CSA HKM Knowledge Sharing Event – November 2025

The ascent of AI and Large Language Models (LLMs) introduces a new class of cybersecurity threats that target the models themselves. Adversaries are now exploiting vulnerabilities unique to these systems through attacks like prompt injection to hijack outputs, training data poisoning to corrupt behavior, and model extraction to steal intellectual property. These techniques bypass conventional security controls, making the AI a primary attack surface.

Securing AI requires a focused shift in strategy. Defenses must move beyond perimeter security to directly fortify the AI lifecycle. While many conferences extensively cover AI security methodologies, a critical gap remains: the lack of a unified, rapid-protection solution. To address this gap, the Cloudflare team will present their solution: leveraging the Cloudflare SASE platform and Gateway to create a dedicated security layer for AI. This provides a much-needed guardrail, applying the proven principles of a WAF directly to AI applications.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants may claim 1 CPE

DATE: November 27, 2025 (Thursday)

TIME: 12:30 – 01:30 pm

FORMAT: Webinar (in English)

SPEAKER: Chad LAU, Senior Solution Engineer, Cloudflare

TOPIC: From Shadow IT to Agentic AI: The Unified Platform for AI Security

CONTENT:
AI adoption brings massive productivity gains, but it also introduces significant security risks like data exfiltration. Traditional security strategies, such as blocking AI entirely, are failing. These strategies ignore the reality of how your teams and customers want to implement.

This session explores how to resolve and provide solution. Chad will introduce the Cloudflare AI Security Suite, a unified platform designed to help organizations adopt AI by managing risk, boosting productivity, and enabling secure development – all at once.

SPEAKER:
Chad is a Senior Solution Engineer at Cloudflare, where he focuses on Hong Kong with Cloud and cybersecurity solutions. Chad works with enterprise clients to design and implement strategies that protect their infrastructure and data without compromising performance.

VIEW THE PRESENTATION: https://youtu.be/-t7e8cWLNrY

CCSK v5 Now Available


CSA is thrilled to announce the release of the Certificate of Cloud Security Knowledge (CCSK) v5, the mark of the modern cybersecurity professional. This latest version of our vendor-neutral cloud security training is designed to help you demonstrate mastery of essential and up-to-date cloud security knowledge.

CCSK v5 builds upon the strong foundation of CCSK v4, offering substantial updates that provide a detailed understanding of modern cloud components and state-of-the-art security best practices. Key enhancements include:

  • Increased and Refined Focus Areas: Expanded coverage on Cloud Workloads, Serverless/FaaS, Application Security, CI/CD, DevSecOps, and Automation.
  • Strengthening Core Areas: Improved content across Governance,
    Auditing, Compliance, Organizational Security, IAM, and Incident Response.
  • New Additions: Integration of Artificial Intelligence
    (AI) and Generative AI, Zero Trust strategy, and explicit references to Data Lakes.

With CCSK v5, you gain access to the groundbreaking CCSK Orb chatbot, an interactive tool designed to help you master the body of knowledge and provide ongoing assistance in your daily challenges managing the roadblocks of a cloud security professional. This certificate remains the benchmark for cloud security expertise, equipping you to tackle both current and emerging security threats.

Explore CCSK v5

CSA HKM Knowledge Sharing Event – May 2023

The Knowledge Sharing Event in May will be focused on another hot topic – AI and Cloud computing again.

In the Knowledge Sharing Event on ChatGPT in March, our R&D Vice Chairman – Samuel NG mentioned that Cloud Security Alliance has published a document on Cybersecurity implications of ChatGPT and further publish that into a new research publication. This topic is still hot in the IT industry.

In the forthcoming event, we invited Kevin Liu, representative from Microsoft, to talk about another hot topic how to use AI to enhance our cybersecurity posture – Microsoft’s AI-Powered Copilot. Kevin Liu is also our Education Director. He will bring us to the Multicloud Security world.

Participants will claim 1 CPE

DATE: May 11, 2023 (Thursday)
TIME: 12:30 – 01:30 pm
FORMAT: Webinar (in Cantonese)
TOPIC: AI-Powered Copilot and Multicloud Security by Microsoft
LANGUAGE: Cantonese
SPEAKER: Kevin Liu, Security Technical Specialist, Microsoft and Education Director of Cloud Security Alliance (HK & Macau) Chapter

ABSTRACT:

Microsoft Security delivers new multicloud capabilities to help customers strengthen visibility and control across multiple cloud providers, workloads, devices, and digital identities. Microsoft Security Copilot, it is an AI-powered security analysis tool that enables analysts to respond to threats quickly, process signals at machine speed, and assess risk. Microsoft’s Cloud Infrastructure Entitlement Management (CIEM) solution helps organizations manage permissions and identities in the cloud. Microsoft’s Zero Trust approach to security helps organizations protect their data and resources by verifying every access request and enforcing least-privilege access principles. This sharing session will give you an overview on how Microsoft empowering Defenders with AI on security.

THE SPEAKER:

Kevin Liu is a Security, Compliance and Modern Work Technical Specialist in Microsoft. He has more than 20 years’ experience in providing advisory and solution consultation in CyberSecurity, Infrastructure and cloud for large companies across Asia Pacific region.

He is a speaker and demonstrator for major industry events in the APAC region including HKISS, APAC O2O digital resilience workshop and RSA Conference APAC.

Kevin worked for many different major IT vendors and solution provider including Microsoft, RSA Security, Symantec, Hewlett-Packard Enterprise and Orange Cyberdefense. Kevin is a CISSP, CEH and ITIL certified.

VIEW THE PRESENTATION: https://youtu.be/vZkS9IRv7z4

CSA HKM Knowledge Sharing Event – January 2023

Chinese New Year is coming and it is a good time to plan your learning process and schedule.

In this year the Cloud Security Alliance Hong Kong & Macau Chapter will continue to lead and conduct more cloud security and audit training. In February and March 2023, CSA HKM and Hatter Company Limited jointly organized two RTTP supported Cloud Security Training courses.

How to prepare, understand and get the best training that drives your career plan. In this Knowledge Sharing Event, Ricci Ieong, Vice-Chairman of Cloud Security Alliance (HK & Macau) chapter will share different context and direction of different cloud security trainings (such as CCSK, CCAK, CCSP).

Participants will claim 1 CPE.

DATE: January 31, 2023 (Tuesday)
TIME: 12:30 – 01:30 pm
FORMAT: Webinar
TOPIC: Plan your Cloud Security Training for this year
LANGUAGE: Cantonese
SPEAKER: Ricci IEONG, Vice Chairman of Cloud Security Alliance (HK & Macau Chapter)

AGENDA:

  • Comparison of different cloud security certificate/certification courses
  • Highlights about the different certificate examinations and preparation for examinations
  • Understand other Cloud Computing Training by Cloud Security Alliance
  • Special discount will be given to (selected) participants.

THE SPEAKER:

Dr. Ricci Ieong is one of the course developers and one of the four pioneer trainers of the CCAK course worldwide. Dr. Ieong is a qualified Certificate of Cloud Security Knowledge (CCSK) instructor and grandfathered to teach the Certificate of Cloud Auditing Knowledge (CCAK). He is also an authorized ISC2 Certified Cloud Security Professional (CCSP).

Apart from running his consulting business, Dr. Ieong delivers lectures in local universities. He is both an Adjunct Assistant Professor teaching Cybersecurity courses and an authorized trainer in AWS Academy in Hong Kong University of Science and Technology (HKUST). He teaches Applied Blockchain and Cryptocurrencies course at Chinese University of Hong Kong (CUHK).

Dr. Ieong is the Vice Chairman of professional development of Cloud Security Alliance (HK & Macau Chapter) and has served on CSA Cloud Incident Response Working Group and Certificate of Cloud Auditing Knowledge (CCAK) Working Group. He is an active speaker at numerous security events, including CSA summits, in Hong Kong and throughout APAC. He is one of the recipients of 2021 Ron Knode Service Award awarded by CSA.

REGISTRATION: https://csahkmkse2301.eventbrite.hk

Followup links to 15 sample questions from CCSK, CCSP and CCAK exam.

Christmas Gift for CSA HKM Members

World cup 2022 is completed and Christmas time is coming. Merry Christmas to all of you. We will have our knowledge sharing talk on 22 Dec 2022 (Thursday) as usual in lunch time. Don’t miss the opportunity to learn something from our China based Service Provider.

Other than knowledge sharing session, we would also like to announce some more Christmas gifts for all of you, our members, the CCAK and CCSK class discounts.

We will organize our second round CCAK training. Our CCAK 2 days training class will be conducted before end of this year on 28 – 29 Dec 2022. As a Christmas gift to our members, you can get 40% off Special Christmas discount for non-RTTP applicants.

There will be another CCAK 3 days training to be held on 3 – 5 Jan 2023 for more hands on training for Cloud Audit.

Besides, CSA (HK and Macau Chapter) together with Hatter Company Limited also achieved to get RTTP funding support for CCSK Training (with examination token). If you plan to take CCSK exam in the coming year, the actual amount you need to pay cover the examination token, course material and course lecture that you can learn more together. The CCSK training will be held on 20 – 21 Feb 2023 for CCSK Basic training (2 days) or 20 – 22 Feb 2023 CCSK Plus training (3 days).

You can always register through RTTP web site or contact the training vendor here.

More Trainings about Cloud Security in the Cloud Security Alliance

Last week, when I taught the CCSP class by ISC2 in Hong Kong Productivity Council, I discussed with the participants in our cloud journey about the upcoming trend in Cloud Security which are Cloud Data Security, Zero Trust and Cloud Audit.

Almost at the same time, Cloud Security Alliance published the new document about Cloud Data Security and Zero Trust Training.

Cloud Data Security is one of the most important elements within Cloud Security. So CSA published the Understanding Cloud Data Security and Priorities. This summarises what should be the priorities in defining cloud data security aspects. More details can be found in this link.

Zero Trust Technology is considered as one of the hot topics in this year. Many companies mentioned about their solutions related to Zero Trust. In fact, Zero Trust Technology is not just a specific product but a philosophy and mindset. CSA CTO Daniele Catteddu mentioned about this in both the ISSummit 2022 event and also in CSA HK & Macau Chapter Summit 2022 event that held this month. In the presentation, Daniele also mentioned that CSA is going to develop a micro training series which is open and free for everyone. So it is definitely a good time for us to learn online together.

In the event, Daniele also mentioned about Cloud Audit Training which is CCAK training. After some time, we (CSA and Hatter Company Limited) successfully get the CCAK and hopefully CCSK (another flagship training by Cloud Security Alliance) to be officially endorsed by VTC under the RTTP program. Our first public class will be held on 7 – 9 Nov, 2022 (virtually through zoom). Seats are still available for registration.

Lastly, CSA also prepared some Cloud Security for Financial Services webinar. So anyone can check in and join the webinar.

Happy Learning.

Certificate of Cloud Auditing Knowledge (CCAK) – More classes in Hong Kong and Macau

After announcing our first local class on Certificate of Cloud Auditing Knowledge (CCAK) class in Hong Kong, we received more official supports from VTC that more of our CCAK class are now officially accepted RTTP approved training programs (That is, 66% off from the listed price of the course).

In the coming 2 months, we will have 4 available CCAK classes that available for interested parties at different pace. 2 days, 3 days and weekly evening classes are available for different participants to take the class online.

In order to catch this training opportunity for yourself or your company offered by Cloud Security Alliance (HK & Macau) chapter and Hatter Company Limited, you can check the list of courses within the schedule CCAK class schedule.

If you are interested in registering the class, you can register in the RTTP web site or in Hatter Company CCAK class site.

More cloud security and audit class will be available soon.

Happy Learning.