PTS Managed Services · Free quick audit
Where does your firm stand on the 24 security controls?
Built on the SFC's rules for the IT environment of Hong Kong's licensed firms: the 24 security controls a licensed hedge fund must have in place. Any company can use them as the benchmark. If you want to improve your security and IT management, licensed or not, this is the standard to measure against.
33 plain questions, about ten minutes, no IT knowledge needed; Not sure is always an answer. You get each control marked in place or not, where to start, and a report to keep.
- Test and find weaknesses. Find the gaps before an attacker does.
- Control who gets in. The right people, the right access, nothing more.
- Protect the data. Keep sensitive information safe, recoverable and under your control.
- Detect and respond. Spot trouble early and handle it calmly.
- Govern and oversee. Make security someone's job, including your suppliers'.
What this is
The SFC's rules, as a benchmark for any company
The 24 security controls the SFC expects in the IT environment of Hong Kong's licensed firms, asked as 33 plain questions and judged against the SFC's own text, with PTS's stricter standard marked where it applies. Licensed or not, they are the standard to measure your security and IT management against. About ten minutes; Not sure is always an answer.
What you get
A clear picture, and a report to keep
Each control marked in place, a gap or needing an answer; where to start, in the order that reduces risk fastest; and a report you can print to PDF. Nothing leaves your browser unless you send it.
Why do it
The threats do not check your licence
A proven, proportionate benchmark; easier investor and bank due diligence; better cyber-insurance terms; and, if the firm is licensed, the start of the full SFC assessment with nothing asked twice.
Your SFC licences
They decide which of the SFC's requirements apply to you. Not licensed? Say so: the 24 controls are still the benchmark, because the firms you deal with have to meet them.
Which SFC licences does the firm hold?
Most hedge fund managers hold Type 9, often with Type 4 or Type 1. The licences decide which codes apply.
Your IT support
Who answers the technical questions, and who would put a gap right.
Who provides the firm's IT support?
The IT provider has administrator access to everything; the SFC expects a contract and oversight.
Penetration testing
Pay a friendly attacker to find the way in before a real one does.
Has an independent firm tested the firm's defences (a penetration test) in the last 12 months?
Scanners find known flaws; a tester finds the chain of small weaknesses that leads to a real breach. The SFC strongly advises licensed firms to have one at least once a year.
Phishing simulation and training
Most attacks start with an email. Train people to spot them.
Do staff get regular security awareness training that covers phishing?
Most attacks start with an email, and AI now makes fake ones far more convincing. The SFC expects regular awareness training for all staff, yearly for internet brokers; test phishing emails are how the best firms make it stick.
Internal vulnerability scanning
A regular health check of every device inside your network.
How often are the firm's laptops, servers and network devices scanned for vulnerabilities?
Once an attacker is inside, unpatched machines let them spread. The SFC strongly advises a technical review with vulnerability scanning at least once a year; monthly is PTS's standard.
External vulnerability scanning
See your organisation the way the internet sees it.
How often is everything the firm exposes to the internet (website, email, remote access, the firewall) scanned for weaknesses?
Internet-facing systems are probed constantly; a forgotten test server or an old VPN is often the way in. The SFC expects unnecessary ports closed and access lists reviewed; monthly scanning is PTS's standard.
Patch management
Fix known holes quickly, and have a plan for urgent ones.
Are security patches tested promptly and installed on every device within a month, with urgent ones sooner?
Most breaches use a flaw that already had a fix. The SFC expects patches implemented within one month of completing testing, and urgent ones as soon as possible.
Removing end-of-life software
If the vendor no longer fixes it, it should not be on your network.
Is any operating system or software out of its maker's support?
Software out of support cannot be patched. The SFC bars it on critical servers and databases and expects the rest replaced, or its risk mitigated.
Multi-factor authentication
A password alone is no longer enough.
Is a second factor required for remote access and for administrator and cloud accounts?
That is the SFC's rule: multi-factor authentication for remote access, and phishing-resistant MFA on administrator, cloud and privileged accounts.
Must every member of staff use a second factor (not just a password) to sign in?
The SFC requires it for remote access and client logins, and phishing-resistant MFA on administrator and cloud accounts; a second factor on every account is PTS's standard.
Least privilege and admin control
People get the access they need, and nothing more.
Are administrator rights limited to a few named people, with their use logged and monitored?
The SFC's rule: access on a need-to-have basis, administrator accounts granted to a limited number of users, and their use logged and monitored.
Do administrators use separate accounts for admin work, never their everyday account?
Everyday accounts with admin rights are how ransomware gets in. The SFC limits and monitors administrator accounts; separate accounts for admin work are PTS's standard.
Maker-checker approvals
Two people for anything that could really hurt.
Are payment instructions confirmed by a call-back or a second person before anyone acts on them?
Payment instructions are the target of impersonation fraud.
Secure remote access
Working from anywhere should not mean open to anyone.
Is remote access to the firm's systems only through a VPN or a zero-trust service, with a second factor?
The SFC's rule for reaching the internal network from outside: a VPN or its equivalent, with multi-factor authentication. A firm on cloud services alone, with no office network to reach, can answer Yes.
Can firm data be opened only on devices the firm manages?
Firm data on personal devices is outside the firm's control.
Network segmentation
Build internal walls so one breach does not become total.
Are the staff, server and guest networks kept apart?
Separation stops one infected laptop reaching everything.
Encryption in transit and at rest
If data is stolen, make it unreadable.
Is every laptop's disk encrypted?
A lost laptop with unencrypted client files is a reportable incident.
Endpoint protection
Every laptop and phone is a front door. Lock each one.
Which anti-malware or endpoint protection runs on every laptop and server?
The SFC expects anti-malware on every server and workstation; detection and response with someone watching the alerts is PTS's standard.
Email and web security
Stop threats before they reach anyone's inbox.
Is incoming email scanned for phishing, with outside senders tagged?
Phishing is the most common way into a fund manager.
Backup and recovery
Assume the worst will happen. Be able to get it all back.
Could someone who took over an administrator's account delete the backups?
Answer No only if the backup is offline or in a separate account that the firm's own administrators cannot reach.
Record keeping and retention
Keep what you must, find it when asked, delete it when due.
Are the firm's email and files kept for at least seven years before they can be deleted?
SFC firms must keep most records for seven years; a retention policy in Microsoft 365 or the file store is how it is done.
Cloud and storage due diligence
Your data in someone else's data centre is still your responsibility.
Has the firm checked each cloud provider that holds its data: its security certifications, where it keeps the data, and how the firm would get it back?
Your data in someone else's data centre is still your responsibility: keep access, control and an exit plan.
Audit logging and review
Record who did what, and actually look at it.
How many days are the audit and sign-in logs kept?
The SFC says keep and review the logs of critical systems, and sets no period; PTS's standard is at least a year.
Does someone review the security logs regularly?
The SFC expects audit logs to be reviewed, not just kept.
Security monitoring
Someone watching for trouble, day and night.
Are security alerts monitored and followed up, at least during working hours?
The SFC expects detection and monitoring in step with the threat, with anomalies followed up; round-the-clock watching is PTS's standard.
Are security alerts watched 24 hours a day, 7 days a week?
An alert at 2am that nobody sees until Monday is not detection. The SFC expects detection and monitoring in step with the threat; round-the-clock watching is PTS's standard.
Incident response and exercises
Know who does what before the crisis, not during it.
Does the firm have an incident response plan?
The plan covers handling an incident and reporting it to the SFC.
Has the incident response plan been exercised (a tabletop exercise) in the last 12 months?
The SFC expects incident plans to be tested.
Business continuity and recovery
Keep working when systems, offices or people are unavailable.
Does the firm have a business continuity plan?
The SFC expects a plan covering loss of the office, systems, people and providers.
Accountable ownership
One named senior person answers for technology risk.
Is one named senior person accountable for technology risk?
Without a named owner security becomes nobody's job and budgets are set blind. SFC firms must name a Manager-in-Charge for Information Technology.
Does that person get a report on technology risk at least every quarter?
PTS's practice: a quarterly report on risks, tests and incidents, so the owner can act on them.
Supplier risk management
You can outsource the work, not the responsibility.
Does the firm keep a register of the suppliers that hold its data or can reach its systems, checked before they start and reviewed every year?
Many breaches arrive through a supplier, and the firm stays responsible for anything it outsources.
Governance of AI tools
Use AI with your eyes open.
Does the firm have a policy on using generative AI?
The AI circular expects a policy on what AI may be used for and with what data.
Your results
Where the firm stands on the 24 controls
Nothing answered yet. Start with the two questions about the firm.
Each control is judged against the SFC's own text. Answer the licences question to see how the 24 controls relate to the SFC's requirements for your firm. PTS has checked nothing here: every result rests on what you said.
The 24 controls
Test and find weaknesses
Find the gaps before an attacker does.
- 01Penetration testingNeeds an answer
- 02Phishing simulation and trainingNeeds an answer
- 03Internal vulnerability scanningNeeds an answer
- 04External vulnerability scanningNeeds an answer
- 05Patch managementNeeds an answer
- 06Removing end-of-life softwareNeeds an answer
Control who gets in
The right people, the right access, nothing more.
- 07Multi-factor authenticationNeeds an answer
- 08Least privilege and admin controlNeeds an answer
- 09Maker-checker approvalsNeeds an answer
- 10Secure remote accessNeeds an answer
- 11Network segmentationNeeds an answer
Protect the data
Keep sensitive information safe, recoverable and under your control.
- 12Encryption in transit and at restNeeds an answer
- 13Endpoint protectionNeeds an answer
- 14Email and web securityNeeds an answer
- 15Backup and recoveryNeeds an answer
- 16Record keeping and retentionNeeds an answer
- 17Cloud and storage due diligenceNeeds an answer
Detect and respond
Spot trouble early and handle it calmly.
- 18Audit logging and reviewNeeds an answer
- 19Security monitoringNeeds an answer
- 20Incident response and exercisesNeeds an answer
- 21Business continuity and recoveryNeeds an answer
Govern and oversee
Make security someone's job, including your suppliers'.
- 22Accountable ownershipNeeds an answer
- 23Supplier risk managementNeeds an answer
- 24Governance of AI toolsNeeds an answer
Where to start
You do not need all 24 on day one. This order gives the biggest risk reduction first.
1First 90 days
- Patch management Needs an answer
Automated patching on a monthly cycle, an emergency route for urgent fixes, and a report showing what is and is not patched.
- Removing end-of-life software Needs an answer
An inventory that records support end dates, replacements planned a year ahead, and anything that cannot be removed isolated.
- Multi-factor authentication Needs an answer
A second factor on every account: email, cloud apps, VPN and administrators, with phishing-resistant methods rather than text-message codes.
- Encryption in transit and at rest Needs an answer
Every laptop's disk encrypted, modern TLS for web and email traffic, and encrypted backups and cloud storage.
- Endpoint protection Needs an answer
Endpoint detection and response on every laptop and server, centrally managed with enforced settings, and local administrator rights restricted.
- Email and web security Needs an answer
Advanced email filtering; SPF, DKIM and DMARC set to enforce; outside senders tagged; and web filtering that blocks known bad sites.
- Backup and recovery Needs an answer
Daily backups, Microsoft 365 included; an immutable or offline copy an attacker cannot delete; and restores tested at least quarterly.
23 to 6 months
- Phishing simulation and training Needs an answer
Monthly or quarterly simulated phishing emails, short training for anyone who clicks, and click and report rates tracked over time.
- Internal vulnerability scanning Needs an answer
Laptops, servers and network devices scanned every month for missing patches and weak settings, with the results fed into patching.
- External vulnerability scanning Needs an answer
Everything the firm exposes to the internet scanned every month, an alert when a new service appears, and critical findings fixed within days.
- Least privilege and admin control Needs an answer
Access limited to what each role needs, separate administrator accounts raised only when needed, and access reviewed quarterly and removed on exit.
- Maker-checker approvals Needs an answer
A second person approves payments, bank detail changes and major system changes, with a call-back on a known number before payment details change.
- Secure remote access Needs an answer
VPN or zero-trust access, always with a second factor; only managed devices allowed in; company data kept off personal devices.
- Network segmentation Needs an answer
Separate networks for staff, guests, printers and meeting-room equipment, firewall rules between them, and servers and backups in a restricted zone.
- Incident response and exercises Needs an answer
A written plan with roles, contacts and decision points; IT, legal and insurer support agreed in advance; and an exercise every year.
- Business continuity and recovery Needs an answer
Recovery time targets agreed for key systems, cloud-based working so staff can operate anywhere, and recovery tested at least once a year.
36 to 12 months
- Penetration testing Needs an answer
An independent, accredited firm tests the firm's defences every year; findings are ranked by risk, fixed and retested.
- Record keeping and retention Needs an answer
Retention policies in Microsoft 365 and the file store that keep records for seven years, in known locations, with search and legal hold tested.
- Cloud and storage due diligence Needs an answer
Each provider's certifications checked, where the data is held on record, and contract terms for access, audit and exit.
- Audit logging and review Needs an answer
Sign-ins, administrator actions and data access collected centrally, kept for at least twelve months, protected from tampering, and reviewed regularly.
- Security monitoring Needs an answer
Managed detection and response around the clock, with alerts for unusual sign-ins, mass downloads and new administrator rights.
- Accountable ownership Needs an answer
A named owner, often the COO; a quarterly report on risks, tests and incidents; and an annual review of the policies and the risk register.
- Supplier risk management Needs an answer
A supplier register ranked by risk, security checks before a supplier starts, and contract terms on security, breach notice and audit.
- Governance of AI tools Needs an answer
An approved list of AI tools, such as Copilot in the firm's own tenant; clear rules on what data may go in; and a person reviewing AI output used in decisions.
Talk to PTS about the gaps
Send this to PTS and within two business days a consultant comes back to walk through the gaps with you: what closes each one, in what order, and what the full assessment would add. Your answers are attached automatically. No obligation.
This quick audit is general guidance on technical good practice, prepared by PTS Managed Services to structure a security discussion. It is not legal or regulatory advice and does not certify compliance with any requirement of the Securities and Futures Commission; each result rests on what you said. PTS Managed Services Limited is ISO/IEC 27001 and ISO/IEC 20000 certified. Question set current at 25 September 2026. SFC-licensed firm? The SFC Licence Navigator sets out your regulatory obligations.
Security controls audit FAQs
Where do the 24 controls come from?
From the SFC's own guidelines and circulars for licensed corporations: the Internet Trading Guidelines, the circulars on external data storage (2019), remote working (2020) and generative AI (2024), the 2025 cybersecurity review and the 2026 circular on AI-enabled attacks. PTS grouped what they expect of every firm into 24 controls.
My firm is not SFC-licensed. Is this for me?
Yes. Family offices, wealth managers, fund administrators and private companies hold the same kind of data and move the same kind of money as a licensed hedge fund, and attackers treat them the same way. The 24 controls are a proven, proportionate benchmark; say the firm is not licensed and the audit uses them as such.
How long does it take, and what do I need?
About ten minutes and no IT knowledge. Each control is one plain question, with a second where the SFC's bar and PTS's standard differ. Not sure is always an answer; it usually means worth checking, and those are the items a PTS assessment looks at first.
What does "below PTS's standard" mean?
Each control is judged against the SFC's own text. On nine controls PTS's standard is stricter than the SFC's, for example endpoint detection and response rather than antivirus alone, or logs kept a year where the SFC sets no period. A control that meets the SFC's text but not PTS's is in place, and marked so you know what PTS would do next. It is never counted as a gap.
What happens to my answers?
They stay in your browser. You can print the result to PDF. If you send it to PTS, it goes to our inbox to prepare a conversation, and nowhere else.
What is the difference from the full assessment?
The full assessment measures the firm against every SFC requirement that applies to its licences, system by system, checks the documents behind each control and ends in a signed report. The 24 controls stand behind most of those requirements, and every answer given here carries straight into it.