2025-04-16

Added · Updated

Cyber Incidents Watch: Guidance on Strengthening Protection Measures against Distributed Denial-of-Service Attacks

The Hong Kong Monetary Authority issues this guidance to require Authorized Institutions to enhance their defense posture against increasingly sophisticated Distributed Denial-of-Service attacks. The regulator mandates that institutions critically review their multi-layered defense strategies, ensure appropriate incident response configurations, and actively collaborate with group offices to manage network effects. Additionally, Authorized Institutions are encouraged to leverage the Cyber Intelligence Sharing Platform to exchange threat intelligence and strengthen the collective resilience of the banking sector.

Hong Kong Monetary Authority logo

Hong Kong

Hong Kong Monetary Authority

Click to view thumbnail

55th Floor, Two International Finance Centre, 香 港 中 環 金 融 街 8 號 國 際 金 融 中 心 2 期 55 樓 8 Finance Street, Central, Hong Kong 網 址:www.hkma.gov.hk Website: www.hkma.gov.hk Our Ref.: B1/15C 16 April 2025 The Chief Executive All Authorized Institutions Dear Sir/Madam, Cyber Incidents Watch: Guidance on Strengthening Protection Measures against Distributed Denial-of-Service Attacks I am writing to provide further guidance on how Authorized Institutions (AIs) can enhance their defence posture against the growing threat of Distributed Denial-of-Service (DDoS) attacks. Globally, DDoS attacks have continued to grow and develop in sophistication over the years. While the number of DDoS-related cases reported by AIs in Hong Kong have remained manageable, there have been isolated instances where a DDoS incident has resulted in service impacts and disruptions for customers. With this, the Hong Kong Monetary Authority (HKMA) sees merits to share the key learnings from these incidents more widely for the industry’s attention. As stated in the HKMA’s Supervisory Policy Manual (SPM) module “TM-C-1 Supervisory Approach on Cyber Risk Management”, all AIs are expected to design and implement effective systems and safeguards to manage cyber risks, as well as be prepared to effectively respond to and recover from severe but plausible cyber incidents, including DDoS incidents1 . /…Page 2 1 The HKMA has also provided specific guidance on how AIs can protect themselves from DDoS attacks in its circular, "Guidance on anti-DDoS protection", issued on 25 November 2022.

  • 2 - Key observations and lessons learnt in recent global and isolated local incidents • Stay alert to network effects: While some recent DDoS attacks appeared to target specific regions or jurisdictions outside of Hong Kong, it was observed that AIs could still be impacted if they shared or relied on their group offices’ infrastructure and systems (e.g. e-banking systems) to support their Hong Kong operations. AIs should therefore stay alert to these potential network effects, and take them into account when formulating response procedures against DDoS incidents. It is good practice for AIs to sufficiently consider the need to engage and collaborate with group offices, and review whether local management are adequately involved in overseeing incident response processes when triggered. In particular, local management are expected to actively participate in impact assessment, incident investigation and resolution, the development of customer communications and business contingency planning, especially where an AI’s group office may take more extreme measures to contain the DDoS incidents (e.g. suspending online banking services). • Enhance readiness to combat evolving DDoS attack techniques: Various DDoS attack techniques (including volumetric attacks, protocol attacks, and application layer attacks) have been deployed by threat actors globally, including in combination, to increase the sophistication and potential impacts of the attacks. To ensure readiness to handle such evolving threats, AIs should: (i) critically review the robustness of their measures and controls for handling sophisticated DDoS attack techniques; and (ii) seek to adopt multi-layered defence strategies that offer appropriate coverage and necessary protective capabilities. • Ensure incident response measures remain appropriate: Besides the adequacy of its defence strategies, how an AI responds to, or handles a DDoS incident can also impact the outcome. For instance, inappropriate customer communications (e.g. instructing customers to retry logging in during DDoS incidents) and misconfiguring anti-DDoS measures (e.g. time lag in activating traffic scrubbing and incorrectly dropping legitimate banking service requests instead of filtering out malicious traffic) could inadvertently amplify the impacts of a DDoS incident. It is therefore crucial that AIs continually calibrate their incident handling processes, including to ensure the appropriateness of configurations (e.g. thresholds for the anti-DDoS measures) and the effectiveness of defence mechanisms by conducting periodic testing that includes technical simulations of possible types of DDoS attacks. /…Page 3

  • 3 - AIs should critically review the relevance of the learnings to their institution and take action, as appropriate, to further enhance their risk management capabilities. The HKMA will continue to monitor cyber incident trends and regularly provide further guidance to AIs as needed to support the industry in managing cyber risks. In tandem with the enhancements made to the Cyber Intelligence Sharing Platform (CISP) in December 20242 , AIs are also highly encouraged to help strengthen the collective cyber resilience of the banking sector in Hong Kong by actively monitoring the risk landscape, and exchanging the latest threat intelligence through the platform. Should your institution have any questions on the above, please contact us at ebanking@hkma.iclnet.hk. Yours faithfully, Carmen Chu Executive Director (Banking Supervision) 2 The enhancements made to the CISP include (1) establishing further guidelines for threat intelligence sharing; (2) adopting a forum for verbal intelligence sharing that complements the online platform; and (3) linking up intelligence sharing platforms between the banking, insurance and capital market sectors.

More like this from HKMA

HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share