Skip to content Skip to footer

The HR Function has a Strategic Role to Play in Maintaining Cybersecurity Defences – By the Hong Kong Internet Registration Corporation Limited

The HR Function has a Strategic Role to Play in Maintaining Cybersecurity Defences – By the Hong Kong Internet Registration Corporation Limited

Key Takeaways:

 

  • The pivot to work from home (WFH) has made it more challenging for organisations to protect themselves from cybersecurity threats, and cybersecurity protocols should include the use of software tools such as two-factor authentication, VPN, and tools to manage passwords.

  • With the rise of AI tools, cybercriminals are using generative artificial intelligence to create convincing phishing campaigns. It is recommended to establish clear protocols outlining the permissible use of AI tools and to ensure they are regularly updated to keep pace with the latest cybersecurity threats.

  • Cybersecurity awareness and training programmes need to be periodically updated and offered to employees at regular intervals, and a people-centric approach that focuses on motivating employees to care about cybersecurity is recommended.

As well as playing an integral role protecting organisations from cyberattacks, the HR function is also one of the most targeted functions by cybercriminals.

 

While the IT department can put cybersecurity technology controls in place to protect the organisation, the HR function can play a primary role ensuring that cybersecurity education is woven into the culture of the organisation.

 

Ensuring cybersecurity awareness programmes fit with an organisation’s specific cybersecurity needs is vital to providing the right training for staff. 

 

To be effective, employee cybersecurity training programmes need to be interactive and engaging.

 

Amid a rapidly evolving cybersecurity threat landscape, when it comes to protecting an organisation from cyberattacks, the HR function has a vital role to play, notes Arktos Lam, Cyber Security Manager with the Hong Kong Internet Registration Corporation Limited (HKIRC). For example, as the business function with a wide range of inflection points to external sources, the HR function is both a target for cybersecurity attacks as well as an “access gateway” for cybercriminals.

 

Lam emphasises that the risk of a cyberattack is always present. There are no holidays or days off, he says. While cybercriminals use advanced technology to probe network inflection points for weakness and vulnerabilities, they also seek to exploit human weaknesses to gain access to data, devices, systems and networks. “The HR function holds sensitive employee information such as personal data, addresses, phone numbers and bank account details, which are valuable targets for cybersecurity criminals,” Lam says. Since HR practitioners need to open emails and attachments from unknown sources as part of their work, the HR function is often targeted by cybercriminals in phishing attacks. 

 

Lam explains that phishing attacks can come in many different forms; common examples include emails from fake job applicants which include malware attachments, which could be in the form of a CV. Malware attachments within malicious emails can be disguised as documents, PDFs, e-files and voicemails, which are not only capable of stealing information, but also provide unauthorised access to an organisation’s sensitive data, destroy data or extort ransom from the victim. Phishing emails sent to the HR function can also take the form of an employee pretending to be a member of staff requesting changes to be made to his or her employment records. Noting how cybercriminals have become more emboldened and resourceful, Lam points out that “bad actors” are using smarter techniques to trick employees into leaking sensitive data or downloading malicious attachments. An increasingly frequent ploy involves conducting research on a specific individual — such as an organisation’s senior executive — in order to create an attack that can be difficult to distinguish from a real email. 

 

 

“As AI tools become increasingly ubiquitous, cybercriminals are leveraging generative artificial intelligence to craft highly convincing phishing campaigns tailored to the language of the intended recipients. Instead of prohibiting staff from using AI tools, establishing clear protocols outlining which tools can be used and how they can be utilized is recommended. “

– Arktos Lam, Cyber Security Manager, Hong Kong Internet Registration Corporation Limited  

 

The cyber threat landscape has become more complex

 

As the world of work continues to evolve in the aftermath of the COVID-19 outbreak, Lam notes how the the pivot to work from home (WFH) and remote working has made it more of a challenge for organisations to protect themselves from cybersecurity threats. “The attack surface has increased,” he says. While previously, organisations had the majority of their staff working from an office where cybersecurity efforts could be focused on a contained corporate network, staff now log-in from home or other remote locations using different devices and network connections. This requires organisations to establish WFH cybersecurity protocols to prevent sensitive data from being compromised. Lam recommends that cybersecurity protocols should include the use of software tools such as two-factor authentication, VPN (virtual private networks) and tools to manage passwords. To create a secure environment, even when staff are using their own home Wi-Fi network, it is important for the HR function to train users to only use work-related tools and accounts for messaging, emailing, video calls or any other form of communication. 

 

Meanwhile, as AI tools become more prevalent, cybercriminals are using generative artificial intelligence (GPT) — the language model that underlies AI applications such as ChatGPT, to create convincing phishing campaigns in the language of the targeted audience. Consequently, tell-tale signs of fraudulent messages such as bad grammar and spelling become less obvious. While AI tools can be used to intercept or help to detect cybersecurity threats, Lam cautions that AI tools must be regularly updated to keep up with the latest cybersecurity threats. Furthermore, instead of prohibiting staff from using AI tools, Lam recommends establishing clear protocols outlining which tools can be used and how they can be utilised.  Access should correspond to necessity, Lam advises.

 

Cybersecurity is everyone’s responsibility

 

To build preparedness and strengthen resilience to phishing and other forms of cybersecurity attacks, Lam proposes increasing user awareness and personnel education. This requires close collaboration between the HR function, the IT function and the organisational buy-in. Regardless of role or seniority, Lam believes by educating staff across the organisation makes it easier for individuals to be aware of cybersecurity risks, and therefore, be aware of the importance of adhering to security controls and data privacy processes.

 

When developing employee cybersecurity training programmes, Lam recommends focusing on a people-centric approach rather than a one-size-fits-all approach.  “A people-centric approach focuses on what matters most—motivating employees to care about cybersecurity,” Lam says. This can be achieved by tailoring training with bite-sized, interactive, digital or video programmes which are suited to different job roles. For example, setting up a fake phishing attack relevant to the role of the employee. To offer a realistic scenario, a salesperson might get different phishing emails than a back-office customer support employee. “Providing training that looks and feels like the content they consume every day engages people,” Lam says. Incorporating competitive challenges into training programmes can also help to motivate employees and build team spirit. For instance, teams from different business functions may compete against each other on identifying passwords by using techniques similar to the techniques cybercriminals use. “Role-based content helps to improve learning through customisation,” Lam notes. Quizzes can also be used to monitor the effectiveness of the learning experiences.

 

Build a clear cybersecurity culture

 

As the business department responsible for maintaining recruitment and retention programmes, the HR function is often the first point of contact for current and future employees. Engaging with employees at the start of employment is a good opportunity to establish the foundation for a culture of cybersecurity risk awareness, Lam says. The on-boarding stage is an ideal time to highlight how cybersecurity awareness is part of the key performance indicator (KPI) measures included in the staff performance review. “This reinforces the fact the company takes cybersecurity seriously,” Lam says. While every organisation is different, it is important to establish cybersecurity best practices, such as guidelines to never reuse passwords and transfer work data to personal devices, as well as incident handling and data backup policies.

 

Lam also stresses the importance of maintaining the privacy settings on their social media accounts and refraining from using the same passwords for personal and professional accounts. As such, personal devices staff use for work should be password-protected and equipped with biometric authentication in case the device is lost or stolen.

 

To keep cybersecurity top-of-mind for employees, Lam recommends that awareness and training programmes need to be periodically updated and offered to employees at regular intervals, just as the same way the cybersecurity threat landscape continuous to evolve. “Employees should complete specific cybersecurity training at least one a year,” Lam advises.

 

For HR practitioners interested improving their organisation’s cybersecurity awareness, the HKIRC’s free training platform provides cybersecurity e-training at anytime and anywhere. The HKIHRM also arranges cybersecurity seminars and workshops for its members

E-mail*
Set Your Password*
Confirm Your Password*
** Your password must be minimum of 8 characters in length and use at least three of the following: uppercase letters, lowercase letters, numbers, and symbols.** eg. A12345^ /// Ab1234
  • I understand and agree that the personal data provided above will be used by the Institute for direct marketing activities and notification according Privacy Policy until further notice.
  • Your registered email address will serve as your login ID.
?
Join as member
to enjoy exclusive discount
 

訂閱HKIHRM最新資訊 Subscribe HKIHRM's Latest Update

【開放給非會員】登記電郵以獲取學會最新消息及公告。   想收取所有會員資訊請立即入會! 【Open for Non Members】Sign up for our email updates to get the latest news and announcements.   Seeking ALL information? Apply membership now!

*必填 indicates required
info@hkihrm.org

I understand and agree that the personal data provided above will be used by the Institute for direct marketing activities and notification according Privacy Policy until further notice.

我已明白並同意上述個人資料將由學會根據《私隱政策聲明》用作直接營銷活動及通訊之用,直至另行通知。

我已閲讀並同意以上條款。 I have read and agree to the above Terms. *

彰顯您的專業資格:香港人力資源管理學會資深會員 – F.I.H.R.M.(HK)

F.I.H.R.M.(HK) 標誌著您作為香港人力資源管理學會的資深會員,此乃香港人力資源專業知識的權威基準。

此資格代表您對業內高標準、道德實踐及持續發展的承諾。

展示方式:
自豪地展示您的成就。請在所有專業資料中統一標明 F.I.H.R.M.(HK) 會籍。範例參考:

  1. 名片
    您的姓名, F.I.H.R.M.(HK)
  2. LinkedIn 標題
    人力資源領導者 | 香港人力資源管理學會資深會員 (F.I.H.R.M.(HK)) | 專注於人才策略與組織發展
  3. 履歷 / 個人簡介
    「作為香港人力資源管理學會資深會員 (F.I.H.R.M.(HK)),我致力推動人力資源實踐的專業標準。」/

    「持有香港人力資源管理學會資深會員資格 (F.I.H.R.M.(HK)),此為香港人力資源領域之權威專業認證,標誌著對行業最高標準之認可與承諾。」

立即更新個人資料,讓 F.I.H.R.M.(HK) 資格成為您專業能力的最佳證明。

Showcase Your Designation: Fellow Member – F.I.H.R.M.(HK)

The designation F.I.H.R.M.(HK) marks you as a Fellow Member of the Hong Kong Institute of Human Resource Management, the definitive benchmark of HR expertise in Hong Kong.

This designation signifies a commitment to high standards, ethical practice, and continuous development in the field.

Where to Display It:

Be proud of your achievement! Incorporate F.I.H.R.M.(HK) consistently across your professional profile. Sample is as below.

  1. Business Cards

Your Name, F.I.H.R.M.(HK)


  • LinkedIn Headline

HR Leader | Professional Member of the Hong Kong Institute of Human Resource Management (F.I.H.R.M.(HK)) | Specialising in Talent Strategy & Organisational Development

 

  1. Resume/Bio
    “As a Fellow Member of the Hong Kong Institute of Human Resource Management (F.I.H.R.M.(HK)), I am committed to upholding the professional standards of HR practice.” / 

 

“Holder of the F.I.H.R.M.(HK) designation, which denotes recognised expertise and a formal commitment to continuous professional development within the Hong Kong HR sector.”

Update your profile today and let your F.I.H.R.M.(HK) designation speak for your professionalism.

彰顯您的專業資格:香港人力資源管理學會專業會員 – M.I.H.R.M.(HK)

M.I.H.R.M.(HK) 標誌著您作為香港人力資源管理學會的專業會員,此乃香港人力資源專業知識的權威基準。

此資格代表您對業內高標準、道德實踐及持續發展的承諾。

展示方式:
自豪地展示您的成就。請在所有專業資料中統一標明 M.I.H.R.M.(HK) 會籍。範例參考:

  1. 名片
    您的姓名, M.I.H.R.M.(HK)
  2. LinkedIn 標題
    人力資源領導者 | 香港人力資源管理學會專業會員 (M.I.H.R.M.(HK)) | 專注於人才策略與組織發展
  3. 履歷 / 個人簡介
    「作為香港人力資源管理學會專業會員 (M.I.H.R.M.(HK)),我致力推動人力資源實踐的專業標準。」/

    「持有香港人力資源管理學會專業會員資格 (M.I.H.R.M.(HK)),此為香港人力資源領域之權威專業認證,標誌著對行業最高標準之認可與承諾。」

立即更新個人資料,讓 M.I.H.R.M.(HK) 資格成為您專業能力的最佳證明。

Showcase Your Designation: Professional Member – M.I.H.R.M.(HK)

HKIHRM Members’ Privilege – Asia Council Membership of The Conference Board (TCB)

The designation M.I.H.R.M.(HK) marks you as a Professional Member of the Hong Kong Institute of Human Resource Management, the definitive benchmark of HR expertise in Hong Kong.

This designation signifies a commitment to high standards, ethical practice, and continuous development in the field.

Where to Display It:

Be proud of your achievement! Incorporate M.I.H.R.M.(HK) consistently across your professional profile. Sample is as below.

  1. Business Cards

Your Name, M.I.H.R.M.(HK)

 

  • LinkedIn Headline

HR Leader | Professional Member of the Hong Kong Institute of Human Resource Management (M.I.H.R.M.(HK)) | Specialising in Talent Strategy & Organisational Development

  1. Resume/Bio
    “As a Professional Member of the Hong Kong Institute of Human Resource Management (M.I.H.R.M.(HK)), I am committed to upholding the professional standards of HR practice.” / 

“Holder of the M.I.H.R.M.(HK) designation, which denotes recognised expertise and a formal commitment to continuous professional development within the Hong Kong HR sector.”

Update your profile today and let your M.I.H.R.M.(HK) designation speak for your professionalism.

需要幫助?想加入我們?有問題想查詢?

我們隨時為您服務!請留言給我們,我們的團隊會盡快回覆您。

      Pesonal Information

      Training Information

      Need assistance? Interested in joining us? Or just have a question?

      We’re here to help! Reach out via message, and our team will respond as quickly as possible.

        Asia Council Membership

        HKIHRM Members’ Privilege – Asia Council Membership of The Conference Board (TCB)

        As a HKIHRM Fellow and Professional Member, you are entitled to a 20% discount for joining the Asia Council Membership of TCB, an international think tank that delivers trusted insights for what’s ahead.

        TCB of Asia Council package offers a peer network, a portfolio of thought leadership, and access to experts to help address your job challenges and strengthen your team and organisation’s performance. By bringing together select senior executives from the world’s leading companies, the Council engages you in an immersive, solutions-focused conversation.

        The Asia Council Membership includes:

        • Two to three in-person meetings a year
        • Private Council website
        • Council bench-marking surveys and dedicated support from your Council team

        Eligibility:

        • Active HKIHRM Fellow and Professional Members
        • Individual basis
        • The application is subject to TCB’s vetting and approval

        Discounted Offer (1st year of membership only)

        • Year 1: USD 9,000 (USD 7,200)

        Application & Enquiry:
        Mr Brendan Moran
        Email: Brendan.moran@conference-board.org Tel: +65 6645 4696

        Reciprocal Membership

        Mutual Recognition of Professional Membership between HKIHRM and Canada-based CPHR British Colombia & Yukon

        HKIHRM has established mutual recognition of Professional Membership with the Chartered Professionals in Human Resources of British Columbia and Yukon CPHR British Colombia & Yukon since 2015. This understanding is based on a recognition of ‘substantial equivalency’ of the F.I.H.R.M.(HK) or M.I.H.R.M.(HK) designation to those of the CPHRTM designation, a CPHR British Colombia & Yukon’s Chartered Professional in Human Resources designation. HKIHRM Fellow Members and Professional Members are eligible to obtain the CPHRTM designation from CPHR British Colombia & Yukon.

        • To become a Professional Member M.I.H.R.M.(HK) of HKIHRM, please click HERE  for more information. Application form can be downloaded HERE .
        • To become a CPHRTM member of CPHR British Colombia & Yukon, please click HERE for more information. Application form can be downloaded HERE.

        Enquiry:

        HKIHRM: +(852) 2837 3814, membership@hkihrm.org 

        CPHR British Colombia & Yukon: Please send your application directly to cphr@cphrbc.ca, https://cphrbc.ca/cphr/i-am-a-cphr/cphr-mutual-recognition/

        Terms and Conditions

        1. Membership fee is charged for members joining between 1 April and 31 March for one-year or two-year subscription. (and subject to meeting mandatory CPD requirement for Professional-route-based Membership  only for renewed Fellow, Professional and Associate Members)
        2. Entrance and annual subscription fees are subject to review by the Institute without prior notice.
        3. HKIHRM will notify members to renew their membership via mail and email every year in March. Members can settle renewal fee by different payment methods marked in the invoice and enjoy the discount rate if the renewal fee is settled before the early bird period. E-vouchers will be provided if the renewal fee is settled.
        4. The upgraded membership fee is charged for members joining between 1 April and 31 March for one year or two years subscription (Same as selected membership renewal period).
        5. Member must have a valid membership and meet the upgrade requirements in order to apply for a membership upgrade. For assistance with the application process, please contact Member Services Team.
        6. Those aged 60 or above AND on permanent retirement may notify HKIHRM by email to enjoy 50% discount on the individual membership fee.
        7. Members can apply for membership reinstatement after their membership has been suspended since the introduction of new membership scheme on 1 April 2010 by:
          • paying a reinstatement fee (all the outstanding annual membership fee since his / her suspension); and
          • providing CPD records for the year(s) showing you have met the CPD requirement since you have ceased to be a member (if applicable)
        8. HKIHRM shall has absolute discretion in respect of each application to decide conclusively whether he / she has fulfilled the conditions applicable to his / her case or not. The decision of the HKIHRM is final and shall not be subject to any appeal. Membership fee is non-cancellable and non-refundable.


        If you have any enquiry on membership, please contact
        Member Services Team (2837 3814 / 2837 3813) or email at membership@hkihrm.org.