HK regulator imposes $2.1M fine on Luk Fook Securities (HK) Limited for deficient cybersecurity control measures
The Securities and Futures Commission (SFC) of Hong Kong has reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) $2.1 million for failing to implement adequate and effective cybersecurity control measures, which might have contributed to its failure to withstand a ransomware attack and led to a delay of approximately three weeks in fully recovering its systems from the cyberattack.
The disruption from the 19 September 2022 ransomware attack on LFSHK’s critical IT infrastructure was sweeping, affecting file servers, domain controllers, email servers, trading application servers, and accounting servers. LFSHK restored its system in phases, and the process was not complete until 7 October 2022.
During the recovery period, LFSHK’s clients were unable to trade via the firm’s mobile trading app or internet platform, and they could only place orders through their account executives.
The SFC conducted an investigation which revealed multiple deficiencies in LFSHK’s cybersecurity policies and systems, following LFSHK’s self-report about the incident in which a hacker exploited the firm’s remote access system to gain entry to its server.
These deficiencies, which increased LFSHK’s vulnerability to cyberattacks and contributed to a delay in its recovery from the incident, included:
- a lack of firewall protection and adequate network monitoring;
- outdated operation systems and antivirus software;
- weak controls over user access and privileged accounts;
- poor password management practices, such as storing credentials in unencrypted files;
- insufficient controls over remote access and external devices;
- a lack of regular cybersecurity awareness training for staff; and
- inadequate data backup and business continuity arrangements.
The regulator concluded that LFSHK is guilty of misconduct after determining that the firm failed to fully comply with the cybersecurity requirements applicable to its regulated activities. LFSHK’s systemic failures, reflecting the firm’s failure to meet fundamental cybersecurity requirements mandated under multiple frameworks, have significantly contributed to both its inability to withstand the incident and the severity of its impact, thereby compromising its clients’ interests and the integrity of its operations.
In deciding the disciplinary sanction, the SFC took into account a variety of factors, including:
- LFSHK has conducted reviews to identify the root causes and extent of its failings, including by appointing an independent reviewer at the SFC’s request to conduct an independent assessment of the incident and its cybersecurity related internal controls;
- LFSHK has taken steps to enhance its systems and controls to prevent future breaches;
- there is no evidence that LFSHK’s clients suffered any loss as a result of its deficiencies;
- LFSHK’s co-operation in resolving the SFC’s concerns; and
- LFSHK’s clean disciplinary record.
