2024-09-27

Added · Updated

Risk Associated with Third-party IT Solutions

The Hong Kong Monetary Authority issued this letter to remind Authorized Institutions of the critical need to manage third-party IT dependencies following a major global cybersecurity incident. The regulator highlights that the outage resulted from inadequate testing, uncontrolled automatic updates, and poor risk management practices. Senior management is expected to review and enhance controls by adopting good industry practices outlined in the annex to ensure operational resilience.

Hong Kong Monetary Authority logo

Hong Kong

Hong Kong Monetary Authority

Click to view full text

More like this from HKMA

HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.

Share