Cybersecurity Firms in Hong Kong: 5 Compared for 2026
Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

We have probably seen your problem before. Our smallest client had eight employees. Our largest secures the nuclear power plant of the United Arab Emirates. Whatever shape yours is, tell us about it and we will tell you how we would fix it.
Hong Kong has a smaller pure-play cybersecurity sector than its size as a financial centre would suggest. Most serious security work here is done either by the global vendors through their regional offices or by capable local managed providers, and there are comparatively few independent local security specialists. This guide is honest about that, and compares five providers with a genuine Hong Kong presence.
Disclosure: this guide is published by Atlant Security, which appears at number 4 of 5 below. We are not a reseller or partner of any firm listed, none paid for placement, and none saw this before publication. Every company here was checked against its own live website on 14 September 2026. Strengths and weaknesses are our editorial judgement; each quoted line is taken verbatim from the firm’s own site.
What changed in this edition: This edition was rebuilt. The previous version discussed the Hong Kong threat environment at length but named no companies at all, which makes it useless for anyone trying to choose one. Two candidates were dropped during fact-checking: one firm’s domain now displays "Your domain is expired", and another returns no HTTP response. We have listed five rather than padding the count with web design and general consulting firms that appear in directory listings under a cybersecurity heading.
Start Here: the 30 Second Version
If you read nothing else on this page, read the row that describes you. The five providers are compared in detail further down, but choosing the right category of firm matters more than choosing between two firms in the same category.
| If this is you | Buy this first | Because |
|---|---|---|
| You hold an HKMA licence | A C-RAF inherent risk and maturity assessment | Under CFI 2.0 the framework sets your baseline. Your own risk appetite does not. |
| A 20 to 60 person professional firm in Central | A local managed provider with real security hygiene | Your gap is day to day operations, not strategy. Proximity is cheap in a territory this size. |
| The Hong Kong arm of a European or US parent | An independent assessment from a firm with nothing to resell | You need an answer to the group questionnaire that survives being checked. |
| You already have an MSP and are losing money to invoice fraud | A process change, not a product | Business email compromise is defeated by a verified callback, which nobody on this page can sell you. |
| You genuinely do not know which of these you are | A scoped, fixed-price audit | The cheapest thing to buy first is the ordering. Everything else gets more expensive if you guess. |
Atlant Security editorial assessment, September 2026. This is our reading of the market, not a figure taken from any published source.
Does a Hong Kong Cybersecurity Company Need to Be in Hong Kong?
For technical work, no. For regulated financial services work, yes, and considerably. Hong Kong banking supervision expects institutions to manage technology risk to a defined standard, and a provider who has been through that scrutiny with other clients understands what evidence actually satisfies an examiner.
The territory is also small enough that on-site presence costs almost nothing. An engineer can be at your office in Central within the hour, which removes the usual argument for preferring a remote specialist over a local one.
The genuine caution in Hong Kong is depth. A directory search returns many firms listing cybersecurity among a dozen services where it represents a fraction of their revenue. Ask what proportion of the business is security, and who on the team does it full time.
Work out which one you are
Which Hong Kong rulebook binds you?
Most companies here sit in at least one of these, and a good number sit in two. Establish which before you scope any security work, because it decides what evidence you will eventually be asked to produce.
Licensed with the HKMA
Cybersecurity Fortification Initiative 2.0, in force since 1 January 2021. Its assessment pillar is the C-RAF.
The framework sets your baseline, not your risk appetite.
Handling personal data in Hong Kong
The Personal Data (Privacy) Ordinance, in force since December 1996, enforced by the Privacy Commissioner.
Applies to the private and the public sector alike.
Asian arm of a foreign parent
Hong Kong law, plus whatever the group imposes. GDPR frequently arrives contractually from head office.
The most commonly missed case. Usually both apply at once.
Framework names and dates from the HKMA press release of 3 November 2020 and from the Privacy Commissioner’s summary of the Ordinance, both read on 15 September 2026. Confirm your own position with counsel; supervisory practice moves faster than published guidance.
| Your situation | What applies | Who enforces it | What it changes when you buy |
|---|---|---|---|
| HKMA Authorized Institution | Cybersecurity Fortification Initiative 2.0, whose assessment pillar is the Cyber Resilience Assessment Framework (C-RAF), with iCAST testing for institutions designated higher risk | The Hong Kong Monetary Authority, through ongoing supervision | Your provider has to produce evidence an examiner will accept, not just a good technical outcome. We cover this on our HKMA C-RAF compliance page. |
| You hold personal data in Hong Kong | The Personal Data (Privacy) Ordinance and its six Data Protection Principles, in Schedule 1 to the Ordinance. DPP4 is the data security one. | The Office of the Privacy Commissioner for Personal Data | You stay liable for your provider. See the note below on data users and data processors. |
| Your parent company is in the EU or the US | Local law, plus group standards and any GDPR obligation flowing down to you by contract | Your head office, your auditors, and your customers | The questionnaire usually asks for evidence in a vocabulary local providers do not always speak. |
| You are a small private company with no regulator | The PDPO still applies. Nothing else does. | The Privacy Commissioner, on complaint | You are buying on commercial risk, not compliance, so buy the thing that reduces loss. |
Framework names and dates taken from the HKMA press release of 3 November 2020 and from the Privacy Commissioner’s own summary of the Ordinance, both read on 15 September 2026. The right-hand column is Atlant Security’s editorial judgement, not regulatory guidance, and is not legal advice.
What Drives Security Spending in Hong Kong
Financial services dominate, and with them supervisory expectation. Hong Kong banks and licensed institutions operate under a technology risk regime administered by their regulator, with assessment frameworks covering cyber resilience that are considerably more prescriptive than general good practice. If you are a licensed institution, that framework rather than your own risk appetite sets your baseline, and we cover it on our HKMA C-RAF compliance page.
The HKMA introduced the Cybersecurity Fortification Initiative in 2016 and launched the upgraded CFI 2.0 on 3 November 2020, with effect from 1 January 2021 on a phased basis. It rests on three pillars, and only one of them is the thing most people mean when they say C-RAF.
| Pillar | What it is | What it means for you |
|---|---|---|
| C-RAF | The Cyber Resilience Assessment Framework. An inherent risk assessment, then a maturity assessment against the level that risk profile requires. | This is the part a consultancy is engaged for, and the part that generates the remediation backlog. |
| iCAST | Intelligence-led Cyber Attack Simulation Testing, required for institutions the inherent risk assessment designates as higher risk. | Red team work against your live environment. Scope it with the assessment, not after it. |
| PDP and CISP | The Professional Development Programme and the Cyber Intelligence Sharing Platform, the other two pillars of the CFI. | Talent and intelligence sharing rather than assessment. Less commonly outsourced. |
Pillar names and the 2016 and 2021 dates are from the HKMA press release announcing CFI 2.0, dated 3 November 2020 and read on 15 September 2026. The right-hand column is our own commentary.
Over 90% of banks found the C-RAF useful, especially in identifying previously unrecognised gaps.
Hong Kong Monetary Authority, press release announcing CFI 2.0, 3 November 2020
That line is worth sitting with if you are not a bank. The institutions in Hong Kong with the largest security budgets and the most mature teams still found previously unrecognised gaps when somebody assessed them against a structured framework. The odds that a fifty person firm in Sheung Wan has no unrecognised gaps are not good.
The Personal Data (Privacy) Ordinance applies far more broadly, to essentially any organisation handling personal data in Hong Kong, and is administered by the Privacy Commissioner. It is one of the older data protection regimes in Asia and has been amended over time, so check the Commissioner’s current guidance rather than a vendor summary, this one included.
The distinction that catches people out: the PDPO regulates data users, the party that controls the data. In the Commissioner’s own words, data processors are not directly regulated under the Ordinance. Instead, data users are required to, by contractual or other means, ensure that their data processors meet the applicable requirements. Read that again with a vendor contract in front of you. When you hand your systems to a Hong Kong managed provider, they become your data processor and the obligation stays with you. If the contract does not bind them to DPP4, you have outsourced the work and kept the liability.
The enforcement path is also not what most people assume. Contravening a Data Protection Principle is not itself an offence. The Commissioner investigates, may publish a report, and may issue an enforcement notice; it is ignoring that notice which becomes a criminal matter. The practical consequence is that the cost of getting this wrong usually arrives as a published investigation report with your name on it, long before it arrives as a fine.
| What happens | Is it an offence? | Maximum penalty |
|---|---|---|
| You contravene a Data Protection Principle | No. Contravention of a DPP is not in itself an offence. | None directly. It is the start of the ladder, not the end of it. |
| A data subject complains and the Commissioner investigates | Not applicable | The Commissioner may publish an investigation report naming you if it is in the public interest. |
| The Commissioner issues an enforcement notice | Not applicable | You are directed to take remedial or preventive steps. |
| You contravene the enforcement notice | Yes | HK$50,000 and 2 years, plus a daily penalty of HK$1,000. On a subsequent conviction, HK$100,000 and 2 years, plus HK$2,000 daily. |
| You fail to erase data no longer needed (section 26) | Yes | HK$10,000. |
| You breach the direct marketing provisions | Yes | HK$500,000 and 3 years. HK$1,000,000 and 5 years if the data went to a third party for gain. |
| A data subject sues you for damage caused | Separate civil route | Compensation, decided by the court. |
Penalties quoted verbatim from the Privacy Commissioner’s Ordinance at a Glance page, read 15 September 2026. This is a summary for orientation and is not legal advice.
Hong Kong’s position as a regional headquarters location creates a third and less obvious driver. Many companies here are the Asian arm of a European or American parent, which means obligations arrive from head office rather than from local law: a group-wide standard, a GDPR requirement flowing from the parent, or a customer questionnaire written in another jurisdiction. A local provider who has handled that mismatch before is worth more than one who has not.
Operationally, the most common expensive incident here is the same as across Asian trade centres: business email compromise against invoiced payments. The control is procedural, a verified callback to a known number before acting on any change to payment details, and no provider on this page can sell it to you as a product.
Cybersecurity Companies in Hong Kong: Side-by-Side Comparison
All 5 firms below have a real presence in the Hong Kong area. The table is sorted in the same order as the reviews that follow.
| Provider | Based | Team size | Hourly rate | Best for |
|---|---|---|---|---|
| Function One | Kowloon Bay, Hong Kong | 10-49 | Not published | Hong Kong businesses wanting managed IT and managed security from one provider |
| UD (UDomain) | Kowloon, Hong Kong | 50-249 | Not published | Hong Kong organisations wanting hosting, cloud and security from a local provider |
| Dual Layer IT Solutions | Quarry Bay, Hong Kong | 10-49 | $25-$49 | Hong Kong SMEs wanting managed IT and network security at a low entry point |
| Atlant Security | Remote, serving 14 countries | Small senior team | Fixed price, not hourly | Companies that need someone to decide what to do and then implement it |
| Kite Systems | Sheung Wan, Hong Kong | 2-9 | Not published | Small Hong Kong firms wanting a hands-on local IT partner with security hygiene |
Team size, hourly rate and minimum engagement are as published by each firm on the Clutch directory, checked 14 September 2026. They are the firms’ own figures, not our measurements. “Best for” is Atlant Security’s editorial assessment.
What each firm actually claims to do
The table above compares them on price and location. This one compares them on capability, which is the comparison that decides whether the engagement works. Note how much of it is blank: that is the honest state of public information in this market, and it is why the next section is a list of questions rather than a recommendation.
| Provider | Day to day IT support | Security operations | Monitoring tier (MSSP) | Offensive testing | Audit and compliance | Hosting and cloud |
|---|---|---|---|---|---|---|
| Function One | Yes | Yes | Partial | Not stated | Not stated | Not stated |
| UD (UDomain) | Not stated | Yes | Not stated | Not stated | Not stated | Yes |
| Dual Layer IT Solutions | Yes | Yes | Not stated | Not stated | Not stated | Not stated |
| Atlant Security | No | No | No | Yes | Yes | No |
| Kite Systems | Yes | Partial | Not stated | Not stated | Not stated | Not stated |
Built from each firm’s own positioning on its own website, checked 14 September 2026. Not stated means exactly that: the firm does not claim the capability publicly. It is not a finding that they cannot do it, and several of these firms will do more than their website says. It does mean you have to ask.
Read the Atlant Security row as a limitation, not a boast. Three of the six columns are a flat no. We do not run a help desk, we do not operate a monitoring platform, and we are not a hosting provider. If what you need is somebody to answer the phone when a laptop dies, buy from one of the other four. We are on this page because deciding what to fix and in what order is a separate purchase from keeping the estate running, and most bad outcomes in this market come from buying one and expecting the other.
The 5 Best Cybersecurity Companies in Hong Kong for 2026
Ordered by fit for a Hong Kong buyer. All five are genuinely present in the territory; none is a pure-play offensive security specialist, because the territory has very few.
1. Function One
Kowloon Bay, Hong Kong · Website: f1.hk

Best for: Hong Kong businesses wanting managed IT and managed security from one provider
Function One positions across managed IT and managed security services, which in a market like Hong Kong is the practical shape most mid-sized businesses need. The territory has very few pure-play local security firms, so a capable managed provider that genuinely runs a security service, rather than reselling a product and calling it managed, is a reasonable answer. Ask exactly what the MSSP tier monitors, who watches it, and during which hours.
IT Managed Services - MSP, MRSP, MSSP
How Function One describes itself on f1.hk, September 2026
Strengths
- Managed IT and managed security under one provider and one contract
- Established Kowloon presence serving the local mid-market
Watch out for
- No published pricing, so scope and cost need pinning down early
- Verify what the managed security tier actually includes in practice
Team size: 10-49 · Rate: Not published · Minimum engagement: Not published
2. UD (UDomain)
Kowloon, Hong Kong · Website: udomain.hk

Best for: Hong Kong organisations wanting hosting, cloud and security from a local provider
UD is one of the longer-established local technology providers in Hong Kong, with hosting and cloud services alongside a security offering. Where that matters is data residency and latency: if your infrastructure is already hosted locally with them, having the same provider handle its protection removes a genuine coordination problem. As with any provider whose core business is hosting, confirm how much of the security capability is theirs rather than a resold platform.
UD Cloud Service & Security
How UD (UDomain) describes itself on udomain.hk, September 2026
Strengths
- Long-established local provider with hosting, cloud and security together
- Local infrastructure, which helps with data residency questions
Watch out for
- Hosting-led rather than security-engineering led
- No published pricing or minimum engagement
Team size: 50-249 · Rate: Not published · Minimum engagement: Not published
3. Dual Layer IT Solutions
Quarry Bay, Hong Kong · Website: duallayerit.com

Best for: Hong Kong SMEs wanting managed IT and network security at a low entry point
Dual Layer names network security directly in its own positioning and publishes one of the lowest rate bands in this series, with a $1,000 minimum. For a Hong Kong SME that has never bought security services and wants to start with something bounded, that combination is genuinely accessible. Treat the low rate as a signal about the nature of the work rather than a bargain on specialist expertise, and ask who specifically is assigned.
Dual Layer IT - IT Solutions Hong Kong, network security systems
How Dual Layer IT Solutions describes itself on duallayerit.com, September 2026
Strengths
- Network security named explicitly rather than assumed
- Low published rate and a $1,000 entry point
Watch out for
- Low rate band reflects operational IT work rather than specialist security
- No offensive testing or formal compliance practice
Team size: 10-49 · Rate: $25-$49 · Minimum engagement: $1,000+
4. Atlant Security
Remote, serving 14 countries · Website: atlantsecurity.com

Best for: Companies that need someone to decide what to do and then implement it
Atlant Security is a consultancy rather than a managed services provider or a product vendor, and the distinction is the reason it is on this list at all. There is no help desk, no monitoring platform and nothing to resell. What it does is the part most local providers leave to you: an audit that produces a prioritised remediation plan with named owners and effort estimates, and the same engineers then implementing the fixes. The firm has run 200+ security assessments across 14 countries since 2013, works to fixed prices rather than hourly billing, and is vendor-independent, so the recommendation carries no resale commission. For a company that does not yet know whether it needs an MSP, a penetration test or a compliance programme, that ordering is the useful thing to buy first.
Strengths
- Fixed price, so scope and invoice are agreed before work starts
- Implements the fixes rather than stopping at a findings report
- Vendor-independent, with no product resale margin behind the advice
Watch out for
- No help desk, so day-to-day IT support still needs a local provider
- No 24/7 monitoring platform of its own; continuous detection goes to a partner
- Remote-first, so regular on-site presence is not the model
Team size: Small senior team · Rate: Fixed price, not hourly · Minimum engagement: $8,000+
5. Kite Systems
Sheung Wan, Hong Kong · Website: kitesystems.com

Best for: Small Hong Kong firms wanting a hands-on local IT partner with security hygiene
Kite Systems is a small Sheung Wan consultancy serving Hong Kong businesses with IT consulting and support, security included as part of the service rather than as a separate practice. For a twenty to fifty person firm in Central or Sheung Wan, that is frequently the right purchase: someone who knows your systems, answers quickly, and keeps the basics correct. It is not a specialist security practice and does not claim to be.
IT Consulting & Support Services in Hong Kong
How Kite Systems describes itself on kitesystems.com, September 2026
Strengths
- Genuinely small and local, so you deal with the same people each time
- Well placed for small professional firms in the central business district
Watch out for
- General IT with security hygiene, not a specialist security practice
- Neither rate nor minimum engagement is published
Team size: 2-9 · Rate: Not published · Minimum engagement: Not published
How to Choose a Cybersecurity Company in Hong Kong
Hong Kong has very few pure-play local security specialists, so the realistic choice is between managed providers with security practices, a hosting-led provider, and an independent consultancy. That makes the selection process matter more than the shortlist. Work through these five steps in order.
- Work out which of the three things you are buying
A managed provider keeps your estate running day to day. A testing firm tries to break in and reports how it went. A consultancy decides what you should do and in what order. Most bad purchases in this market are one of these bought when the problem needed another.
- Ask who fixes the problem after it is found
A scan, an audit and a penetration test all end with a document. Somebody then has to change firewall rules, rebuild permissions, roll out multi-factor authentication and argue with a vendor about a legacy application. Ask in writing whether remediation is included, excluded, or billed separately.
- Get the scope and the price in writing before anyone starts
Only one of the five providers here publishes a rate. A proposal that prices security services without listing what is monitored, tested or documented is not a proposal you can hold anyone to. Ask for a fixed or capped price and an explicit list of exclusions.
- Bind the provider to DPP4 in the contract
They will be your data processor, and under the PDPO the obligation stays with you as the data user. The contract is the only mechanism the Ordinance gives you. This clause costs nothing to add and is close to impossible to add later.
- Ask what you keep if you leave after twelve months
Documentation, configurations, log history, tenancy ownership. If the answer is that you keep nothing, you are not buying a security programme, you are renting one, and the renewal conversation will reflect that.
Good signs
- They name the engineer who will do the work, and you can check that person exists
- They tell you what is out of scope before you ask
- They are willing to quote a fixed price for a bounded piece of work
- They ask about your parent company and your customers, not just your firewall
- They can say plainly which parts of the job they would subcontract
Walk away if
- Security is one of fourteen services listed and nobody on the team does it full time
- The proposal prices security services as a single line with no itemised scope
- The recommendation happens to be the product they resell
- They will not put the remediation position in writing
- They quote a compliance outcome as guaranteed. C-RAF is supervisory, not a pass or fail certificate
Five questions worth putting in the RFP
| Ask this | Why it matters | What a good answer sounds like |
|---|---|---|
| What proportion of your revenue is security work? | A directory search in Hong Kong returns many firms listing cybersecurity among a dozen services. | A number, followed by the names of the people who do it full time. |
| Who specifically will be assigned, and what is their background? | Small teams sell with a senior and deliver with a junior. It is the single most common complaint. | A name, a history you can verify, and a willingness to put it in the contract. |
| What does your managed security tier actually monitor, and during which hours? | MSSP is a marketing term as often as it is an operating model. | Named data sources, named hours, and who reads an alert at 03:00. |
| Is remediation included, excluded, or billed separately? | This is where the budget you did not plan for appears. | One of the three words, in writing, before you sign. |
| What happens contractually if we are breached during the engagement? | It reveals how much of the risk the provider is genuinely taking on. | A clear, unembarrassed answer. The answer itself matters less than whether they have thought about it. |
Atlant Security editorial, September 2026. These are the questions we would ask, based on what goes wrong in engagements we are called in to rescue.
What Cybersecurity Costs in Hong Kong
Hong Kong pricing is less transparent than in the US or UAE markets, and most local providers do not publish rates at all. Where bands are published they run low, from $25 to $49 per hour, which reflects operational IT work rather than specialist security engineering. Minimum engagements start around $1,000.
That opacity is the main practical difficulty of buying here. Insist on a written scope and a fixed or capped price before work starts, and be specific about what is excluded. A proposal that prices "security services" without listing what is monitored, tested or documented is not a proposal you can hold anyone to.
A fixed-price independent audit generally runs $8,000 to $35,000 depending on scope. For a Hong Kong company that is the Asian arm of a foreign parent, an independent assessment is frequently the fastest way to answer a head-office questionnaire honestly.
The practical problem with buying here
Price transparency among the five providers
What each firm publishes about what it charges, before you have spoken to anyone.
| Provider | Hourly rate published | Minimum engagement published | Fixed price offered |
|---|---|---|---|
| Function One | |||
| UD (UDomain) | |||
| Dual Layer IT Solutions | |||
| Atlant Security | |||
| Kite Systems |
One of the five publishes an hourly rate. Two publish a minimum engagement. Expect to ask, and expect to get the answer in writing before anyone starts.
Rates and minimums as published by each firm on the Clutch directory, checked 14 September 2026. A cross means the figure is not published. It is not a finding that the firm refuses to quote.
| What you are buying | Price | Where this number comes from |
|---|---|---|
| Managed IT with security hygiene, per hour | US$25 to US$49 | Published by Dual Layer IT Solutions. The only hourly band published by any of the five. |
| Minimum engagement, managed provider | From US$1,000 | Published by Dual Layer IT Solutions. |
| Minimum engagement, fixed-price consultancy | From US$8,000 | Published by Atlant Security, the publisher of this guide. |
| Fixed-price independent security audit | US$8,000 to US$35,000 | Atlant Security estimate for the regional market, based on our own engagements. Not a published figure. |
| Penetration test, bounded scope | US$8,000 to US$20,000 | Atlant Security estimate. Varies more with scope than with provider. |
| Managed detection and response, per year | From US$30,000 | Atlant Security estimate. The variable is who reads the alerts, not the platform licence. |
| C-RAF assessment for an Authorized Institution | Quoted per institution | Scope depends on your inherent risk profile. Our own assessment runs about two weeks; see the C-RAF page. |
Rows marked as published are the firms’ own figures from the Clutch directory, checked 14 September 2026. Rows marked as an estimate are Atlant Security’s, are clearly labelled as such, and should be treated as a planning range rather than a quotation.
Frequently Asked Questions: Cybersecurity Companies in Hong Kong
Which cybersecurity firms are actually based in Hong Kong?
Function One in Kowloon Bay, UD in Kowloon, Dual Layer IT Solutions in Quarry Bay and Kite Systems in Sheung Wan all have genuine Hong Kong offices. All are managed IT providers with security practices rather than pure-play security specialists, which reflects the structure of the local market.
Why are there so few pure cybersecurity companies in Hong Kong?
The territory is a major financial centre but a compact market, and the large institutions that drive most security spending tend to buy from global vendors or build in-house. That leaves limited room for independent local specialists, so the local sector is dominated by managed IT providers with security practices attached.
What does the PDPO require of my company?
The Personal Data (Privacy) Ordinance sets obligations around how personal data is collected, used, secured and retained, and applies broadly to organisations operating in Hong Kong. It has been amended over time, so check the Privacy Commissioner’s current guidance or take legal advice rather than relying on a summary.
We are the Asian office of a European company. Whose rules apply?
Frequently both. Hong Kong law applies to your local operations, while your parent may impose group standards and may itself be subject to GDPR in a way that flows down to you contractually. This dual obligation is common here and is worth scoping explicitly, because assuming only local law applies is a recurring and expensive mistake.
What does a cybersecurity firm cost in Hong Kong?
Most local providers do not publish rates. Where they do, bands run from $25 to $49 per hour with minimum engagements from $1,000, reflecting operational IT work. A fixed-price independent audit generally runs $8,000 to $35,000 depending on scope.
Who is liable under the PDPO if my IT provider loses the data?
You are, in the first instance. The Privacy Commissioner states that data processors are not directly regulated under the Ordinance; instead, data users are required to ensure by contractual or other means that their data processors meet the applicable requirements. Your managed provider is your data processor. That makes the contract, not the provider’s good intentions, the mechanism the law gives you.
What actually happens if we contravene a Data Protection Principle?
Contravention of a Data Protection Principle is not in itself an offence. The Privacy Commissioner may investigate, may publish an investigation report, and may issue an enforcement notice directing you to take remedial steps. Contravening that enforcement notice is an offence, carrying a maximum fine of HK$50,000 and two years, with a daily penalty of HK$1,000, rising to HK$100,000 on a subsequent conviction. In practice the published report tends to cost more than the fine.
What is C-RAF and does it apply to us?
The Cyber Resilience Assessment Framework is the assessment pillar of the HKMA’s Cybersecurity Fortification Initiative, introduced in 2016 and upgraded to CFI 2.0 with effect from 1 January 2021. It applies to Authorized Institutions supervised by the HKMA. If you do not hold an HKMA licence it does not apply to you, though it is a reasonable structure to borrow if you want one.
Not sure which of these you actually need?
That is the question a fixed-price security audit answers. We assess what you have, tell you what to fix and in what order, and give you a plan you can hand to any provider on this page, including one of our competitors. 200+ assessments across 14 countries since 2013, fixed price agreed before we start.
See what a fixed-price audit coversRelated reading: the 15 largest computer security companies compared, our fixed-price IT security audit, and virtual CISO services.
Looking wider than this list? cybersecuritycompanies.io is a free directory of cybersecurity companies worldwide, filterable by category, location and credentials.

Alexander Sverdlov
Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.
Connect on LinkedIn