Built for SFC-licensed firms

We speak the SFC's language — and turn it into an IT plan.

The SFC now holds licensed corporations to clear cybersecurity expectations, and investors probe the same areas in operational due diligence. Our Compliance+ service maps to each one — so your technology stands up to scrutiny, and you have the evidence to prove it.

The obligation

Why this is now non-negotiable.

The SFC's thematic cybersecurity review found half of reviewed firms running end-of-life systems and widespread gaps in cloud security. Circular 25EC7, in effect since February 2025, advises licensed corporations to run a comprehensive technical review — including penetration testing — at least annually; a further June 2026 circular addresses AI-enabled threats. Between them they expect controls across patching, access, monitoring, third-party risk and incident response. For a small firm with no IT department, meeting this alone is not realistic. That's the gap we fill.

The mapping

Each SFC expectation, and how Komstadt covers it.

A plain-English view of what the regulator looks for and what our managed service delivers against it.

SFC expectation areaWhat it meansHow Komstadt covers it
Asset managementKnow every device and system you runLive, automated asset inventory via our management agents
End-of-life softwareNo unsupported operating systems in useLifecycle tracking + planned upgrades before support ends
Patch managementTimely, verified security updatesManaged patching to a 30-day SLA with monthly evidence
Access controls / 2FAMFA enforced, least-privilege accessMFA across email, remote access and all admins; access reviews
Remote accessSecure VPN with controlsCompany VPN, session timeouts and IP allow-listing
Email & phishingAnti-spoofing and staff awarenessSPF/DKIM/enforcing DMARC + phishing simulations and training
Cloud securityHardened Microsoft 365 configurationConditional access, least-privilege admin, DLP, regular review
Data protection & backupEncrypted, tested backups; recoverableManaged backup (incl. M365) with tested restores and a DR plan
Third-party / vendor riskDue diligence and SLAs on IT providersVendor due-diligence pack and cybersecurity SLAs you can show the SFC
Incident responseA plan, and the ability to reportDocumented incident-response runbook, contacts and annual drill
Governance & oversightPolicies and senior-management visibilityCore IT policies, documentation and quarterly compliance reviews

Mapping reflects the areas addressed in the SFC's cybersecurity guidance for licensed corporations. It is general guidance, not legal or regulatory advice; your compliance team remains responsible for your obligations.

Fundraising & ODD

Investor-ready, not just inspection-ready.

When an allocator runs operational due diligence, IT and cybersecurity are on the questionnaire. Firms that can answer with evidence — an asset inventory, a tested backup, a vendor due-diligence pack, an incident-response plan — clear ODD faster and look more institutional. We give you that evidence, and keep it current, so the next questionnaire is an attachment, not a scramble.

What we hand you

  • A written IT & cyber readiness report
  • SFC control mapping for your environment
  • A vendor due-diligence pack
  • An incident-response plan and drill record
  • Evidence of MFA, backup and patching
2-minute self-check

10 questions every Hong Kong business should be able to answer.

The same ones the SFC asks licensed firms. Answer honestly — most firms your size score 4–6.

We'll verify your answers — free.

Our complimentary review checks all ten areas in one visit and gives you a written findings report you can show your board, your investors or the SFC. No obligation, no sales deck.

Book your free assessment