The implementation of many strict cybersecurity regulations and requirements (including GDPR, NYDFS, and more) continues to increase on a global scale. 2018 has also brought about the continuation of strict cybersecurity regulations in the Asia Pacific region: most notably in Singapore, Australia, and Hong Kong. This year, one new requirement from 2017, the Securities & Futures Commission’s Guidelines, go into effect.
In October 2017, the Securities & Futures Commission (SFC) of Hong Kong issued a set of twenty baseline cybersecurity measures called the “Guidelines for Reducing & Mitigating Hacking Risks Associated with Internet Trading.” The SFC is an independent Hong Kong statutory body set up to regulate Hong Kong securities & futures markets. These guidelines seek to prevent, detect, and control the risks posed by cyber attacks. The implementation of these guidelines will be put into effect in a two-phase process. Phase One’s implementation went into effect in April 2018 — this primarily focused on the effectiveness of two-factor authentication. Phase Two will commence in July 2018, and focuses on instating all other guidelines.
These guidelines apply to both individuals and businesses engaged in internet trading that are licensed or registered with the SFC for regulated activities dealing with securities, futures contracts, foreign exchange trading, or asset management. As of this year, the guidelines will become legally binding and “failure to comply with these guidelines may result in punitive action.”