Being informed that your bank is protected by security measures is not sufficient. It is also important to understand if those controls are aligned with the expectations of the HKMA and what your resilience gaps are. In Hong Kong, the HKMA Cyber Resilience Assessment Framework (C-RAF) provides a structured way to assess that position.
The framework has helped identify areas of weakness that institutions may not have been aware of. In HKMA’s review of C-RAF, over 90% of banks said the framework was useful, particularly for identifying previously unrecognized gaps.
This Guide describes how C-RAF is applied, including the Inherent Risk Assessment, Maturity Assessment and iCAST requirements. It also addresses the essential changes to C-RAF 2.0, next steps for implementation, challenges and opportunities, and how institutions can respond to gaps identified.
Key Takeaways
- C-RAF offers a risk-based approach towards enhancing cyber resilience among Hong Kong financial institutions.
- IRA evaluates inherent cyber risks from business, technology, service, and threat exposures.
- MA assesses the maturity of controls against the institution’s identified risk profile.
- iCAST evaluates resilience in practice via intelligence-driven cyber attack simulation.
- C-RAF 2.0 enhances the ability of your institutions to respond to incidents, recover from incidents, and conduct Blue Team testing.
- Remediation and continual monitoring assist institutions in addressing resilience gaps.
- Regular assessment enables AIs to adapt to new technologies and cyber threats.
What Is the HKMA Cyber Resilience Assessment Framework (C-RAF)?
The HKMA Cyber Resilience Assessment Framework (C-RAF) is a risk-based approach that helps Hong Kong’s Authorized Institutions to evaluate and enhance their cyber resilience. The HKMA adopted this framework in 2016 under its Cybersecurity Fortification Initiative (CFI), which later became C-RAF 2.0.
C-RAF focuses on:
- Risk-based assessment: Institutions conduct their cyber resilience assessment based on the risks that they are exposed to.
- Proportionate requirements: Security needs will depend on a variety of factors, including technology adoption, online services provided, and size of the operation.
- Continuous improvements: The framework enables your institution to assess vulnerabilities, level of security maturity, and enhance controls over time.
- Divergent risk profiles: A retail bank with a strong online presence would have different resilience requirements compared to a specialized wholesale bank.
- Regulatory oversight: C-RAF gives the HKMA a structured way to assess the cyber resilience of AIs without applying identical requirements to every institution.
What Are the Key Pillars of HKMA C-RAF?
The HKMA Cyber Resilience Assessment Framework (C-RAF) uses three sequential assessment stages to help Authorized Institutions (AIs) understand their cyber risk. It measures the maturity of their controls and tests their ability to withstand realistic attacks.
- Inherent Risk Assessment (IRA) – This assesses the inherent cyber risk of the institution.
- Maturity Assessment (MA) – This assesses whether the controls are effective in delivering adequate cyber resilience.
- Intelligence-led Cyber Attack Simulation Testing (iCAST) – Tests the capability of the organization to withstand an attack. It provides intelligence-led simulation testing for banks.
1. Inherent Risk Assessment (IRA)
The Inherent Risk Assessment (IRA) is the starting point of C-RAF. It assists an Authorized Institution in determining its baseline cyber risk prior to evaluating the effectiveness of its security controls.
IRA considers several factors that can increase or reduce your institution’s exposure, including:
- Technology and architecture: Core banking platforms, cloud adoption, API ecosystems, network complexity, and other technology dependencies.
- Delivery channels: Online banking, mobile applications, digital wallets, and other customer-facing services.
- Products and services: The complexity and criticality of offerings such as payments, trading, and custody.
- Organizational characteristics: Institution size, customer base, transaction volumes and values, and reliance on outsourcing or third-party providers.
- External threat landscape: Cyber threats and attack activity relevant to Hong Kong’s financial sector.
This risk-based approach means that institutions with larger technology footprints, more complex operations, higher transaction volumes, or greater third-party exposure may face different resilience expectations from smaller or less complex institutions.
2. Maturity Assessment (MA)
The Maturity Assessment (MA) evaluates how effectively an institution’s cybersecurity controls address its identified risk against relevant HKMA cybersecurity assessment criteria. It compares the institution’s current maturity level with the target maturity level determined by its inherent risk profile.
The assessment covers core cybersecurity areas:
- Identify: Asset management, governance, risk management, and third-party risk.
- Protect: Access control, data security, secure development, and protective technologies.
- Detect: Continuous monitoring, anomaly detection, and security event management.
- Respond: Incident response planning, communication, and mitigation.
- Recover: Recovery planning, improvements, and post-incident communication.
During the MA, institutions need to:
- Measure current maturity: Determine how effectively existing controls operate.
- Compare against the target: Identify where current maturity falls below the level expected for the institution’s inherent risk.
- Provide supporting evidence: Demonstrate that controls operate in practice, rather than relying only on documented policies. Evidence can include logs, detection rules, incident records, and security test results.
- Identify control gaps: Record areas where existing capabilities do not meet the required maturity level.
- Plan remediation: Prioritize gaps and assign appropriate remediation actions.
IRA and MA are conducted as self-assessments by the institution. However, the assessments need to be sufficiently robust to support HKMA supervisory review and may also require independent or external validation where applicable.
3. Intelligence-led Cyber Attack Simulation Testing (iCAST)
Intelligence-led Cyber Attack Simulation Testing (iCAST) tests whether your institution can detect, respond to, and manage a realistic cyber attack. iCAST uses threat intelligence to simulate attack scenarios relevant to the financial sector.
iCAST applies to Authorized Institutions (AIs) with Medium or High inherent cyber risk under C-RAF. You should also consider the iCAST intermediate maturity level requirements when preparing your testing scope and resilience capabilities. C-RAF 2.0 also considers your institution’s maturity and resilience requirements when setting testing expectations.
iCAST vs Traditional Penetration Testing
iCAST takes penetration testing far beyond technical vulnerability discovery. It uses threat intelligence and defined attack objectives to assess whether your organization can withstand a realistic attack and protect functions.
The key differences are:
-
Threat-intelligence-led: Uses relevant intelligence on threat actors, TTPs, and attacks targeting the financial sector.
-
Objective-driven: Tests whether attackers can achieve specific objectives or affect critical business functions.
-
Broader scope: Assesses people, processes, and technology, rather than focusing only on technical weaknesses.
-
Critical services: Can cover core banking, payment systems, online and mobile banking, and other important services.
-
Third-party exposure: Can consider relevant dependencies and connections with third-party providers.
-
Detection and response: Tests how effectively the institution detects, responds to, and manages a simulated attack.
Traditional penetration testing focuses on exploitable vulnerabilities within a defined scope, while iCAST evaluates resilience against a realistic, intelligence-led attack.
What Has Changed in C-RAF 2.0?
It was announced by HKMA that C-RAF 2.0 will become effective from 1 January 2021 through the Cybersecurity Fortification Initiative 2.0 (CFI 2.0). The update was designed to reflect changes in technology, evolving cyber threats, and international cybersecurity practices.
This HKMA C-RAF 2.0 compliance guide explains the key changes institutions should consider when assessing their cyber resilience.
1. Enhanced Controls for Modern Technology
C-RAF 2.0 added and updated controls to reflect today’s technology environments and cybersecurity practices. This includes greater consideration of:
- Cloud technology
- Virtualization security
- Cyber incident response
- Cyber incident recovery
For your organization, cyber resilience should cover not only the traditional infrastructure but also the newer technology environments.
2. Stronger Incident Response and Recovery
The new framework focuses more on what happens after a security incident. It doesn’t focus only on prevention.
You need to demonstrate your ability to:
- Detect and assess incidents
- Contain malicious activity
- Recover impacted systems and services
- Learn from incidents and refine controls
This helps in determining the ability of your institution to continue or resume critical services when preventive controls are bypassed.
3. Blue Team Requirements for iCAST
In CFI 2.0, Blue Team requirements for iCAST were introduced. Blue Team is the defensive part of the assessment that deals with the detection, reaction to, and recovery from the attack performed by your institution.
The exercise therefore assesses more than whether an attacker can penetrate a target. It also examines whether defenders can:
- Identify suspicious behavior
- Investigate the attack
- React according to the procedure
- Support recovery after the simulated attack
4. Broader Recognition of Professional Qualifications
CFI 2.0 expanded the professional qualifications recognized under the Professional Development Programme (PDP) to include equivalent qualifications from major overseas jurisdictions.
The HKMA also sets out the equivalency requirements for relevant C-RAF and iCAST roles such as:
- C-RAF Assessor
- iCAST Manager
- iCAST Threat Intelligence Specialist
- iCAST Specialist
- Infrastructure Tester
But an international degree is not automatically accepted. It has to meet the HKMA’s relevant equivalency standards for the appropriate position.
5. Greater Flexibility for Group-Level Assessments
C-RAF 2.0 provides the flexibility for Authorized Institutions to take advantage of similar assessments of cyber-resilience conducted by their banking group or headquarters.
This may benefit international banking groups:
- Minimize duplication of assessment tasks
- Reuse relevant group-level assessment results
- Maintain a consistent approach between entities
The AI retains responsibility for compliance with appropriate HKMA regulations and any risks that are unique to its operations in Hong Kong.
How Can Financial Institutions Implement C-RAF?
The practical implementation of C-RAF brings your institution closer to risk profile, control maturity, and cyber-attack testing. The following six steps offer a step-by-step approach to evaluate resilience, close the resilience gap, and sustain improvement.
-
Step 1: Define the Scope and Map Critical Assets
First, determine the systems, data, and dependencies that facilitate your critical banking applications. This includes core banking systems, customer data, cloud infrastructure, APIs, and associated third parties.
-
Step 2: Conduct the Inherent Risk Assessment (IRA)
The cyber-risk level of the AI is first identified by the IRA before assessing the current security measures. Consider the size of your business, technology, the nature of products and services, and the way you deliver them. Also check how your business is exposed to cyber threats.
-
Step 3: Assess Control Maturity
After you determine the inherent risk level, determine if your cybersecurity controls are appropriate for that level of risk. Conduct a review of governance, protection, detection, response, and recovery capabilities and record gaps.
-
Step 4: Prioritise Remediation
Develop a straightforward remediation plan that is built on risk and business impact considerations related to identified control gaps. Assign owners, set target dates, and track progress to ensure important weaknesses are addressed.
-
Step 5: Conduct iCAST and Validate Resilience
iCAST is a cyber resilience intelligence-led attack scenario that applies to AIs of medium or high inherent risk. This assessment will assess both Red Team activity and Blue Team detection, response, and recovery.
-
Step 6: Report, Monitor and Improve
The implementation of C-RAF should not stop after the initial evaluation. Record findings, track remediation. Re-evaluate your cyber-risk situation when major changes to your business, technology, or threats happen.
What Challenges Do Financial Institutions Face When Implementing C-RAF?
Implementing C-RAF can be challenging when institutions need to align legacy systems, third-party dependencies, and internal resources with evolving cyber resilience expectations. Common challenges include:
- Legacy systems: older systems might not have the monitoring and security features necessary to conduct a C-RAF assessment.
- Third-party risk: Risk assessment and oversight of vendors, cloud providers, and critical dependencies can be more complicated.
- Advanced skills: There are specialized skills needed for complex assessments like iCAST.
- Resource constraints: Limited budgets, staff, and time can make it difficult to complete assessments and remediation activities effectively.
- Regulatory alignment: Mapping existing security processes and controls to C-RAF requirements can require significant coordination across teams.
Note: Failing to address these challenges can leave your organization with unresolved cyber resilience gaps and increase regulatory risk. You should address identified gaps promptly and maintain evidence that required controls are operating effectively.
How Does Qualysec Help with HKMA C-RAF Compliance?
Qualysec is a CREST-accredited specialized penetration testing company offering cybersecurity services across various countries. Supporting financial institutions in building their cyber resilience to meet the C-RAF requirements. We conduct structured assessments, penetration testing, and practical remediation assistance. We tackle technical security controls and your organization’s ability to detect and respond to realistic cyber threats.
- Inherent Risk & Maturity Alignment Support: We assist you in measuring baseline risk factors and match them with the 7 C-RAF maturity domains to determine gaps early.
- Advanced Penetration Testing & iCAST Preparation: This testing is based on realistic threat-actor techniques and APT tactics to measure your technical defenses and Blue Team detection.
- Cloud, API and Infrastructure Auditing: We audit your cloud environments, virtualized workloads, APIs and other key infrastructure that underpins digital banking services.
- Actionable, Risk-Prioritized Roadmaps: We offer prioritized findings and actionable remediation suggestions to help your teams move forward systematically and address the weaknesses.
Conclusion
The HKMA Cyber Resilience Assessment Framework assists financial institutions in systematically assessing their cyber risk, control maturity, and resilience. By performing the IRA and MA, the AIs will be able to detect any weaknesses and apply remedial action. When needed, the iCAST confirms that the institution is capable of detecting, reacting to, and recovering from actual cyber threats. Ongoing monitoring and reassessment ensure continued resilience amid ongoing changes in technology and cyber threats.
FAQs
1. What is the HKMA Cyber Resilience Assessment Framework (C-RAF)?
The HKMA Cyber Resilience Assessment is a risk-based framework for Hong Kong financial sectors to assess cyber risk and security maturity. It also helps institutions test their ability to detect, respond to, and recover from realistic cyber attacks.
2. Who is required to undergo iCAST under C-RAF?
Financial institutions with Medium or High inherent cyber risk are required to undergo Intelligence-led Cyber Attack Simulation Testing (iCAST) under C-RAF.
3. What are the core criteria of C-RAF 2.0?
C-RAF 2.0 expands technical coverage to modern environments like cloud platforms and APIs. It introduces mandatory Blue Team evaluation during iCAST and offers greater flexibility for group-level assessments.
4. How do financial institutions address gaps found during a Maturity Assessment?
Institutions formulate risk-prioritized remediation roadmaps that assign specific internal owners. They also set strict completion timelines and use empirical evidence like logs to track continuous progress.
5. What role do external vendors play in C-RAF compliance?
External cybersecurity vendors assist financial institutions by mapping infrastructure against the seven maturity domains. Helps by conducting advanced penetration testing and iCAST preparation, and delivering risk-prioritized remediation roadmaps.








