric for assessing compliance. For financial institutions in Hong Kong, establishing a "Human Risk Management Platform"—one that features continuous operation, precise measurability, flexibility to adapt to business functions, and the ability to fully retain audit trails for review by management and regulatory authorities—is the practical solution to ensuring an organization’s cybersecurity resilience.

As we enter 2026, the cybersecurity risks facing Hong Kong’s financial institutions have far exceeded the scope of traditional phishing emails. In June 2026, the Hong Kong Monetary Authority (HKMA) issued a special reminder to Authorized Institutions (AIs) that they must pay close attention to new types of cyber threats enabled by artificial intelligence (AI). Deepfake impersonation, highly realistic AI-generated social engineering content, and highly targeted identity theft and cross-border payment fraud are severely testing employees’ ability to assess risks in real time during day-to-day operations.

Core Operational Risks Faced by Hong Kong Financial Institutions

According to official data released by the Hong Kong Police Force, a total of 43,212 fraud cases were recorded across Hong Kong in 2025, with total losses amounting to approximately 8.1 billion Hong Kong dollars. Although the overall number of fraud cases and the amount of losses saw only a slight adjustment compared to 2024, fraud cases still accounted for nearly half of all crimes in Hong Kong. Among these, 5,135 cases of online investment fraud were recorded, involving losses totaling HK$3.58 billion, reflecting the extremely destructive impact that tech-enabled crimes—disguised as financial transactions and investment products—have on financial markets.

However, for financial institutions, cyber threats are by no means limited to clients falling victim to scams; attackers are increasingly targeting the institutions’ own employees and business approval processes.

1. Impersonation of Senior Executives and Fraud Involving Commercial Payment Instructions

Hackers and criminal groups often impersonate key figures such as chief executive officers (CEOs), chief financial officers (CFOs), fund managers, outside legal counsel, or long-standing suppliers to issue instructions directly to internal finance or operations staff:

  • Handling unexpected cross-border fund transfers on an emergency basis;
  • Update the bank account information for long-term suppliers;
  • Purchasing gift cards, cryptocurrency, or virtual assets;
  • Submitting sensitive customer personal information, compensation data, or tax documents;
  • Requiring employees to “handle matters on a case-by-case basis” and bypass the established dual authorization process;
  • Citing "trade secrets" or "urgent mergers and acquisitions," the company prohibits employees from verifying information with other colleagues within the organization.

These types of social engineering attacks typically do not contain malicious attachments or phishing links, making it extremely difficult for traditional email security gateways (SEGs) to verify their legitimacy; technical defenses alone cannot effectively block business instructions that appear legitimate.

2. Phishing Scams Targeting Customer Accounts and One-Time Passwords

The Hong Kong Securities and Futures Commission (SFC) issued a regulatory circular in May 2025 noting that clients of certain licensed corporations had received phishing text messages (SMS phishing) from fraudulent entities, After clicking on the links contained in these messages and entering their login credentials or one-time passwords (OTPs), these clients’ accounts were used by criminals to conduct unauthorized financial transactions.

The Securities and Futures Commission has specifically reiterated the compliance requirements for licensed corporations:

  • It is strictly prohibited to use hyperlinks embedded in emails or text messages to direct customers to the official website or mobile app to execute transactions;
  • It is strictly prohibited to ask customers to submit their personal login credentials or one-time passwords (OTPs) via any link;
  • Licensed institutions must regularly send cybersecurity alerts to their customers and establish a routine monitoring mechanism to promptly detect and block unauthorized access to online trading accounts.

Front-line customer service and operations teams must have a thorough understanding of the organization’s standard operating procedures (SOPs) for external communications so that, when they receive customer inquiries or reports, they can immediately and accurately identify fraudulent messages and promptly activate the internal cybersecurity incident reporting mechanism.

3. AI-powered voice, video, and deepfake impersonation

Generative AI enables attackers to easily create Chinese and English emails that sound extremely natural, and even mimic the voices and video footage of corporate executives. Data from the Hong Kong Police Force shows that in 2024, a total of fraud cases involving deepfake technology were recorded, including two cases suspected of using pre-recorded video conferences, which resulted in substantial losses of up to 240 million Hong Kong dollars and 4 million Hong Kong dollars, respectively. This clearly demonstrates that “seeing or hearing a colleague in person during a video conference” is no longer sufficient as the sole basis for confirming payment instructions or sensitive operations.

The skills required of finance, treasury, accounting, executive assistants, and IT support staff go far beyond simply identifying screen distortions; they must be able to strictly follow standard operating procedures (SOPs) to suspend operations when receiving high-risk instructions and confirm them through established, independent secondary verification channels.

4. Incorrect Transmission and Improper Handling of Customer Data

The risk of data breaches at financial institutions does not necessarily stem entirely from malicious attacks; human error on the part of employees can be just as devastating. Sending an email to the wrong recipient, attaching the wrong file, transmitting a full bank account number via unencrypted email, or copying confidential company data to a personal device can all pose serious privacy compliance and operational risks.

The Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong previously handled a case involving a financial institution: an employee unauthorizedly copied more than 4,000 company files to a personal computer, 51 of which contained personal data of approximately 6,600 customers, employees, and job applicants. In another case involving an insurance company, the Office specifically pointed out that internal guidelines alone are far from sufficient; in addition to providing ongoing training for frontline employees, organizations must also implement appropriate technical safeguards to eliminate the risk of data breaches caused by human error. Such risks cannot be addressed through routine annual tests; employees need to repeatedly practice, in scenarios closely resembling real-world work situations, how to identify sensitive data, verify recipient identities, use approved encrypted transmission tools, and immediately report incidents when mistaken transmissions occur.

Key Focus Areas of Regulatory Compliance: Continuity and Proportionality of Risk

Hong Kong’s financial sector is regulated by multiple agencies, and the specific compliance requirements for banks, securities firms, insurance companies, and Mandatory Provident Fund (MPF) providers each have their own distinct focus; therefore, it is not appropriate to simplify regulatory requirements into a fixed number of training hours or a list of courses. However, five core principles can be derived from the current regulatory framework:

  • Regular Training: Training must be ongoing, rather than limited to orientation or an annual formality;
  • Threat-Oriented: Training content must accurately reflect the real cyber threats currently facing the organization;
  • Dynamic Defense: Establish appropriate competency reviews and control measures for high-risk roles (such as financial approval and system administrators);
  • Auditable Records: Fully preserve the audit trail for training, phishing simulation tests, and corrective actions;
  • Coordination Mechanism: Training must be seamlessly integrated with technical controls, real-time monitoring, and the Incident Response Standard Operating Procedure (SOP).

1. Banks and Authorized Institutions

The Hong Kong Monetary Authority’s (HKMA) “Cybersecurity Fortification Initiative 2.0” (CFI 2.0) requires Authorized Institutions (AIs) to assess their cybersecurity resilience based on their inherent risks and maturity levels, and to continuously enhance their overall defensive capabilities.

The “Cybersecurity Professional Qualifications Framework” (ECF-C), implemented by the Hong Kong Monetary Authority (HKMA) and the banking industry, is a non-mandatory competency framework primarily intended for professionals in specific cybersecurity roles, rather than serving as a general training benchmark for all banking employees. Holders of ECF-C professional qualifications must meet corresponding Continuing Professional Development (CPD) requirements; for example, holders of the Associate Cybersecurity Professional (ACsP) qualification must complete at least 20 hours of verifiable CPD annually and accumulate a minimum of 120 hours every three years. However, this requirement applies only to holders of specific professional certifications; it cannot be directly equated with the training hours for general employees, nor can it be assumed that standard cybersecurity awareness courses automatically qualify for CPD credit.

2. SFC-Licensed Corporations

In its regulatory circular on cybersecurity risks associated with remote work, the Securities and Futures Commission (SFC) explicitly requires licensed corporations to provide appropriate cybersecurity training to all users of their internal systems on a regular basis. The scope of this training should cover phishing attacks, ransomware, secure Wi-Fi, and video conferencing.

3. Authorized Insurers and Mandatory Provident Fund Service Providers

Both the Insurance Authority (IA) and the Mandatory Provident Fund Schemes Authority (MPFA) emphasize the importance of information system security and data privacy. Insurance institutions and intermediaries must establish regular information security awareness programs to ensure that their employees are able to identify social engineering scams and safeguard customers’ confidential information.

4. Privacy of Personal Information

In accordance with Hong Kong’s Personal Data (Privacy) Ordinance (PDPO), financial institutions, as data users, must take all reasonably practicable steps to protect customers’ personal data from unauthorized access, processing, erasure, or use.

Why Can't Traditional Annual Training Keep Up with Current Threats?

  • The Same Old Canned Content: The company uses exactly the same training materials across the board, ignoring the fact that the threat models faced by senior management, finance, IT, and front-line customer service representatives are completely different;
  • Focusing Only on "Course Completion Rates": Using only the course completion rate as a metric does not allow for an assessment of employees’ actual ability to respond to real phishing emails or social engineering attacks;
  • Testing Is Out of Step with the Real-World Work Environment: Tests that are too simple or conducted too frequently make it easy for employees to figure out the pattern, preventing them from developing a genuine instinct for risk prevention.

Five Steps for Hong Kong Financial Institutions to Implement “Human Factors Risk Management”

  • Step 1: Establish a Risk Baseline (Baseline Assessment): Measure an organization’s current “Phish-Prone Percentage” through unannounced social engineering and phishing simulation tests;
  • Step 2: Grouping by Business Function (Role-Based Segmentation): Design customized scenario-based simulations and training for high-risk departments (finance, treasury, executive assistants, and system administrators);
  • Step 3: Establish a Regular Training Routine (Continuous Training Cadence): Replace one-time annual training with micro-learning and monthly phishing drills to maintain a high level of cybersecurity awareness;
  • Step 4: Integrating the Incident Reporting Process (Incident Reporting Integration): Streamline the process for employees to report suspicious emails and messages, and include “timely reporting” as a metric in drill evaluations;
  • Step 5: Measure Risk Reduction, Rather Than Focusing Solely on Participation (Measure Risk Reduction): Use data to track changes in employee behavior, increases in reporting rates, and reductions in high-risk behavior.

How Does KnowBe4 Help Financial Institutions in Hong Kong Implement Human-Factors Risk Management?

  • Multilingual Training and Localized Phishing Simulations: Provides multilingual materials, including Traditional Chinese (Hong Kong localization) and English, with content closely aligned with common phishing emails and fraud schemes targeting Hong Kong's financial markets;
  • Test scenarios specifically designed for financial functions: Provides highly realistic simulations for financial scenarios such as SWIFT fund transfers, customer OTP verification, and CEO payment instructions;
  • Smart Groups Dynamic Risk Management: Automatically identify high-risk employees or users who frequently click on phishing links, and automatically assign them supplemental training;
  • SmartRisk™ Risk Quantification Assessment: Calculates dynamic cybersecurity risk scores for individuals, departments, and the entire organization using algorithms, and provides clear data visualizations;
  • AIDA: Automation and Personalized Training: Use AI to automatically assign the most appropriate training content and testing frequency based on employees' risk profiles;
  • Real-Time Coaching: When employees perform high-risk actions (such as clicking on unknown external links or attempting to send sensitive data), a prompt appears immediately to provide real-time guidance;
  • Phish Alert Button—Quick Report Button: Report suspicious emails with a single click, seamlessly integrate with SOC/IT teams, and turn every employee into a "human firewall" for the company;
  • Comprehensive reports that meet regulatory and audit requirements: Generate detailed reports and audit trails that comply with HKMA, SFC, IA, and external audit requirements with a single click.

Key Considerations When Selecting a Cybersecurity Awareness Training Platform

When evaluating platforms, financial institutions in Hong Kong can ask vendors to specifically demonstrate the following capabilities, rather than simply comparing the number of courses:
  1. Does it support Traditional Chinese (Hong Kong), English, and any other languages required by the organization?
  2. Is it possible to tailor the content by department, position, region, and risk level?
  3. Can it simulate scenarios such as impersonation by senior management, payment changes, customer account phishing, and data transmission errors?
  4. Is it possible to track various employee actions, such as clicking, replying, and submitting data and reports?
  5. Is it possible to identify users who repeatedly make the same mistakes and arrange for targeted follow-up?
  6. Is it possible to compare risk trends at the individual, departmental, regional, and organization-wide levels?
  7. Can reports be exported, scheduled, and integrated with internal audit procedures?
  8. Is it possible to incorporate the organization’s own policies, branding, and incident reporting procedures?
  9. How does the platform handle user data, test data, and administrator permissions?
  10. Which features are included in the standard subscription, and which require a higher subscription tier or additional products?
  11. Can the supplier assist in designing the training schedule and performance metrics for the first year?
  12. If the course is to be used for CPD, has it been accredited by the relevant professional organization?
These questions help organizations determine whether a platform merely “delivers courses” or is capable of supporting ongoing human-factor risk management.

Conclusion: The True Value of Cybersecurity Awareness Training

Faced with increasingly complex AI-driven cyber threats and a stricter regulatory environment in 2026, Hong Kong’s financial institutions can no longer rely solely on technical firewalls for their cybersecurity defenses. Only by establishing a data-driven, routine, and dynamically adaptable human risk management mechanism can employees be transformed from “the most vulnerable weak point” into “the organization’s most resilient line of defense.”

Other Articles

Hongke Case

[Hongke Solution] Autonomous Driving Simulation Hybrid Rendering Solution – 3DGS and NeRF High-Fidelity Reconstruction

Hongke has launched an autonomous driving simulation hybrid rendering solution that combines the real-time splash rendering capabilities of 3DGS with the reconstruction advantages of NeRF. It supports multi-modal data output from cameras and LiDAR, as well as HIL (Hardware-in-the-Loop) testing, effectively addressing the challenges of domain offset and scene fixation.

Read more
Hongke Dry Goods

[Hongke Insights] How Can Real-World Road Scenarios Be Replicated in the Lab? Enhanced NMEA Playback Revolutionizes GNSS Scenario Replication Capabilities

An In-Depth Analysis of Enhanced NMEA Playback Technology. By combining messages such as GGA, GSV, and GSA with carrier-to-noise ratio data, this technology accurately recreates real-world GNSS road scenarios—including urban canyons and multipath interference—overcoming the limitations of traditional NMEA and IQ/RF recording methods, and enabling the validation of positioning algorithms for autonomous driving and the low-altitude economy.

Read more
Hongke Dry Goods

[Hongke Solutions] How Can Hong Kong Companies Prevent Phishing and Data Breaches? From Compliance Training to Employee Risk Management

The latest data from Hongke and the PCPD shows a sharp surge in phishing and data breaches in Hong Kong! Relying solely on rigid technical safeguards and annual training is no longer sufficient to prevent AI-powered social engineering. This article provides an in-depth analysis of how Hong Kong B2B enterprises can transition to “Human Risk Management,” effectively comply with the PDPO and financial regulatory requirements, and establish a zero-trust defense against human-related risks.

Read more

Contact Hongke to help you solve your problems.

Let's have a chat