Skip to main content
PTS Managed Services

PTS Managed Services · Free quick audit

Where does your firm stand on the 24 security controls?

Built on the SFC's rules for the IT environment of Hong Kong's licensed firms: the 24 security controls a licensed hedge fund must have in place. Any company can use them as the benchmark. If you want to improve your security and IT management, licensed or not, this is the standard to measure against.

33 plain questions, about ten minutes, no IT knowledge needed; Not sure is always an answer. You get each control marked in place or not, where to start, and a report to keep.

The 24 controls, five groups
  • Test and find weaknesses. Find the gaps before an attacker does.
  • Control who gets in. The right people, the right access, nothing more.
  • Protect the data. Keep sensitive information safe, recoverable and under your control.
  • Detect and respond. Spot trouble early and handle it calmly.
  • Govern and oversee. Make security someone's job, including your suppliers'.
Your answers stay in this browser until you clear them.

What this is

The SFC's rules, as a benchmark for any company

The 24 security controls the SFC expects in the IT environment of Hong Kong's licensed firms, asked as 33 plain questions and judged against the SFC's own text, with PTS's stricter standard marked where it applies. Licensed or not, they are the standard to measure your security and IT management against. About ten minutes; Not sure is always an answer.

What you get

A clear picture, and a report to keep

Each control marked in place, a gap or needing an answer; where to start, in the order that reduces risk fastest; and a report you can print to PDF. Nothing leaves your browser unless you send it.

Why do it

The threats do not check your licence

A proven, proportionate benchmark; easier investor and bank due diligence; better cyber-insurance terms; and, if the firm is licensed, the start of the full SFC assessment with nothing asked twice.

A

Your SFC licences

They decide which of the SFC's requirements apply to you. Not licensed? Say so: the 24 controls are still the benchmark, because the firms you deal with have to meet them.

Not answered

Which SFC licences does the firm hold?

Most hedge fund managers hold Type 9, often with Type 4 or Type 1. The licences decide which codes apply.

B

Your IT support

Who answers the technical questions, and who would put a gap right.

Not answered

Who provides the firm's IT support?

The IT provider has administrator access to everything; the SFC expects a contract and oversight.

01

Penetration testing

Pay a friendly attacker to find the way in before a real one does.

Not answered

Has an independent firm tested the firm's defences (a penetration test) in the last 12 months?

Scanners find known flaws; a tester finds the chain of small weaknesses that leads to a real breach. The SFC strongly advises licensed firms to have one at least once a year.

02

Phishing simulation and training

Most attacks start with an email. Train people to spot them.

Not answered

Do staff get regular security awareness training that covers phishing?

Most attacks start with an email, and AI now makes fake ones far more convincing. The SFC expects regular awareness training for all staff, yearly for internet brokers; test phishing emails are how the best firms make it stick.

03

Internal vulnerability scanning

A regular health check of every device inside your network.

Not answered

How often are the firm's laptops, servers and network devices scanned for vulnerabilities?

Once an attacker is inside, unpatched machines let them spread. The SFC strongly advises a technical review with vulnerability scanning at least once a year; monthly is PTS's standard.

04

External vulnerability scanning

See your organisation the way the internet sees it.

Not answered

How often is everything the firm exposes to the internet (website, email, remote access, the firewall) scanned for weaknesses?

Internet-facing systems are probed constantly; a forgotten test server or an old VPN is often the way in. The SFC expects unnecessary ports closed and access lists reviewed; monthly scanning is PTS's standard.

05

Patch management

Fix known holes quickly, and have a plan for urgent ones.

Not answered

Are security patches tested promptly and installed on every device within a month, with urgent ones sooner?

Most breaches use a flaw that already had a fix. The SFC expects patches implemented within one month of completing testing, and urgent ones as soon as possible.

06

Removing end-of-life software

If the vendor no longer fixes it, it should not be on your network.

Not answered

Is any operating system or software out of its maker's support?

Software out of support cannot be patched. The SFC bars it on critical servers and databases and expects the rest replaced, or its risk mitigated.

07

Multi-factor authentication

A password alone is no longer enough.

Not answered

Is a second factor required for remote access and for administrator and cloud accounts?

That is the SFC's rule: multi-factor authentication for remote access, and phishing-resistant MFA on administrator, cloud and privileged accounts.

Must every member of staff use a second factor (not just a password) to sign in?

The SFC requires it for remote access and client logins, and phishing-resistant MFA on administrator and cloud accounts; a second factor on every account is PTS's standard.

08

Least privilege and admin control

People get the access they need, and nothing more.

Not answered

Are administrator rights limited to a few named people, with their use logged and monitored?

The SFC's rule: access on a need-to-have basis, administrator accounts granted to a limited number of users, and their use logged and monitored.

Do administrators use separate accounts for admin work, never their everyday account?

Everyday accounts with admin rights are how ransomware gets in. The SFC limits and monitors administrator accounts; separate accounts for admin work are PTS's standard.

09

Maker-checker approvals

Two people for anything that could really hurt.

Not answered

Are payment instructions confirmed by a call-back or a second person before anyone acts on them?

Payment instructions are the target of impersonation fraud.

10

Secure remote access

Working from anywhere should not mean open to anyone.

Not answered

Is remote access to the firm's systems only through a VPN or a zero-trust service, with a second factor?

The SFC's rule for reaching the internal network from outside: a VPN or its equivalent, with multi-factor authentication. A firm on cloud services alone, with no office network to reach, can answer Yes.

Can firm data be opened only on devices the firm manages?

Firm data on personal devices is outside the firm's control.

11

Network segmentation

Build internal walls so one breach does not become total.

Not answered

Are the staff, server and guest networks kept apart?

Separation stops one infected laptop reaching everything.

12

Encryption in transit and at rest

If data is stolen, make it unreadable.

Not answered

Is every laptop's disk encrypted?

A lost laptop with unencrypted client files is a reportable incident.

13

Endpoint protection

Every laptop and phone is a front door. Lock each one.

Not answered

Which anti-malware or endpoint protection runs on every laptop and server?

The SFC expects anti-malware on every server and workstation; detection and response with someone watching the alerts is PTS's standard.

14

Email and web security

Stop threats before they reach anyone's inbox.

Not answered

Is incoming email scanned for phishing, with outside senders tagged?

Phishing is the most common way into a fund manager.

15

Backup and recovery

Assume the worst will happen. Be able to get it all back.

Not answered

Could someone who took over an administrator's account delete the backups?

Answer No only if the backup is offline or in a separate account that the firm's own administrators cannot reach.

16

Record keeping and retention

Keep what you must, find it when asked, delete it when due.

Not answered

Are the firm's email and files kept for at least seven years before they can be deleted?

SFC firms must keep most records for seven years; a retention policy in Microsoft 365 or the file store is how it is done.

17

Cloud and storage due diligence

Your data in someone else's data centre is still your responsibility.

Not answered

Has the firm checked each cloud provider that holds its data: its security certifications, where it keeps the data, and how the firm would get it back?

Your data in someone else's data centre is still your responsibility: keep access, control and an exit plan.

18

Audit logging and review

Record who did what, and actually look at it.

Not answered

How many days are the audit and sign-in logs kept?

The SFC says keep and review the logs of critical systems, and sets no period; PTS's standard is at least a year.

days

Does someone review the security logs regularly?

The SFC expects audit logs to be reviewed, not just kept.

19

Security monitoring

Someone watching for trouble, day and night.

Not answered

Are security alerts monitored and followed up, at least during working hours?

The SFC expects detection and monitoring in step with the threat, with anomalies followed up; round-the-clock watching is PTS's standard.

Are security alerts watched 24 hours a day, 7 days a week?

An alert at 2am that nobody sees until Monday is not detection. The SFC expects detection and monitoring in step with the threat; round-the-clock watching is PTS's standard.

20

Incident response and exercises

Know who does what before the crisis, not during it.

Not answered

Does the firm have an incident response plan?

The plan covers handling an incident and reporting it to the SFC.

Has the incident response plan been exercised (a tabletop exercise) in the last 12 months?

The SFC expects incident plans to be tested.

21

Business continuity and recovery

Keep working when systems, offices or people are unavailable.

Not answered

Does the firm have a business continuity plan?

The SFC expects a plan covering loss of the office, systems, people and providers.

22

Accountable ownership

One named senior person answers for technology risk.

Not answered

Is one named senior person accountable for technology risk?

Without a named owner security becomes nobody's job and budgets are set blind. SFC firms must name a Manager-in-Charge for Information Technology.

Does that person get a report on technology risk at least every quarter?

PTS's practice: a quarterly report on risks, tests and incidents, so the owner can act on them.

23

Supplier risk management

You can outsource the work, not the responsibility.

Not answered

Does the firm keep a register of the suppliers that hold its data or can reach its systems, checked before they start and reviewed every year?

Many breaches arrive through a supplier, and the firm stays responsible for anything it outsources.

24

Governance of AI tools

Use AI with your eyes open.

Not answered

Does the firm have a policy on using generative AI?

The AI circular expects a policy on what AI may be used for and with what data.

Your results

Where the firm stands on the 24 controls

0of 24
In place0on your answers
Gaps0to put in place
Needs an answer24unanswered or not sure

Nothing answered yet. Start with the two questions about the firm.

Each control is judged against the SFC's own text. Answer the licences question to see how the 24 controls relate to the SFC's requirements for your firm. PTS has checked nothing here: every result rests on what you said.

Talk to PTS about the gaps

The 24 controls

1

Test and find weaknesses

Find the gaps before an attacker does.

0/6
  • 01Penetration testingNeeds an answer
  • 02Phishing simulation and trainingNeeds an answer
  • 03Internal vulnerability scanningNeeds an answer
  • 04External vulnerability scanningNeeds an answer
  • 05Patch managementNeeds an answer
  • 06Removing end-of-life softwareNeeds an answer
2

Control who gets in

The right people, the right access, nothing more.

0/5
  • 07Multi-factor authenticationNeeds an answer
  • 08Least privilege and admin controlNeeds an answer
  • 09Maker-checker approvalsNeeds an answer
  • 10Secure remote accessNeeds an answer
  • 11Network segmentationNeeds an answer
3

Protect the data

Keep sensitive information safe, recoverable and under your control.

0/6
  • 12Encryption in transit and at restNeeds an answer
  • 13Endpoint protectionNeeds an answer
  • 14Email and web securityNeeds an answer
  • 15Backup and recoveryNeeds an answer
  • 16Record keeping and retentionNeeds an answer
  • 17Cloud and storage due diligenceNeeds an answer
4

Detect and respond

Spot trouble early and handle it calmly.

0/4
  • 18Audit logging and reviewNeeds an answer
  • 19Security monitoringNeeds an answer
  • 20Incident response and exercisesNeeds an answer
  • 21Business continuity and recoveryNeeds an answer
5

Govern and oversee

Make security someone's job, including your suppliers'.

0/3
  • 22Accountable ownershipNeeds an answer
  • 23Supplier risk managementNeeds an answer
  • 24Governance of AI toolsNeeds an answer

Where to start

You do not need all 24 on day one. This order gives the biggest risk reduction first.

1First 90 days

  • Patch management Needs an answer

    Automated patching on a monthly cycle, an emergency route for urgent fixes, and a report showing what is and is not patched.

  • Removing end-of-life software Needs an answer

    An inventory that records support end dates, replacements planned a year ahead, and anything that cannot be removed isolated.

  • Multi-factor authentication Needs an answer

    A second factor on every account: email, cloud apps, VPN and administrators, with phishing-resistant methods rather than text-message codes.

  • Encryption in transit and at rest Needs an answer

    Every laptop's disk encrypted, modern TLS for web and email traffic, and encrypted backups and cloud storage.

  • Endpoint protection Needs an answer

    Endpoint detection and response on every laptop and server, centrally managed with enforced settings, and local administrator rights restricted.

  • Email and web security Needs an answer

    Advanced email filtering; SPF, DKIM and DMARC set to enforce; outside senders tagged; and web filtering that blocks known bad sites.

  • Backup and recovery Needs an answer

    Daily backups, Microsoft 365 included; an immutable or offline copy an attacker cannot delete; and restores tested at least quarterly.

23 to 6 months

  • Phishing simulation and training Needs an answer

    Monthly or quarterly simulated phishing emails, short training for anyone who clicks, and click and report rates tracked over time.

  • Internal vulnerability scanning Needs an answer

    Laptops, servers and network devices scanned every month for missing patches and weak settings, with the results fed into patching.

  • External vulnerability scanning Needs an answer

    Everything the firm exposes to the internet scanned every month, an alert when a new service appears, and critical findings fixed within days.

  • Least privilege and admin control Needs an answer

    Access limited to what each role needs, separate administrator accounts raised only when needed, and access reviewed quarterly and removed on exit.

  • Maker-checker approvals Needs an answer

    A second person approves payments, bank detail changes and major system changes, with a call-back on a known number before payment details change.

  • Secure remote access Needs an answer

    VPN or zero-trust access, always with a second factor; only managed devices allowed in; company data kept off personal devices.

  • Network segmentation Needs an answer

    Separate networks for staff, guests, printers and meeting-room equipment, firewall rules between them, and servers and backups in a restricted zone.

  • Incident response and exercises Needs an answer

    A written plan with roles, contacts and decision points; IT, legal and insurer support agreed in advance; and an exercise every year.

  • Business continuity and recovery Needs an answer

    Recovery time targets agreed for key systems, cloud-based working so staff can operate anywhere, and recovery tested at least once a year.

36 to 12 months

  • Penetration testing Needs an answer

    An independent, accredited firm tests the firm's defences every year; findings are ranked by risk, fixed and retested.

  • Record keeping and retention Needs an answer

    Retention policies in Microsoft 365 and the file store that keep records for seven years, in known locations, with search and legal hold tested.

  • Cloud and storage due diligence Needs an answer

    Each provider's certifications checked, where the data is held on record, and contract terms for access, audit and exit.

  • Audit logging and review Needs an answer

    Sign-ins, administrator actions and data access collected centrally, kept for at least twelve months, protected from tampering, and reviewed regularly.

  • Security monitoring Needs an answer

    Managed detection and response around the clock, with alerts for unusual sign-ins, mass downloads and new administrator rights.

  • Accountable ownership Needs an answer

    A named owner, often the COO; a quarterly report on risks, tests and incidents; and an annual review of the policies and the risk register.

  • Supplier risk management Needs an answer

    A supplier register ranked by risk, security checks before a supplier starts, and contract terms on security, breach notice and audit.

  • Governance of AI tools Needs an answer

    An approved list of AI tools, such as Copilot in the firm's own tenant; clear rules on what data may go in; and a person reviewing AI output used in decisions.

Talk to PTS about the gaps

Send this to PTS and within two business days a consultant comes back to walk through the gaps with you: what closes each one, in what order, and what the full assessment would add. Your answers are attached automatically. No obligation.

No obligation · Goes to our inbox, not a database · Two business days

This quick audit is general guidance on technical good practice, prepared by PTS Managed Services to structure a security discussion. It is not legal or regulatory advice and does not certify compliance with any requirement of the Securities and Futures Commission; each result rests on what you said. PTS Managed Services Limited is ISO/IEC 27001 and ISO/IEC 20000 certified. Question set current at 25 September 2026. SFC-licensed firm? The SFC Licence Navigator sets out your regulatory obligations.

Security controls audit FAQs

Where do the 24 controls come from?

From the SFC's own guidelines and circulars for licensed corporations: the Internet Trading Guidelines, the circulars on external data storage (2019), remote working (2020) and generative AI (2024), the 2025 cybersecurity review and the 2026 circular on AI-enabled attacks. PTS grouped what they expect of every firm into 24 controls.

My firm is not SFC-licensed. Is this for me?

Yes. Family offices, wealth managers, fund administrators and private companies hold the same kind of data and move the same kind of money as a licensed hedge fund, and attackers treat them the same way. The 24 controls are a proven, proportionate benchmark; say the firm is not licensed and the audit uses them as such.

How long does it take, and what do I need?

About ten minutes and no IT knowledge. Each control is one plain question, with a second where the SFC's bar and PTS's standard differ. Not sure is always an answer; it usually means worth checking, and those are the items a PTS assessment looks at first.

What does "below PTS's standard" mean?

Each control is judged against the SFC's own text. On nine controls PTS's standard is stricter than the SFC's, for example endpoint detection and response rather than antivirus alone, or logs kept a year where the SFC sets no period. A control that meets the SFC's text but not PTS's is in place, and marked so you know what PTS would do next. It is never counted as a gap.

What happens to my answers?

They stay in your browser. You can print the result to PDF. If you send it to PTS, it goes to our inbox to prepare a conversation, and nowhere else.

What is the difference from the full assessment?

The full assessment measures the firm against every SFC requirement that applies to its licences, system by system, checks the documents behind each control and ends in a signed report. The 24 controls stand behind most of those requirements, and every answer given here carries straight into it.

Call Talk to PTS