First announced: Securities and Futures Commission circulars issued in 2025.
Submitted by: NYBACS Compliance Desk
What changed
New baseline controls, penetration testing requirements, and incident reporting standards apply to regulated financial institutions.
Who’s affected
Broker-dealers, asset managers, fintech operators licensed by the SFC.
Immediate actions
• Perform cybersecurity gap assessment.
• Update incident reporting plan.
• Review third-party IT vendor security.
Practical notes & timeline Enforcement monitoring continues through 2026 supervisory reviews.



