All articles
18 June 2026 7 min read Pentastic Governance Team

SFC Cybersecurity Guidelines: What Hong Kong Brokers Must Do in 2026

A practical breakdown of the SFC's 20 baseline cybersecurity requirements and the gap-analysis steps internet brokers should prioritize this year.

The Securities and Futures Commission's Cybersecurity Guidelines continue to reshape how licensed corporations in Hong Kong protect client assets and trading systems. As enforcement activity increases, internet brokers can no longer treat the 20 baseline requirements as an audit checkbox — regulators expect demonstrable, continuous control.

The most common gaps we see during SFC readiness engagements are inconsistent two-factor authentication coverage, weak logging on internet trading systems, and outdated incident response playbooks that don't reflect current ransomware tradecraft.

For 2026, prioritize three areas: (1) a documented network segmentation review that isolates internet-facing trading systems, (2) independent penetration testing of the trading front-end and APIs, and (3) tabletop exercises that rehearse regulator notification within the required timeline.

A structured gap analysis, mapped directly to the 20 baseline requirements, produces defensible evidence for both internal audit and SFC inspections. Done well, it also shortens remediation cycles because owners, deadlines, and risk ratings are captured in one artifact.

Need help applying this in your organization?

Pentastic's consultants advise Hong Kong enterprises on penetration testing, SFC compliance, PIAs, and security awareness.

Talk to a consultant