HKCERT’s latest outlook paints a sharp picture for Hong Kong business leaders: cyber risk is accelerating, AI is amplifying attacker capabilities, and many enterprises still lack the people, controls and governance needed to keep pace.
The Hong Kong Computer Emergency Response Team Coordination Centre recorded 15,877 cybersecurity incidents in 2025, a 27% year-on-year increase and a new high, with phishing remaining the dominant threat.
AI and supply chains
For CISOs and CIOs, the most important shift is not the volume of attacks alone, but their changing shape. HKCERT said cyberattacks are becoming more automated, targeted and destructive as AI spreads, while the top risks for 2026 include AI-driven attacks, weak AI governance, third-party exposure, over-reliance on cloud infrastructure and emerging threats from AI-enabled devices.
The report highlights a practical governance problem. Around 35% of businesses using AI said they would enter corporate data into AI tools, suggesting that data leakage risk remains live. HKCERT also warned that agentic AI systems could be especially dangerous because they can execute actions autonomously if compromised.
Edmond Lai, chief digital officer of HKPC, said the proliferation of AI can drive innovation but can also become “a powerful tool for hackers, making cyber threats stealthier and more scalable”. He added that supply chain attacks have become “the weakest link in enterprise security”, where a single vendor’s vulnerability can trigger a chain reaction of crises even when internal protections are strong.
Incident patterns
Phishing accounted for 57% of all reported incidents in 2025, and HKCERT said generative AI is making fraudulent messages more realistic and harder to detect. Attack delivery has also broadened beyond email, with social media and instant messaging platforms such as WhatsApp accounting for 34% of cases, and cryptocurrency platforms 18%.
The surge in vulnerable-system incidents is another signal for operations teams. HKCERT recorded 2,328 such cases, 15% of the total and more than 3.5 times the prior year, indicating that misconfigurations and unpatched systems are being actively exploited.
Skills and resourcing
The enterprise landscape study suggests preparedness is uneven, particularly among SMEs. Nearly 70% of enterprises have dedicated cybersecurity personnel, but only 26% of SMEs do, versus 59% of large enterprises. SMEs also trail on email security, privileged access management and remote access security controls.
That gap matters because resources are still moving slowly: only 13% of SMEs increased cybersecurity resources in the past year, and just 5% plan to recruit more cybersecurity personnel in the next 12 months.
HKCERT’s message is clear for business leaders: cyber resilience now depends on proactive AI governance, stronger third-party oversight, and better investment in people and controls, not just technical defences. It is also pushing practical support through the Cybersecurity Service Providers Connect Programme, which links enterprises with vetted providers.








