Back to perspectives

Family risk and cybersecurity

AI-enabled cyber risk: authorisation design and operational resilience for family offices

G70 content review draft | Information as at 5 August 2026

AI-enabled cyber risk: authorisation design and operational resilience for family offices

When voice, video and email can all be credibly imitated, cybersecurity is no longer only about blocking malware. It is about redesigning how an instruction earns trust.

Hong Kong incident trend

As attacks scale, authorisation procedures must change

12,536

Cybersecurity incidents in Hong Kong in 2024

15,877

Cybersecurity incidents in Hong Kong in 2025

About +27%

Year-on-year increase cited in the SFC circular

01

AI changes the cost and speed of an attack

Generative tools did not create every cyber risk, but they are reducing the time needed for reconnaissance, impersonation and social engineering. Attackers can organise public information, imitate tone, create deepfake audio or video and target several family members and providers at once. The most sensitive exposure for a family office usually lies in the connections between identity, authority, schedules, asset data and payment instructions.

02

Regulatory data is a warning, not a universal legal rule

In its June 2026 circular, the Securities and Futures Commission cited Hong Kong Computer Emergency Response Team Coordination Centre data showing cyber incidents rising from 12,536 in 2024 to 15,877 in 2025—about 27%. The circular directly applies to licensed corporations, licensed virtual-asset service providers and associated entities, and should not be presented as a legal requirement for every family office. Its principles on vulnerability management, authentication and monitoring are nevertheless relevant to highly sensitive private organisations.

03

Move from recognising a person to verifying a process

A familiar voice, a face on video or caller ID is not sufficient authorisation in a deepfake environment. Adding a beneficiary, changing bank instructions, resetting multi-factor authentication, exporting large datasets and elevating administrator rights should require separate maker and checker roles, plus confirmation through a pre-registered channel different from the originating message. Good controls assume that one account or one colleague may be compromised, without allowing that compromise to complete a high-impact action.

04

The attack surface includes every external relationship

Email, cloud storage, accounting, IT support, banking platforms, asset management and communications are often spread across providers. Each connection can extend the movement of data and permissions. Provider due diligence should therefore continue after procurement, covering access rights, subcontracting, incident-notification timeframes, data location and recovery capacity. Access should be withdrawn when the relationship ends.

05

Resilience must be exercised, not merely documented

Useful testing asks whether the team can suspend access, notify banks, preserve evidence and move to clean systems within an hour of an executive email takeover, deepfake payment request, cloud leak or abnormal trading activity. The use of AI also requires controls: sensitive identity, transaction and asset data should not be entered into public models, while AI connected to mail, files or workflows should have least privilege and auditable records.

06

Classify data before deploying AI

A public model, an enterprise tool and an agent connected to internal email or files do not carry the same risk. A family office should set input rules for identity data, asset information, payment instructions, legal documents and general research instead of leaving every decision to individual staff.

Any AI that can read email, cloud files or workflows should have a defined purpose, least-privilege access, short-lived credentials, usage logs and a revocation mechanism. Model efficiency does not replace approval by the data owner.

07

G70 conclusion: verify the authorisation process, not just the person

Deepfakes mean that voice, face, tone and caller ID no longer provide sufficient proof on their own. High-impact instructions need pre-registered channels, dual review, a delay or cooling-off period, and transaction and authority limits.

Resilience does not assume that nobody will be deceived. It ensures that the compromise of one account, device or colleague is still insufficient to complete a payment, export data or escalate privileges.

G70

G70 cyber-resilience review

A high-risk instruction should pass five gates

Controls should assume that identities can be imitated and accounts can be taken over.

  1. Does adding a payee or changing bank instructions require different people to propose and approve?
  2. Is verification completed through a pre-registered channel different from the original message?
  3. Do administrator access, MFA resets and bulk data exports generate immediate alerts?
  4. Are vendor access, subcontracting, incident notice and termination controls reviewed regularly?
  5. Can the team disable access, notify banks, preserve evidence and move to a clean system within one hour?
Sources

Official and primary sources

  1. Hong Kong SFC | Emerging risks from AI-enabled cyberattacks (2026-06-02)
  2. Hong Kong SFC | AI-enabled cyber threats press release (2026-06-02)
  3. Hong Kong SFC | Robust authentication and monitoring measures (2026-07-09)

Sources were checked on the publication date shown above. Regulations, policies and market data may subsequently change.