Digital surfaces
Threat themes
- Data Privacy
- Account Abuse
- Content Theft
Recommended services
Verified Hong Kong data
Official, market-level Hong Kong data — reported figures, not per-company loss estimates.
Enterprises experiencing cyberattacks
69% enterprises · 71% corporates
Share of surveyed enterprises and corporates experiencing at least one type of cyberattack in the past 12 months
- Official source:
- PCPD + HKPC — Hong Kong Enterprise Cyber Security Readiness Index and AI Security Survey 2024
- Timeframe:
- 2024 survey
- Scope note:
- Survey context across Hong Kong enterprises; not a probability estimate for any one company.
Awareness training and drills
35% training · 24% drills
Share of surveyed enterprises that provided cybersecurity awareness training and conducted drills
- Official source:
- PCPD + HKPC — Hong Kong Enterprise Cyber Security Readiness Index and AI Security Survey 2024
- Timeframe:
- 2024 survey
- Scope note:
- Use for recurring advisory, incident readiness, leadership and employee-awareness framing.
Phishing share of incidents
57% of incidents
Phishing accounted for 57% of reported cybersecurity incidents
- Official source:
- HKCERT — Hong Kong Cybersecurity Outlook 2026
- Timeframe:
- 2025
- Scope note:
- Use for impersonation, credential, portal, payment and customer-trust risk context.
Attacked enterprises encountering phishing
98%
Among attacked enterprises, phishing remained the most common cyberattack type
- Official source:
- PCPD + HKPC — Hong Kong Enterprise Cyber Security Readiness Index and AI Security Survey 2024
- Timeframe:
- 2024 survey
- Scope note:
- Use for email, SMS, social impersonation, customer support and awareness-risk context.
Likely loss areas
Student and member accounts, enrolment payment flows, learning portals, file sharing, community communication and employee-awareness gaps need recurring control checks.
What structured security support changes
Area
Risk visibility
With structured support
Critical portals, apps, access paths, payment and data flows, cloud dependencies and supplier touchpoints are reviewed on a recurring basis.
Without structured support
Risk is often discovered after a customer complaint, suspicious transfer, failed partner review, outage, fraud case or incident.
Area
Fraud and payment exposure
With structured support
Authentication, payment redirection, invoice workflows, customer account flows, digital-token prompts and API journeys are mapped to likely fraud paths.
Without structured support
Fraud exposure can remain hidden inside checkout, email, mobile, portal, support or admin workflows until loss or trust damage occurs.
Area
Evidence for partners and leadership
With structured support
The organisation keeps a clearer security file with executive summary, prioritised risks, remediation notes, source context and follow-through decisions.
Without structured support
Security answers become reactive during procurement, investor diligence, regulator questions, bank or partner reviews, or post-incident communication.
Area
Incident readiness
With structured support
Access ownership, logs, backup separation, recovery priorities, vendor owners and communication paths are easier to confirm before an incident escalates.
Without structured support
Teams may lose time identifying owners, systems, vendors, evidence, backup status and recovery priorities during a stressful event.
Area
Cost discipline
With structured support
Remediation can be sequenced by business impact, documented clearly and budgeted as planned security work.
Without structured support
Work is often done under pressure with higher uncertainty, rushed decisions, wider disruption and more difficult stakeholder communication.
BilgeQor Method
We turn Hong Kong market evidence, sector exposure and technical findings into a security file leadership can act on.
01
Market & sector research
We connect official Hong Kong data with the digital workflows that matter for the sector.
02
Exposure mapping
We map portals, apps, payment flows, APIs, admin paths, vendors, cloud dependencies and customer data touchpoints.
03
Impact analysis
We rank findings by operational, financial, trust, regulatory and delivery impact — not only technical severity.
04
Security file delivery
We deliver an executive summary, prioritised risks, remediation notes and a practical follow-through path.
