Hong Kong Regulator Fines Broker HKD 2.1 Million for Inadequate Cybersecurity

Stock News
Jul 28

Hong Kong's Securities and Futures Commission (SFC) has publicly reprimanded and fined Luk Fook Securities (Hong Kong) Limited HKD 2.1 million. The penalty was imposed because the firm failed to implement sufficient and effective cybersecurity monitoring measures. This deficiency left the company vulnerable to a ransomware attack and delayed the full recovery of its systems by approximately three weeks.

The ransomware attack, which occurred on September 19, 2022, caused widespread disruption to Luk Fook Securities' critical IT infrastructure. Affected systems included file servers, domain controllers, email servers, trading application servers, and accounting servers. The company restored its systems in phases, a process that was not completed until October 7, 2022. During this recovery period, clients of Luk Fook Securities were unable to trade through the firm's mobile trading app or internet platform and could only place orders through their account executives.

The SFC initiated its investigation after Luk Fook Securities voluntarily reported that a hacker had breached its server by exploiting the company's remote access system. The investigation uncovered multiple deficiencies in Luk Fook Securities' cybersecurity policies and systems. These weaknesses made the company more susceptible to the cyberattack and prolonged the recovery time. Specific failures included: a lack of firewall protection and adequate network monitoring; outdated operating systems and antivirus software; weak monitoring of user access and privileged accounts; poor password management practices, such as storing credentials in unencrypted files; insufficient controls over remote access and external devices; a lack of regular cybersecurity awareness training for staff; and inadequate data backup and business continuity arrangements.

Based on these findings, the SFC determined that Luk Fook Securities had committed misconduct by failing to fully comply with cybersecurity requirements applicable to its regulated activities. The systematic deficiencies at Luk Fook Securities reflected a failure to meet basic cybersecurity standards outlined in multiple regulatory frameworks. These failures were the primary reason the company could not withstand the attack and why its impact was so severe, ultimately harming client interests and the firm's operational stability.

In deciding on this disciplinary action, the SFC considered all relevant circumstances. These included that Luk Fook Securities conducted a review to identify the root causes and scope of its deficiencies, including engaging an independent reviewer (as required by the SFC) to conduct an independent assessment of the incident and its internal cybersecurity controls. The company also took steps to improve its systems and controls to prevent future breaches. Furthermore, there was no evidence that any clients of Luk Fook Securities suffered financial losses due to the firm's failures. The SFC also noted that Luk Fook Securities cooperated in addressing the regulator's concerns and had no prior disciplinary record.

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10