Purpose
Hong Kong leadership is approving GenAI tools faster than security programmes can inventory them. This briefing helps a CISO (or equivalent) deliver a 45-minute session that produces decisions — not slide theatre.
Pair with the Board Briefing Pack for heatmap language, and the AI Security wiki for depth.
Learning outcomes
By the end of the session, attendees should be able to:
- List production GenAI systems with named owners.
- Distinguish AI security risks (prompt injection, data leakage, unsafe tools) from classical malware.
- Agree which high-impact actions require human approval.
- Know when to escalate to HKCERT versus using HKISG programme materials — HKCERT and HKISG.
Session agenda (45 minutes)
| Minutes | Block | Outcome |
|---|---|---|
| 0–5 | Scope and non-goals | “Not a product bake-off” |
| 5–15 | Inventory snapshot | Named owners on a one-page list |
| 15–25 | Top three scenarios | Payment fraud / data leak / agent tool abuse |
| 25–35 | Control decisions | Dual control, logging, abuse tests |
| 35–45 | Board questions & next 30 days | Dated owners and review date |
Facilitator notes
Context to open with
- Prompt injection is not fixed by antivirus.
- Deepfake fraud often pairs with urgent payment requests.
- PDPO still applies when personal data enters models — PDPO glossary.
Hong Kong implications to stress
- Customer chatbots and internal copilots connected to email/CRM.
- MSP or vendor-hosted models with unclear retention.
- Marketing teams pasting client lists into public LLMs.
What good looks like (say this aloud)
- Inventory with owners and data classes.
- Abuse tests before customer launch (direct + indirect injection).
- Human approval for refunds, access changes, bulk exports.
- Logging retained for incident review.
- No “AI security = we bought a tool” vanity claim.
Attendee checklist (handout)
- Every production LLM / RAG / agent has a named owner.
- Tools each agent can call are listed; high-impact ones need human confirmation.
- Personal-data flows have a PDPO note or enterprise contract.
- Last abuse test date is recorded.
- Deepfake / BEC payment rule is published to finance.
- Residual risk is on the board heatmap with a next review date.
Related
- Methodology v2026.2 — how Trust Reviews score AI posture
- CISO · MSSP · LLM
- Ransomware for Hong Kong SMEs
Editorial note
HKISG education content. Membership may unlock worksheets; public pages do not alter Trust Review scores. Not legal advice.