Skip to main content

      In light of the recent guidance issued by the Securities and Futures Commission (SFC) in June 2026, we would like to share a strategic action plan tailored to help your organisation align with the evolving cybersecurity expectations and address the growing risks posed by AI-enabled threats.

      The SFC has emphasised the urgent need for licensed firms to reassess and strengthen their cybersecurity controls, particularly in the areas of patching, access management, threat detection, third-party oversight, and incident response. With the rise in sophisticated cyber incidents — including hyper-personalised phishing, deepfake attacks, and AI-driven reconnaissance — traditional security approaches are no longer sufficient. A shift toward continuous, data-centric, and AI-enhanced defences is now essential.

      KPMG is well-positioned to support your organisation throughout this journey. Our team offers a range of services, including cybersecurity gap assessments, continuous monitoring, incident response planning, and third-party risk governance, all aligned with the latest regulatory expectations and industry best practices.

      Should you wish to discuss how we can tailor our support to your specific needs, please feel free to contact us directly. We remain committed to helping you navigate this evolving landscape with confidence and clarity.


      Download PDF

      Securities and Futures Commission (SFC) Circular – Enhanced Cybersecurity Measures to address evolving risks arising from artificial intelligence-enabled cyberattacks

      Proactive Cybersecurity Measures in Response to SFC Guidance and AI-Driven Threats

      Cybersecurity

      The threats from cyber adversaries are continuing to grow in scale and sophistication.

      Submit RFP

      Find out how KPMG's expertise can help you and your company.