The Hong Kong Security Commission (HKSC) has launched a comprehensive cybersecurity awareness campaign targeted at small and medium enterprises (SMEs) across the territory.
The initiative, which begins in July 2026, will provide free cybersecurity assessments, training workshops, and practical guidelines for businesses that may not have dedicated IT security teams.
“Many SMEs in Hong Kong are facing increasing cyber threats but lack the resources to protect themselves,” said a spokesperson for the HKSC. “This campaign aims to bridge that gap by making cybersecurity knowledge accessible to all businesses.”
The programme will cover essential topics including password hygiene, phishing awareness, basic network security, and incident response procedures. Participating businesses will receive a personalised security assessment and a prioritised action plan.
HKISG will serve as a technical partner for the campaign, providing expert speakers and educational materials in both English and Chinese.
Hong Kong operator checklist
- Confirm whether the systems, vendors, or practices described apply to your estate.
- Assign an owner and a review date — do not leave findings as unread newsletter content.
- Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
- Brief leadership with a dated one-page note when residual risk remains high.
What “good” looks like
- Controls are operated, not only documented
- Privileged access uses phishing-resistant MFA where feasible
- Detection and response paths are exercised at least annually
- Third-party dependencies have an owner and an exit plan
Sources and further reading
- HKISG Security Bulletins
- Assessment Methodology
- Governance & Integrity
- Online Education
- External: HKCERT · PCPD
Editorial note
This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.
Frequently asked questions
Who should read this?
Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims.
Does this change any public HKISG rating?
No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.
How often is this content reviewed?
HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.