← Back to Voice Crypto & Digital Assets

Two Laws, One Standard: How the SFC's New Authentication Mandate and Cap. 653 are Reshaping Cybersecurity Accountability Across Every Sector

JC
Lawyer, Law Lecturer & Co-Chair, HK Web3 Association, HKU SPACE
DD
Do Do Chan
Associate Legal Director at Emperor Group
Aug 2026
Make RegTech.com preferred on Google
Two Laws, One Standard: How the SFC's New Authentication Mandate and Cap. 653 are Reshaping Cybersecurity Accountability Across Every Sector
Image Credit: https://www.hk-lawyer.org/

Hong Kong has always punched above its weight when it comes to financial innovation. She was among the first jurisdictions globally to license virtual banks, a move that forced traditional banks to digitise and genuinely changed everyday life. Gone are the days of queuing at the branch with a red passbook. In that era, draining a bank account required physical presence, a teller, and a signature. The passbook was inconvenient, but it was also a natural checkpoint. Today, customers manage their finances instantly, on any device, from anywhere in the world.

What was unexpected however was that convenience opened something closer to a Cyber-Pandora's box. Every digital device is a potential access point for cyber-criminals. Every app, every login screen, every notification link is a door that a criminal can test, at scale, from anywhere, at negligible cost. Then came AI.

Where the passbook era offered criminals one heavily guarded door (e.g., the bank's security and teller), the digital era offers millions. Cybersecurity incidents in Hong Kong rose 27% in 2025 to 15,877 reported cases, with phishing attacks accounting for 57% of all incidents. AI exasperated the situation by making phishing attacks hyper-realistic. Law enforcement and regulators have been fighting an uphill battle ever since, and the battlefield keeps expanding. Two legislative and regulatory developments in 2026 represent the most substantive escalation yet, and their combined reach extends far beyond the sectors they formally target.

Two Framework, One Architecture

One hard lesson underpins two recent instruments (SFC Circular 26EC35, issued on 9 July 2026 and the Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap 653): A sufficiently resourced attacker (especially where augmented by AI) will eventually find a way in. Law enforcement and regulators have since absorbed that reality.

The design philosophy of both the SFC's Circular 26EC35 and Cap. 653 is not to guarantee prevention. It is to make licensed corporations and critical infrastructure operators an entrenched, accountable line of defence operating on a zero-trust model: assume breach, minimise damage, detect fast, and disclose.

The SFC Circular 26EC35, issued on 9 July 2026, establishes a four-tier protection model for licensed brokers and virtual asset trading platforms.

  • First, prevention: one-time passwords are explicitly called out as inadequate and must be replaced by phishing-resistant authentication, specifically passkeys built on FIDO-standard public key cryptography where the private key never leaves the user's device, or bound-device login tied to a pre-verified registered device. Large internet brokers must comply immediately; all others within 12 months.
  • Second, detection: real-time surveillance of suspicious login, transaction and withdrawal activity, with heightened sensitivity required for virtual asset platforms given the irreversibility of crypto transfers.
  • Third, response: prompt client notification and rapid containment protocols when a breach occurs and detected.
  • Fourth, education: firms must proactively educate and alert clients to evolving nature of phishing threats.

Senior management bears personal accountability for client losses arising from control failures. This is not boilerplate. The SFC has stated it will hold management directly responsible.

Cap. 653 on the other hand came into force on 1 January 2026 and covers eight sectors including banking and financial services and IT infrastructure. Where the SFC circular is technically specific, Cap. 653 is governance-wide. Designated Critical Infrastructure Operators must maintain a formal security management plan, conduct annual risk assessments, commission independent security audits every two years, and report serious incidents to the Commissioner within 12 hours.

Both frameworks arrive at the same architecture: strong access controls, proactive governance, named senior accountability, and mandatory disclosure. Together they define what adequate cybersecurity looks like in Hong Kong law today.

Why Conglomerates Should Apply the Same Standard Even if Not Formally in Scope

Hong Kong is no stranger to multi-industry conglomerate. And whilst a diversified group operating across property, hospitality, entertainment and financial services may not hold an SFC licence or carry a Cap. 653 designation, the question is not whether these laws formally apply today, BUT INSTEAD, it is whether the group's systems are intertwined with entities they do, and whether the group's profile makes it a target regardless.

Cap. 653 requires designated operators to report incidents that originate from connected third-party systems. A group that provides payment processing, IT infrastructure or shared services to a regulated entity is functionally inside the blast radius of any breach. It becomes the weak-link, with contractual, reputational and potentially regulatory consequences even without direct statutory liability. Meanwhile, larger organisations with high visibility, multiple payment channels and extensive customer data are disproportionately attractive targets. Sophisticated attackers do not care for laws.

The Commissioner under Cap. 653 also holds broad ongoing powers to designate new operators, and the SFC has signalled it will progressively extend its cybersecurity expectations. A group that waits for formal designation will be implementing under regulatory scrutiny rather than on its own terms.

Takeaway for General Counsel

Both frameworks reflect a regulatory acknowledgement that determined attackers cannot always be stopped. The law's response is to hold intermediaries to a standard of defence-in-depth, detection, containment and disclosure. Any organisation intertwined with regulated entities, or large enough to be a prime target, will be measured against that standard in any post-incident inquiry regardless of formal scope.

For general counsel, three actions follow:

  • map which business units touch regulated or CI-adjacent activities;
  • benchmark existing access controls and governance plans against the SFC's four-tier model and Cap. 653's Code of Practice; and
  • brief the board that senior management personal liability is now explicit in one framework and structurally implied in the other.

Afterall, voluntary alignment now costs a fraction of enforced remediation after an incident.

This opinion piece by Joshua Chu and Do Do Chan first appeared in Hong Kong Lawyer (hk-lawyer.org). Republished with credit.

Link copied to clipboard