Why this page exists

Ransomware remains one of the highest-impact cyber risks for Hong Kong SMEs: limited IT headcount, shared admin accounts, and backups that exist on paper but fail under timed restore. This guide focuses on operator actions that reduce ruinous outcomes — not vendor marketing.

For national incident coordination during an active attack, contact HKCERT. HKISG materials support readiness, board language, and programme evidence — see HKCERT and HKISG and the Ransomware glossary entry.

Context: how SME ransomware usually unfolds

  1. Initial access via phishing, exposed RDP/VPN, or compromised supplier credentials.
  2. Privilege escalation and lateral movement across flat networks.
  3. Backup sabotage (delete or encrypt connected backup volumes).
  4. Encryption + data theft + ransom note; sometimes deepfake pressure on executives — see Deepfake Fraud in Hong Kong.

AI does not invent ransomware, but it accelerates phishing copy, helpdesk social engineering, and attacker triage of stolen data.

Hong Kong implications

  • Many SMEs rely on MSPs; a single shared privileged identity can cascade across clients.
  • Cross-border cloud and local NAS mixes create restore blind spots.
  • PDPO notification duties may apply if personal data is exfiltrated — see PDPO and privacy wiki.
  • Public Trust Reviews look for operated restore evidence, not slideware — Methodology v2026.2.

What good looks like

Area
Common SME gap
Minimum viable control
Backups
Connected disk only; never restored
Offline/immutable copy; timed restore of a critical system this quarter
Privileged access
Shared “admin” password
Named accounts + MFA; break-glass sealed and logged
Edge exposure
RDP on the internet
VPN/zero-trust with MFA; patch lag tracked
Incident path
“Call the IT guy”
One-page playbook: isolate, preserve, escalate (HKCERT / counsel / insurer)

Practical guidance (next 30 days)

  1. Prove restore — pick one critical system; restore under a clock; record time and gaps.
  2. Kill shared admins — inventory local and cloud privileged accounts.
  3. Close obvious exposure — internet RDP, outdated VPN appliances, unused admin portals.
  4. Segment backups — ransomware that can reach the only backup has already won.
  5. Brief ownership — who decides on paying a ransom (usually: do not decide alone under pressure).
  6. MSP contract — demand MFA on their access to your tenant and a named incident contact.

Deeper learning: Incident Response Basics, Incident Response Planning, Zero Trust wiki.

Hong Kong operator checklist

  1. Offline or immutable backup exists for finance, email, and core line-of-business data.
  2. Last successful restore drill is dated within 90 days.
  3. MFA covers email, VPN, and cloud admin consoles.
  4. RDP is not exposed to the open internet.
  5. MSP privileged access is named, MFA-protected, and revocable in one ticket.
  6. One-page ransomware playbook names HKCERT / insurer / counsel contacts.
  7. Board has seen a dated residual-risk note (Board Briefing Pack).

Editorial note

Educational material from HKISG. Not legal advice, not a guarantee against ransomware, and not a substitute for HKCERT during an active incident. See Policies.