Why this page exists
Ransomware remains one of the highest-impact cyber risks for Hong Kong SMEs: limited IT headcount, shared admin accounts, and backups that exist on paper but fail under timed restore. This guide focuses on operator actions that reduce ruinous outcomes — not vendor marketing.
For national incident coordination during an active attack, contact HKCERT. HKISG materials support readiness, board language, and programme evidence — see HKCERT and HKISG and the Ransomware glossary entry.
Context: how SME ransomware usually unfolds
- Initial access via phishing, exposed RDP/VPN, or compromised supplier credentials.
- Privilege escalation and lateral movement across flat networks.
- Backup sabotage (delete or encrypt connected backup volumes).
- Encryption + data theft + ransom note; sometimes deepfake pressure on executives — see Deepfake Fraud in Hong Kong.
AI does not invent ransomware, but it accelerates phishing copy, helpdesk social engineering, and attacker triage of stolen data.
Hong Kong implications
- Many SMEs rely on MSPs; a single shared privileged identity can cascade across clients.
- Cross-border cloud and local NAS mixes create restore blind spots.
- PDPO notification duties may apply if personal data is exfiltrated — see PDPO and privacy wiki.
- Public Trust Reviews look for operated restore evidence, not slideware — Methodology v2026.2.
What good looks like
Practical guidance (next 30 days)
- Prove restore — pick one critical system; restore under a clock; record time and gaps.
- Kill shared admins — inventory local and cloud privileged accounts.
- Close obvious exposure — internet RDP, outdated VPN appliances, unused admin portals.
- Segment backups — ransomware that can reach the only backup has already won.
- Brief ownership — who decides on paying a ransom (usually: do not decide alone under pressure).
- MSP contract — demand MFA on their access to your tenant and a named incident contact.
Deeper learning: Incident Response Basics, Incident Response Planning, Zero Trust wiki.
Hong Kong operator checklist
- Offline or immutable backup exists for finance, email, and core line-of-business data.
- Last successful restore drill is dated within 90 days.
- MFA covers email, VPN, and cloud admin consoles.
- RDP is not exposed to the open internet.
- MSP privileged access is named, MFA-protected, and revocable in one ticket.
- One-page ransomware playbook names HKCERT / insurer / counsel contacts.
- Board has seen a dated residual-risk note (Board Briefing Pack).
Related
Editorial note
Educational material from HKISG. Not legal advice, not a guarantee against ransomware, and not a substitute for HKCERT during an active incident. See Policies.