Four regulators mapped the system's cyber wiring — and the vendors kept repeating
A quiet week on the wire — one circular, no enforcement, no new filings. But the one circular is the sort worth reading slowly, because it tells you how four regulators are about to look at your outsourcing. This issue covers the week of 27 July – 2 August 2026.
The regulators can now see who you all depend on — and it's the same handful of vendors
On 29 July the SFC published Circular 26EC45, a joint circular with the HKMA, the Insurance Authority and the MPFA reporting the outcomes of the first production run of their cross-sectoral Cyber Mapping exercise, completed in March 2026. For the first time the Authorities could see how over 50 participating financial institutions — across banking, retail payment, securities and capital markets, MPF and insurance — are connected at both business and technology levels.
The headline finding is reassuring: there are no new and major “unknown-unknown” sources of systemic cyber risk. The biggest nodes turned out to be the institutions, market infrastructures and major technology providers — cloud, data centres, data services — already known to support critical functions.
The finding underneath it is the interesting one. A deeper look at specific business processes and ICT arrangements showed similar adoption patterns: participating firms were leaning on the same kinds of network infrastructure appliances and the same cybersecurity solutions for security event monitoring and privileged access management, with recurring specialist vendors also showing up in selected payment processing and customer communication workflows. The Authorities are careful to say this does not mean those providers are unsafe, or that a systemic issue already exists — but it does, in their words, support the case for early and forward-looking supervisory monitoring.
- Who's in scope: the circular is addressed to the Responsible Officers of all licensed corporations, alongside authorized institutions, stored value facility licensees, designated retail payment systems, authorized insurers and MPF approved trustees. Only 50-odd firms took part in the first run; the circular is addressed to everyone.
- What to do: nothing to file. The point is what comes next — the Authorities will adopt the Cyber Map to complement day-to-day supervision, especially in third-party risk and incident management, and where warranted will run drill exercises, thematic reviews and further contingency arrangements.
- By when: no deadline attached. The exercise is intended to become a recurring fixture, with the next run expected to commence in 2027/2028 and more details promised well in advance.
- TechnologyThis Saturday. HKEX Post Release Test 1 is on 8 August and is mandatory for Exchange Participants and China Connect Exchange Participants (26EC44); PRT 2 follows on 22 August. If a vendor runs your HKEX connectivity, confirm in writing that they are testing.
- TechnologyThe SFC's two Zoom sessions on AI-enabled cyberattacks ran on 30 July (26EC40). If you missed them, the underlying expectations are still on the record in 26EC32 — including that senior management, the MIC-IT included, is ultimately responsible for approving cybersecurity framework changes.
- AMLStill open from mid-July: the SFC's relay of FATF's June 2026 statements (26EC39) — countermeasures for the DPRK and Iran, enhanced due diligence proportionate to risk for jurisdictions such as Myanmar. Check client and transaction exposure if you have not since it landed.
The inspection you fail before it starts
No disciplinary action to report this week, so a reminder from the Record that carries real teeth: back on 29 January 2026 the SFC issued Circular 26EC3, telling licensed corporations to comply fully with their statutory obligations during inspections under section 180 of the SFO. It was not a theoretical reminder — the SFC said it had observed unsatisfactory practices that obstructed its supervision. The obligations it listed are unglamorous: give access to records, maintain them and retrieve them promptly, make Responsible Officers available, remain fit and proper, and stay accountable for external representatives acting for the firm. Breaches, it warned, risk supervisory and enforcement action.
The control that would have caught it is not a policy — it is a dry run. Once a year, ask someone to produce a named client’s full file, a specific trade’s audit trail, and the current version of a policy, and time it. If your records live in a departed colleague’s mailbox or on a vendor’s platform you cannot export from, you will discover it in a rehearsal rather than in front of an inspector. “We have it somewhere” is the sentence that turns a routine inspection into a finding.
That's issue three. If you outsource your monitoring, this week's homework is one page long. See you next Monday.
Get next Monday’s briefing in your inbox.
Five minutes, every Monday, 7:30am HKT. Free, unsubscribe anytime.
