Governance & accountability
Board-level ownership, risk appetite language, policy enforcement in practice, escalation paths to executives, and clear accountability for cyber and AI outcomes — not shelfware policies.
Versioned, inspectable rules for Trust Reviews and HKISG IT Awards — with AI security treated as a first-class domain, not a footnote.
Methodology v2026.2
HKISG scores organisational and product trust for Hong Kong buyers and boards. Membership funds capacity and queue access. No payment can alter a score, star band, TrustScore, or published finding.v2026.2 expands the rubric so classical cyber controls and AI-era risks are assessed in one coherent frame.
Two public programmes, one integrity rule: evidence over narrative.
Programme A
Organisation-level trust posture against a 100-point scorecard, mapped to TrustScore / star bands, with dated scope notes and practitioner feedback where collected.
Programme B
Time-boxed white-hat assessment of a nominated product or service — including GenAI, agentic, and AI-security products — with published stars only when the band is met.
Six weighted domains. AI security is scored alongside governance, protection, detection, supply chain, and evidence — not bolted on after the fact.
Board-level ownership, risk appetite language, policy enforcement in practice, escalation paths to executives, and clear accountability for cyber and AI outcomes — not shelfware policies.
Identity and access (MFA / phishing-resistant where feasible), asset inventory, vulnerability handling, network and cloud hardening, backup immutability, and secure configuration baselines.
Telemetry coverage, SOC or MSSP playbooks, escalation SLAs, tabletop and live exercise recency, forensics readiness, and how AI-assisted alerts are validated by humans before high-impact action.
Model and GenAI inventory, prompt/agent abuse testing, training and RAG data controls, third-party LLM diligence, human oversight for high-stakes outputs, deepfake/social-engineering resilience, and AI incident runbooks.
Third-party assurance, concentration risk, realistic RTO/RPO, continuity tests, cloud/SaaS exit plans, and whether critical AI vendors have contractual security and data-handling commitments.
Recency, completeness, reproducibility, and operational proof. Points are not awarded for aspirational roadmaps or undated screenshots. AI claims require versioned model/system records where in scope.
Domain weights always total 100. If AI is formally out of scope after inventory verification, the 18 AI points are redistributed proportionally across the remaining domains for that review only — and the public page states the redistribution.
Trust Reviews may also publish a separate public website hygiene grade (passive TLS / security-header observation of the organisation’s public site). That grade is a buyer lens — not a penetration-test certification and not a substitute for the six-domain scorecard.
Inside the AI Security & Model Governance domain, assessors apply these lenses. They also inform IT Awards testing when a nominated product embeds or sells AI.
Named owners for every production model, GenAI app, agent, and embedded AI feature — including shadow IT discoveries during the review window.
Prompt injection, jailbreak, tool-calling abuse, retrieval poisoning, and adversarial evasion against any AI security controls claimed in marketing.
Training/fine-tune/RAG data provenance, access controls, retention, redaction, and whether customer data can leak into shared model contexts.
Where agents or automated decisions can change access, money, or customer outcomes — and the human approval gates that must fire first.
Provider diligence, residency options, subprocessors, rate-limit and key hygiene, and fallback when a frontier model provider degrades or is blocked.
How the organisation uses AI in SOC/IR without over-trusting it — and how it defends against AI-accelerated phishing, credential stuffing, and recon.
Every Trust Review also samples these operating aspects. Findings map into the six domains rather than creating parallel scores.
Least privilege, step-up authentication, session hygiene, and segmentation assumptions that survive remote and hybrid work.
Lawful use, retention, cross-border transfer awareness, breach notification readiness, and privacy impact thinking for AI features that process personal data.
Shared-responsibility clarity, admin plane hardening, logging export, and misconfiguration debt that attackers actually exploit.
Threat modelling, dependency hygiene, secrets handling, release gates, and how GenAI coding assistants are constrained in production pipelines.
Vendor onboarding evidence, update integrity, MSP/MSSP access paths, and AI API providers treated as in-scope suppliers.
Verification rituals for payment and access changes, executive impersonation drills, and staff awareness tuned to AI-generated voice/video fraud in Hong Kong.
Rubric points map to public star bands. Trust Reviews may also publish a TrustScore (0.0–5.0) with a qualitative label (for example Excellent). We do not award participation trophies.
Nominated platforms face a time-boxed assessment against a written scope. The panel validates attack-path resistance, not marketing claims. For AI-bearing products, testing explicitly includes abuse cases that classical appsec checklists miss.
An award means high resistance during the test window for the stated scope. It does not certify the permanent absence of vulnerabilities or model failures.
Rubric language is written for operators who face local and cross-border pressure: bilingual customer channels, dense SaaS estates, financial and logistics concentration, and rapid GenAI adoption. Assessors expect evidence that fits this market — for example deepfake-enabled payment fraud drills, regional data handling notes, and HKCERT-aligned patch urgency — not generic global checklist theatre.