Hong Kong to tighten cyber-security rules in wake of multiple stock hacks

Hong Kong's Securities and Futures Commission is proposing new rules to strengthen cyber-security controls for stock trading following a spate of hacking incidents that resulted in hundreds of millions of dollars in losses.

  11 Be the first to comment

Hong Kong to tighten cyber-security rules in wake of multiple stock hacks

Editorial

This content has been selected, created and edited by the Finextra editorial team based upon its relevance and interest to our community.

The SFC is launching a two-month consultation on the proposed guidelines that set out 20 baseline cybersecurity requirements to mitigate against hacking risks.

The regulatory body says that for the 18 months ended 31 March 2017, 12 licensed corporations reported 27 cybersecurity incidents, most of which involved hackers gaining access to clients’ internet-based trading accounts with securities brokers, resulting in unauthorised trades totalling more than $110 million. Other incidents involved distributed denial-of-service attacks, accompanied by threats of extortion.

Key proposed requirements include two-factor authentication, for clients’ system login and prompt notification to clients of unusual activities in their internet trading accounts.

In addition, the SFC proposes to expand the scope of cybersecurity-related regulatory principles to cover the trading of securities which are not listed or traded on an exchange and to update the definition of 'internet-trading' to include mobile phones.

“Hacking of internet trading accounts is the most serious cybersecurity risk faced by internet brokers in Hong Kong,” says Ashley Alder, the SFC’s chief executive officer. “Brokers must strengthen their resilience to hacking and other cybersecurity risks by adopting robust preventive and detective controls.”

Sponsored [On-Demand Webinar] Beyond Open Banking – Exploring the Move to Open Finance

Comments: (0)

[New Report] UK Open Banking API Performance 2023-2024Finextra Promoted[New Report] UK Open Banking API Performance 2023-2024