Hong Kong’s Securities and Futures Commission (SFC) has reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) HKD2.1 million for failing to implement adequate and effective cybersecurity controls. This is one of the SFC’s most significant cybersecurity-related enforcement actions to date, and its first arising from an actual cyberattack that disrupted a licensed corporation’s trading systems. The decision offers a useful precedent for all SFC-regulated firms.
On September 19, 2022, a ransomware attack caused extensive disruption to LFSHK’s critical IT infrastructure, affecting file servers, domain controllers, email servers, trading application servers, and accounting servers. LFSHK restored its systems in phases, with full recovery achieved more than two weeks later.
Throughout the recovery period, clients could not trade via the firm’s mobile app or internet platform and were limited to placing orders through their account executives. LFSHK then self-reported on the same day that a hacker had exploited the firm’s remote access system to access its servers, and the SFC subsequently launched an investigation.
The SFC’s investigation identified multiple deficiencies in LFSHK’s cybersecurity policies and systems, including:
The SFC determined that LFSHK had failed to fully comply with the cybersecurity requirements applicable to its regulated activities and had engaged in misconduct. The SFC characterised LFSHK’s failings as “systemic”, stating that the firm failed to meet fundamental cybersecurity requirements mandated under multiple regulatory frameworks. These failings significantly contributed both to the firm’s inability to withstand the attack and to the severity of its impact, compromising client interests and the integrity of its operations.
In setting the sanction, the SFC took into account a number of mitigating factors, including the following:
Read together, this decision demonstrates the SFC’s shift from guidance to enforcement, while reinforcing a broader Hong Kong regulatory expectation that cybersecurity is a senior management accountability issue.
This action signals that the SFC is prepared to impose direct financial penalties for cybersecurity control failures, not merely require remediation, even where there is no evidence of actual client loss. It confirms that the SFC treats cybersecurity as a core regulatory compliance obligation, and that systemic gaps across people, process, and technology can lead to a misconduct finding.
More broadly, the decision is consistent with the wider regulatory approach in Hong Kong, including the HKMA’s expectation that for authorised institutions, senior management, rather than the IT function alone, is ultimately accountable for cybersecurity. Regulators are increasingly focused not only on the effectiveness of technical controls, but also on firms’ governance, incident response capabilities, third-party risk management, and overall resilience to cyber incidents.
Notably, cybersecurity enforcement in Hong Kong has traditionally been driven by the privacy regulator, and recently through critical infrastructure frameworks, rather than by industry-specific regulators.
However, in the absence of a general cyber resilience law, sectoral regulators such as the SFC and the HKMA are increasingly stepping into this space, using their existing supervisory powers to hold licensed firms directly accountable for cyber risk management. This shift underscores a growing expectation that cybersecurity is not merely an IT concern but a fundamental component of regulatory compliance across the financial services industry.
In light of this decision, firms should consider the following steps:
We would be pleased to how evolving regulatory expectations may affect your organisation’s cybersecurity, operational resilience and risk management frameworks, and to assist in assessing and strengthening your preparedness against prevailing industry standards.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought your specific circumstances.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
