Skip to main content

HKPC's HKCERT Urges Hong Kong Businesses to Strengthen Data Protection

(Hong Kong, 25 October 2018) In light of the recent unauthorised access incident at a Hong Kong airline, the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT) of the Hong Kong Productivity Council (HKPC) reminds local companies to strengthen their data protection and security of their IT systems, and be vigilant against any potential unauthorised access and data breach.

HKCERT advises businesses to take the following preventive measures:

  • Put in place a data classification policy to classify confidential and sensitive information, and set up proper control measures such as encryption and user access right on these information;
  • Configure network separation for enterprise internal and Internet facing networks. Also put database servers out of direct contact from the Internet;
  • Perform regular vulnerability scanning on website or web application (e.g. eCommerce, online payment etc.) to identify any weak configuration or vulnerabilities. Apply security patches timely and regularly and fix any configuration issues. Please note that many data breaches may not involve attacks, but are caused by improper or weak configurations such as too much administrator access right or no access control to data storage.
  • Secure the administrator account on web or cloud hosting by multi-factor authentication;
  • Consider deploying data loss prevention (DLP) solution in your infrastructure based on risk assessment and cost evaluation; and
  • Monitor any abnormal network traffic regularly. Gather any events or alerts from servers and endpoints with security information and event management (SIEM) facility, to set up alerts for any abnormal or potential security breach.

Meanwhile, members of the public can also undertake the following precautionary measures:

  • Check on the airline’s website for further information;
  • Review credit card transactions to check if the card has been used for online transaction with the company;
  • Pay attention to SMS or phone call notification of any unusual credit card transactions; and
  • Beware of scam emails making use of the name of the company or their personal information.

Companies and the public wishing to learn more about ways to improve their information security, please visit HKCERT’s website: www.hkcert.org, call the HKCERT hotline on (852) 8105 6060, or email at hkcert@hkcert.org.

- Ends -