2023-12-21

Added · Updated

Managing cyber risk associated with third-party service providers

The Hong Kong Monetary Authority issues this note to guide authorized institutions in strengthening cyber resilience following a 2023 thematic examination of third-party risk management. The document mandates that institutions integrate cyber risk into governance frameworks, conduct holistic lifecycle assessments, and perform rigorous supply chain due diligence for critical operations. Furthermore, it requires expanded threat intelligence sharing, scenario-based incident response drills, and the adoption of modern security architectures and Regtech solutions to automate and enhance defense capabilities.

Hong Kong Monetary Authority logo

Hong Kong

Hong Kong Monetary Authority

Click to view full text

More like this from HKMA

HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.

Share