Cybersecurity Incident Handling for SFC Licensed Firms
The SFC expects licensed firms to maintain cybersecurity frameworks and incident-handling arrangements that address evolving threats, including AI-enabled attacks.
More key points
- Controls should assume that a user, device, privileged account, or network component may be compromised, and firms should regularly test response procedures and oversee critical third-party providers.
On this page16 sections
- Assume a control may be breached
- Make incident handling testable
- Include critical third parties
- Treat incident response as a lifecycle
- First response: contain without destroying evidence
- Assess regulatory and client impact
- Recovery and third-party dependencies
- Current SFC emphasis and practical controls
- After-action review and exam application
- Identity attacks need verification
- Test decisions in tabletop exercises
- Prove recovery works
- Map supplier dependencies
- Close the loop with governance
- Keep a defensible incident record
- Exam takeaway
A cybersecurity incident can affect client assets, trading systems, personal information, and regulatory records. In its June 2026 circular, the SFC called on licensed firms to review and enhance their cybersecurity measures in light of changing threats, including attacks using advanced AI capabilities. The message is operational: plan for compromise, contain it quickly, and test whether the response works.
Assume a control may be breached
The SFC highlights a zero-trust design principle: system controls should be based on the assumption that a user, device, privileged account, or network component may be compromised. Firms should apply access limits, identity verification, segmentation, monitoring, and rapid revocation so that one compromised credential does not provide broad access. Privileged accounts deserve particular attention because they can change controls or access sensitive systems.
Make incident handling testable
Incident procedures should state who detects, escalates, contains, investigates, communicates, and restores affected services. A written plan is not enough: licensed firms should regularly test incident-handling procedures, including realistic scenarios involving vendors, privileged access, data exposure, and interrupted operations. Findings should lead to assigned corrective actions and management oversight.
Include critical third parties
External providers can support essential operations, but dependency introduces concentration and access risks. Firms should understand which providers support critical services, how incidents will be reported, what evidence will be available, and how operations can continue or recover. Contracts, contingency plans, and tests should match the importance of the service.
Treat incident response as a lifecycle
A licensed firm should prepare for prevention, detection, containment, recovery, and learning. A cyber incident can affect client confidentiality, market integrity, business continuity, or regulated records. The response should therefore be integrated with the firm’s risk management and senior-management oversight, not left solely to an IT help desk. The firm should know who can isolate systems, preserve evidence, approve client communications, assess regulatory notification, and restore critical services.
First response: contain without destroying evidence
When an incident is suspected, activate the documented escalation route, identify affected accounts and systems, and assess whether credentials, endpoints, data, or third-party services remain compromised. Containment may include disabling access, rotating credentials, segmenting networks, or temporarily suspending a vulnerable service. Preserve relevant logs, messages, forensic images, and decision records before routine retention overwrites them. Coordinate with specialist responders and legal/compliance teams so containment does not erase evidence or breach legal obligations.
Assess regulatory and client impact
The firm should determine promptly which regulated activities, clients, records, and market functions are affected; whether unauthorized access or data exfiltration occurred; and whether trading, asset custody, or order handling is impaired. Assess notification obligations under applicable SFC requirements and other laws, including privacy obligations where personal data is involved. Do not use a fixed “all incidents are reportable” or “only confirmed breaches count” rule without checking the current requirements and facts. Record the rationale and notify the regulator promptly where required.
Recovery and third-party dependencies
Recovery is not merely restoring a server. Validate clean backups, rebuild or patch compromised components, reset privileged credentials, monitor for persistence, and test the restored process before returning it to production. Map critical outsourced and cloud providers, incident contacts, data locations, access paths, and contractual notification duties. A supplier’s assurance does not transfer the licensed firm’s responsibility for its own controls. Ensure alternate processes have capacity and reconciliations to prevent duplicate or missing orders after service returns.
Current SFC emphasis and practical controls
The SFC’s 2026 circular highlights cyber risk including AI-enabled threats, vulnerability and patch management, zero-trust assumptions for users, devices, accounts and components, access controls, third-party supplier risk, incident response and recovery, and regular tabletop or simulated exercises. Firms should test realistic scenarios such as compromised administrator credentials, ransomware in a vendor environment, or manipulated communications. Exercises should record gaps, owners, target dates, and retesting rather than end with a discussion summary alone.
After-action review and exam application
Once stable, identify root cause and control failures, review whether escalation was timely, assess client impact, remediate affected records, and verify fixes. Update the risk assessment, training, supplier oversight, access design, and business-continuity plan. Keep a chronology of facts, decisions, notifications, and recovery tests. In an exam scenario, the best answer usually combines prompt escalation, proportionate containment, evidence preservation, client and regulatory impact assessment, controlled recovery, and documented remediation—not improvised shutdown without regard to market and client harm.
Identity attacks need verification
AI-enabled phishing and voice impersonation make message appearance unreliable. Verify identity and transaction intent through trusted channels, not only caller ID or wording. Use least privilege, multifactor authentication, device monitoring, privileged-access review and independent confirmation for sensitive account changes. Train staff on impersonation attempts and make incident reporting easy.
Test decisions in tabletop exercises
A useful exercise tests who declares an incident, which services are critical, when to notify clients or the SFC, how evidence is preserved and how vendors are contacted. Include senior management, compliance, operations, IT, legal and suppliers. Record gaps, owners, deadlines and retest results. An unpracticed checklist may fail under pressure.
Prove recovery works
Backup existence is not proof of recovery capability. Test restore times, backup isolation from ransomware, and reconciliation of transactions processed during downtime. Validate data integrity before production resumes and ensure emergency access is logged. Simulations should use clean environments and test decision authority, not only technical restoration.
Map supplier dependencies
Maintain an inventory of critical vendors, services, data, access rights, subcontractors and incident contacts. Contracts should address notification, cooperation, continuity, data return and exit support. Review supplier access proportionately; outsourcing technology does not outsource the licensed firm’s responsibility to manage risk.
Close the loop with governance
Senior management should receive a concise incident report describing business impact, client harm, regulatory notifications, control failures and open remediation. The board or relevant committee should track significant actions to closure and consider whether risk appetite or supplier arrangements need revision. Repeated incidents can indicate a systemic weakness rather than isolated user error.
Keep a defensible incident record
Maintain a chronology of detection, decisions, evidence preservation, containment, notifications, recovery tests and lessons learned. Record the basis for deciding whether a report was required. This allows the firm to explain its response to the SFC and demonstrate that remediation was completed rather than merely planned.
Exam takeaway
Cybersecurity is a governance and operational-resilience issue. Expect controls that assume compromise, limit its reach, test response, and cover third parties—not just a firewall and annual training.
Common questions
What assumption does the SFC highlight for cybersecurity system controls?
Assume that a user, device, privileged account, or network component may be compromised.
How should a licensed firm know whether its incident plan works?
The SFC says firms should regularly test incident-handling procedures and address issues found in testing.