The agenda is the message: cyber and scams, 28 September
Two and a half weeks, nothing new. The SFC’s circular list has not moved since 4 September, which means this issue covers a fortnight in which the regulator published nothing at all. So rather than pad it out, this one is about the single dated thing still on the calendar — and what its subject matter tells you.
The brokers' forum is next Monday, and the topic is the point
Circular 26EC54, issued on 4 September, announced that the SFC will host a brokers’ forum on 28 September 2026 at the SFC’s office on 43/F, One Island East, 18 Westlands Road, Quarry Bay.
The stated aims are to share supervisory observations and regulatory updates with a focus on cybersecurity and anti-scam measures related to the securities industry, and to engage the industry in ongoing discussions. That phrasing is worth reading twice. When a regulator picks one theme for the room it has assembled, it is telling you what its supervisors have been finding.
- Who's in scope: firms were invited to nominate relevant management and compliance personnel. Enrolment was one form per firm, maximum two representatives, and the forum is conducted in Cantonese, free of charge, with 1.5 CPT hours for attending the whole session.
- What to do: the enrolment window closed on 10 September, so if your firm submitted a form, the action this week is to watch the inbox — the circular says successful applicants are notified by email at least two days before the forum, so that notice is due before the weekend closes. Places went to the first nominee on each form on a first-come, first-served basis, with any remaining places then going to second nominees, so a submitted form is not a confirmed seat.
- By when: Monday 28 September. Queries go to brokerforum@sfc.hk.
- TechnologyThe phishing-resistant login clock is the one hard date still running. Circular 26EC35 gives internet brokers and SFC-licensed VASPs a 12-month implementation period ending 8 July 2027 for robust authentication on client login and device binding — but large internet brokers are expected to implement immediately, and the client notification, monitoring and surveillance measures and the hacking-incident response and reporting procedures were to be enhanced immediately, not in 2027.
- ConductSame circular, the detail that catches firms out: the SFC does not treat OTP — by SMS or email — as phishing-resistant. The 2025 incidents it describes were SMS campaigns that harvested credentials including the OTP, with a suspected man-in-the-middle interception. If your login journey still ends at a six-digit code, you are inside the population this circular is aimed at.
- AMLStill open from last month: the simplified eDDA deposit controls in 26EC51 (20 August), which deal with erroneous, unauthorised or fraudulent eDDA setup requests and the subsequent direct debit transactions. The SFC says it has been engaging relevant authorities and stakeholders about the safeguards around these arrangements, but that firms should nevertheless continue to assess the risks of their own use of them and implement appropriate controls in the meantime.
- ProductsType 9 managers of SFC-authorised funds: 26EC55 (3 September) expects existing funds with direct or indirect private market exposure to be reviewed and their offering documents updated as soon as practicable, with distributors told. “As soon as practicable” is not a date, which means the only clock on it is the one you set yourself.
- OTC derivativesThe updated list of prescribed persons who have reached the clearing threshold, posted per 26EC52 (31 August), may be updated from time to time by the HKMA and the SFC. If your entity trades OTC derivatives, checking whether it has appeared on that list is a recurring task, not a one-off.
The attacker that reads your code faster than your vendor patches it
No disciplinary action to report this fortnight, so a supervisory observation from the Record that sits directly under next Monday’s agenda. On 2 June 2026 the SFC issued Circular 26EC32 to licensed corporations, SFC-licensed VATPs and associated entities, setting out what it had found from engaging firms and key internet trading platform providers on their readiness for cyberattacks assisted or accelerated by AI tools. The findings are uncomfortable in a specific way: frontier AI models are increasingly capable of identifying security flaws that software developers have not yet found, and of chaining several individually low-rated vulnerabilities together into one high-impact compromise. The circular also notes that the interval between a vulnerability being disclosed and being exploited is rapidly shrinking, while the volume of vendor patches goes up.
That combination is what makes it an enforcement-shaped risk rather than an IT one. The control that would catch it is not a firewall purchase. It is an accurate, current inventory of technology assets — hardware, software, network, databases, cloud services — with the externally exposed, business-critical and third-party-dependent items flagged, kept current enough to support same-day prioritisation and containment when new threat intelligence lands. Without that list you cannot answer the only question that matters on the morning a zero-day is published: does this affect us, and where. The SFC is explicit about who owns the failure to be able to answer it — senior management, and specifically the Manager-In-Charge of Information Technology, who is expected to ensure changes to the cybersecurity framework are properly reviewed and approved and that enhancements are implemented promptly. If your MIC-IT cannot produce that inventory this week, the forum on Monday is about you whether or not anyone from your firm is in the room.
A quiet fortnight is not an empty one when the regulator has already told you what it wants to discuss. See you next Monday.
Get next Monday’s briefing in your inbox.
Five minutes, every Monday, 7:30am HKT. Free, unsubscribe anytime.

