Insights

SFC cybersecurity & IT, explained for Hong Kong firms.

Practical, no-jargon guides to the IT and cybersecurity expectations facing SFC-licensed fund managers and financial firms — from licensing to investor due diligence.

SFC Compliance

SFC Type 9 licence: the IT & cybersecurity checklist for 2026

A practical IT and cybersecurity checklist for SFC Type 9 (asset management) licence applicants and licensed fund managers in Hong Kong — the controls the regulator expects, and the evidence to prove them.

Read the guide →
Cybersecurity

What the SFC's cybersecurity review found — and where small firms fall short

The SFC's thematic cybersecurity review found half of firms on end-of-life systems. Here are the common gaps in small Hong Kong financial firms, what Circular 25EC7 expects, and how to close them.

Read the guide →
Investor ODD

Investor ODD: the IT questions allocators actually ask

Operational due diligence puts IT and cybersecurity on the questionnaire. Here are the IT questions allocators ask Hong Kong fund managers during ODD — and how to have the evidence ready.

Read the guide →
Stay ahead

New SFC & IT guides, by email.

Occasional, practical notes on SFC cybersecurity, ODD and managed IT — no spam, unsubscribe anytime.

We never share your details.

Want this checked against your own firm?

Book a free IT & cyber assessment — a written, RAG-rated findings report on where your firm stands against the same areas these guides cover. No obligation.

Book your free assessment