Qualysec
Blog

SFC Penetration Testing Requirements in Hong Kong: When Is It Required?

Ensure compliance with SFC regulations in Hong Kong. Discover when cyber security penetration testing is required for your licensed firm and key mandates.

Published on September 23, 2026
Read Time: 10 min
CONNECT WITH US

Hong Kong financial firms operate under strict regulatory and cybersecurity requirements. For firms supervised by the Securities and Futures Commission (SFC), cybersecurity is not limited to protecting networks and data. Firms must also identify, manage and address technology risks that could affect clients, trading systems and business operations.

This raises an important question:

Does the SFC require penetration testing?    

The answer depends on the firm’s regulated activity.

The SFC does not impose one universal rule that requires every licensed firm in Hong Kong to conduct an annual penetration test. However, the SFC expressly includes penetration testing in the cybersecurity assessment framework for Virtual Asset Trading Platforms (VATPs). For internet brokers, the SFC expects regular cybersecurity reviews and strongly advises particularly large internet brokers to conduct technical reviews at least annually, including network and application penetration testing.

What Is the SFC? 

The Securities and Futures Commission, or SFC, is the independent statutory regulator of Hong Kong’s securities and futures markets. Its regulatory role covers areas such as securities dealing, futures activities, asset management and other regulated financial activities. Firms and individuals carrying out regulated activities in Hong Kong may need an SFC licence or registration, depending on the activity.

The SFC also supervises cybersecurity risks within regulated firms. Its cybersecurity framework focuses on protecting trading systems, client accounts, information and other technology resources from unauthorized access, attacks and disruptions.

Why Does Penetration Testing Matter to SFC Regulated Firms?

Financial firms rely on web applications, mobile apps, APIs, trading platforms, databases, cloud services and connected infrastructure.

Any of these systems can have a flaw that compromises client data, disrupts trading or allows an attacker to gain access to a critical system. A penetration test is used to help a company determine if there is a true vulnerability that an attacker could exploit. A Pen Test goes further than a simple vulnerability scan by trying to validate if the weaknesses identified can be exploited.

An SFC-regulated firm can thus use testing to complement a broader cybersecurity programme by helping the firm to:

  • Find exploitable weaknesses
  • Validate security controls
  • Find issues in systems that are network-facing
  • Prioritise remediation
  • Produce evidence of security testing (where appropriate)

The SFC has persisted with increasing its emphasis on cybersecurity. It issued a reminder to licensed corporations and SFC-licensed virtual asset service providers in June 2026 to review and upgrade their cybersecurity protocols, including in the context of new types of cyberattacks, such as those executed using AI.

A Real World Example

The SFC reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million on 28 July 2026 for its failure to have adequate and effective cybersecurity controls.

The SFC noted several issues such as: inadequate network monitoring, outdated systems, insufficient backups, inadequate remote access controls, weak access controls, and other cybersecurity weaknesses. During this period, some of the systems were “disrupted by ransomware and prevented clients from trading via its mobile application and internet platform.”

Need a Pen Test?

Talk directly with senior security experts. Book a quick call or grab a quote today.

Get a Quote

Pentest Quote

When Does the SFC Require Penetration Testing?

The answer changes according to the type of business.

1. Virtual Asset Trading Platforms

NOTE: VATPs face the clearest penetration testing requirement.

As per the SFC Guidelines for Virtual Asset Trading Platform Operators, a platform operator should carry out a rigorous independent cybersecurity assessment before it launches its platform and/or makes changes to it, and from time to time thereafter.

The assessment should include:

  • User application security
  • Wallet security
  • Physical security
  • Network and system security

Penetration testing, source code review and vulnerability scanning of the custody system are part of the network and system assessment.

Furthermore, the SFC launched an enhanced VATP licensing procedure. In a number of the cases that the SFC deemed to be applicants, the SFC imposed a licensing condition that the applicant conduct a penetration test and vulnerability assessment and remediate to satisfactory results before the applicant is allowed to operate on a limited basis of business.

An independent third party will do this testing for the SFC. The testing applies to network devices, firewalls, servers, databases and wallets and user applications (both desktop, web-based and mobile). Must have application layer and network layer testing.

In the case of VATPs, penetration testing is thus an integral component of the SFC’s cybersecurity and licensing regime.

2. Internet Brokers

Note: Internet brokers fall under a separate SFC cybersecurity framework.

According to the SFC, internet brokers are licensed corporations that engage in internet trading under:

  • Type 1: Dealing in securities
  • Type 2: Dealing in futures contracts
  • Type 3: Leveraged foreign exchange trading
  • Type 9: Asset management, where the firm distributes funds through its internet-based trading facilities

The SFC mandates internet brokers to periodically review their compliance with the SFC’s cybersecurity requirements. The SFC commented that it recommends that licensed corporations, especially large internet brokers, carry out a thorough cybersecurity technical review at least once a year for their 2025 cybersecurity review.

During that review, the SFC noted the following areas:

The SFC strongly advises this practice. It does not state that every internet broker must conduct an annual penetration test as a universal rule.

3. Type 9 Virtual Asset Fund Managers

Note: Type 9 firms that manage portfolios involving virtual assets face additional cybersecurity requirements.

The SFC expects virtual asset funds to have appropriate and adequate security measures in place for virtual asset fund managers that are applicable. These controls need to ensure information security and act to prevent and detect unauthorised access, security breaches and security attacks.

However, the applicable SFC terms do not expressly prescribe penetration testing as a standalone requirement.

This implies that Type 9 virtual asset fund managers need to be treated with the same level of care. They should not be deemed to automatically fall under an SFC-mandated penetration test without verifying the conditions and regulatory requirements of the licence which would apply to the firm.

4. Type 4 and Other SFC Licensed Firms

No annual penetration testing obligation will apply to a firm due to its SFC licence.

The specific cyber security responsibilities are dependent on the regulated activities carried out by the firm, its systems and the SFC requirements applicable to regulated activities.

The SFC internet trading cybersecurity framework, for instance, covers cyber security for firms that engage in internet trading. However, the same penetration testing terminology doesn’t necessarily mean the same for every Type 4 firm that advises on securities.

Note: Firms should therefore assess the requirements attached to their actual activities instead of applying one testing rule to every SFC licence type.

Who Should Consider Penetration Testing?

Penetration testing becomes especially relevant for firms that operate systems exposed to the internet or handle sensitive financial information.

This includes companies that operate:

  • Online trading platforms
  • Mobile trading applications
  • Web application
  • The Application Programming Interfaces (APIs) that are linked to trading systems.
  • Client portals
  • Wallet infrastructure
  • Internet-facing servers
  • Cloud Environments with regulated Services

With the SFC cybersecurity framework, the VATP already brings penetration testing right into the assessment process. In addition to SFC cybersecurity requirements, internet brokers’ technology environment and risk profile should dictate the scope and frequency of testing.

SFC Penetration Testing Requirements Decision Flowchart

What Can an SFC-Focused Penetration Test Cover?

The test scope should accurately represent the systems adopted by the firm.

For a trading environment, a test might involve:

  • Application security: Web Applications, mobile Applications, authentication, session management, access controls and business logic.
  • API security: Data access and input validation, endpoint exposure, authentication, authorisation.
  • Network securityInternet-facing infrastructure, firewalls, servers, segmentation and exposed services.
  • Cloud security: Access to cloud resources, access controls, configurations and interfaces between cloud services and regulated systems that are accessible externally.
  • Virtual asset security: If relevant, VATP environments should be tested for wallets and systems linked to custody infrastructure as per relevant SFC requirements.

The test should yield unambiguous results, risk levels, technical information, and remediation plans. Then a follow-up assessment can confirm if any critical weaknesses have been resolved.

Penetration Testing is Only One Part of SFC Cybersecurity

Penetration testing is not a substitute for the other security measures a firm may have.

Other topics covered by the SFC cybersecurity framework include access control, network protection, vulnerability management, monitoring and third party technologies risk and incident response.

In the context of the changing nature of cyber threats, the SFC’s June 2026 cybersecurity circular also urged licensed entities to further build up their capabilities in areas that include vulnerability management, access controls, network segmentation, monitoring, third-party risk management and incident response.

A penetration test should therefore be part of a larger security programme and not just a standalone compliance test.

What should an SFC Regulated Firm should do?

The first step is to determine whether the firm’s actual regulated activity is one of those listed in the SFC’s database.

  1. The independent cybersecurity assessment and penetration testing requirements in the VATP framework should be considered by a VATP.
  2. Internet brokers are advised to review the SFC Cybersecurity Guidelines and conduct regular cybersecurity reviews. Particularly large internet brokers should also consider the SFC’s recommendation for comprehensive technical reviews at least annually, including network and application penetration testing.
  3. A Type 9 virtual asset fund manager is recommended to examine the particular cybersecurity and custody needs of its business and the terms of its licence.
  4. Other SFC licensed firms should evaluate technology risks and regulatory requirements for their activities.

What happens if an SFC Regulated Firm fails to meet the Cybersecurity requirements? 

Violation of an applicable cybersecurity requirement or licensing condition may result in regulatory action. The SFC may require remediation, impose licensing restrictions, suspend or revoke a licence, give a reprimand or impose a monetary fine, depending on the circumstances. A disciplinary fine of up to HK$10 million or up to three times the profit obtained or loss avoided, whichever is higher, may be imposed by the SFC.

The implications can start from the licensing phase for VATPs. Some VATP applicants need to undertake necessary rectification work and receive the results of an independent penetration test and vulnerability assessment to be able to operate under the relevant licensing conditions.

How Can Qualysec Help You?

Qualysec is a CREST-accredited VAPT leader that has completed 3,700+ assessments and found 60,000+ vulnerabilities to deliver tailored VAPT reports.

Book a VAPT Consultation

VAPT Consultation

Final Takeaway

The SFC does not mandate all licensed firms in Hong Kong to carry out an annual penetration test.

This depends upon the type of regulated activity the firm carries out.

VATPs are part of the independent cybersecurity assessment framework, and the SFC has also included penetration testing and vulnerability assessment(VAPT) as a licensing condition for some of its applicants.

The SFC has stated that internet brokers must undergo regular cybersecurity review and strongly urges large internet brokers to undertake a thorough technical review at least once a year, which should include network and application penetration testing.

For Type 9 virtual asset fund managers, the SFC requires appropriate cybersecurity controls, but the applicable terms reviewed do not expressly make penetration testing a standalone requirement.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.