Search Menu
Language Menu
Mobile Menu
OGCIO
21-09-2018

Opening Keynote Speech by Mr. Jason Pun, Assistant Government Chief Information Officer (Cyber Security & Digital Identity), at the “Cyber Security in E-Payment Conference 2018”


Mr. LEE (Mr. Enoch LEE, General Manager of British Standards Institution Hong Kong), distinguished guests, ladies and gentlemen,

Good morning. I am delighted to join you here today at the Cyber Security in e-payment Conference 2018. I would like to express my gratitude to the British Standards Institution Hong Kong for organising this meaningful event and promoting security awareness on the adoption of e-payment technology.

Nowadays, e-payment solutions provide customers with a convenient and versatile choice to settle payments, such as NFC (Near Field Communication), QR code or digital wallet on mobile devices. On the other hand, the number and complexity of cyber attacks continue to increase. According to the Hong Kong Computer Emergency Response Team Coordination Centre, or “HKCERT” in short, the popularity of mobile payment services will likely attract more attacks on mobile payment apps in 2018. It is therefore important for all of us to stay alert in order to avoid monetary loss or data breach. In this connection, a well-managed and secure infrastructure is vital for organisations to protect their critical business operations against cyber attacks. Moreover, appropriate defenses should be properly in place to mitigate the risks of cyber attacks and to strengthen the capability to detect cyber threats.

Hong Kong is an international city. Our financial services are becoming increasingly interconnected and interdependent. This requires a high degree of alignment with international standards. The Government has all along been keeping vigilant on the latest security standards, such as ISO 27001 and COBIT 5, and reviewing our security policies to align with the standards. We also share our security policies and best practices through our InfoSec website (www.infosec.gov.hk) to encourage the public and private sectors to adopt international standards and best practices in managing their information security.

When facing the ever-changing cyber security landscape, traditional security protection techniques and procedures may not be adequate to mitigate the imminent cyber attacks. Collective wisdom and effective information exchange could render a more effective approach to tackle cyber threats, as the security spectrum is so wide that no single entity is able to handle all security matters alone. Therefore, we need to solicit expert advice and wisdom from different security professionals, collect up-to-date information from reliable and trusted sources so as to rationally identify potential risks in today’s cyber world. This year, the Government takes the lead to implement a community-driven partnership programme, the “Cybersec Infohub”, to facilitate the sharing of information and analysis on cyber security risks and vulnerabilities in a trusted environment. It also aims to provide actionable insights for the stakeholders and the general public, thus enabling them to take proactive and timely measures to address imminent security threats.

Apart from strengthening security measures at the corporate level, we also need to raise user awareness in order to manage cyber risks effectively. Therefore, it is important for all organisations to promote cyber security awareness and educate their staff, users and customers on the importance of information security. Via the Cyber Security Information Portal (www.cybersecurity.hk), the Government publishes practical guidelines and advices on cyber security. You may wish to make reference to these documents to develop your own materials and educate your staff, users and customers.

Last but not least, cyber attacks are no longer isolated issues and cyber threats are borderless and ever-evolving. To better prepare for these, we should actively participate in the exchange of cyber security information among all stakeholders to enhance the security capability and resilience of the community as a whole. I wish you all a very successful and rewarding conference. Thank you.

- ENDS -