top of page

Member of the Month | Mr. John Wan: Turning Technology Risk into Business Resilience

20 hours ago
4 min read

This month, the Hong Kong China Network Security Association (HKCNSA) is pleased to feature Mr. John Wan as our Member of the Month.


With more than 15 years of experience across technology, information security, and financial services, John has spent much of his career helping organisations navigate technology risk, regulatory expectations, and cybersecurity governance. Having worked across Hong Kong, Mainland China, and Singapore, he has developed a practical understanding of how businesses can build resilience while operating in increasingly complex regulatory and technology environments.



Translating Technology Risk into Business Language

Reflecting on his experience working with regulators, risk functions, senior executives, and boards, John believes one of the biggest challenges in technology risk management is not identifying risks, but helping business leaders understand them.


Technical vulnerabilities, security weaknesses, and control gaps mean little if they cannot be connected to real business consequences. Throughout his career, John has focused on helping organisations translate technical issues into business risks that executives can understand, evaluate, and act upon.


He also points out that while many regulatory requirements may appear similar on paper, the underlying priorities often differ across jurisdictions. Working across Hong Kong, Mainland China, and Singapore has taught him the importance of understanding local expectations, cultural perspectives, and regulatory priorities rather than relying solely on a one-size-fits-all approach.


Another lesson he has learned is the value of transparency and early engagement. According to John, regulators increasingly appreciate open dialogue and proactive communication, particularly when organisations are introducing new technologies or operating across multiple jurisdictions. Building trust early often makes navigating future challenges significantly easier.



From Preventing Incidents to Building Resilience

John believes organisations need to rethink what effective cybersecurity looks like today.

As artificial intelligence lowers the barriers for attackers and accelerates the speed of cyber threats, the traditional goal of preventing every incident becomes increasingly difficult to achieve. Instead, organisations should be prepared for the reality that cyber incidents will eventually occur.


This is where the concept of “Assume Breach” becomes critical.


"A cybersecurity incident is a matter of when, not if."


In John's view, cyber resilience is no longer measured solely by an organisation's ability to prevent attacks. It is measured by how quickly the organisation can recover, maintain customer confidence, satisfy regulatory expectations, and minimise operational disruption when an incident occurs.


He also highlights the growing importance of third-party risk. As organisations continue to expand their digital ecosystems through cloud services, outsourcing arrangements, and strategic partnerships, vendor risk can no longer be treated as an annual compliance exercise. Continuous monitoring and ongoing assessment are becoming essential components of modern risk management programmes.



Preparing Governance for Emerging Technologies

The rapid adoption of artificial intelligence and machine learning is creating new opportunities, but also new responsibilities.


John notes that organisations must establish appropriate governance frameworks that address issues such as data privacy, model governance, accountability, and emerging threat vectors. However, AI is only one part of a much broader technology evolution.


Looking ahead, he expects technologies such as robotics and quantum computing to introduce additional governance challenges. Organisations therefore need governance models that are both standardised and adaptable, allowing them to evaluate and adopt new technologies without rebuilding risk frameworks from scratch each time.


At the same time, the role of information security assurance is evolving.


Rather than relying solely on periodic audits and point-in-time assessments, organisations are increasingly moving toward continuous monitoring, automated assessments, and data-driven control validation. The goal is to identify weaknesses early and address them before they can be exploited.



Security Should Enable Innovation

For John, strong governance should never become a barrier to innovation.


He believes security works best when it is embedded early through a Security by Design approach. When security requirements are incorporated from the beginning, businesses are able to innovate with greater confidence while maintaining appropriate risk controls.


Over the past fifteen years, he has watched information security evolve from a relatively small technical function into a strategic business discipline. Today's technology risk and security professionals need more than technical expertise. They must understand business objectives, communicate effectively with stakeholders, and keep pace with rapidly changing technologies and regulations.


His advice to aspiring technology risk and cybersecurity professionals is straightforward: do not focus exclusively on certifications. Take the time to understand how organisations operate, develop strong communication skills, and maintain a commitment to continuous learning.





Conclusion

Mr. John Wan's experiences reflect a broader shift taking place across the industry. Technology risk management is no longer simply a compliance function; it has become a critical component of organisational resilience.


As technologies continue to evolve and regulatory environments grow more complex, organisations will increasingly rely on professionals who can bridge technology, governance, and business priorities. By helping organisations turn technology risk into business resilience, John continues to contribute valuable insights to the cybersecurity and risk management community.


HKCNSA is pleased to feature Mr. John Wan as our Member of the Month and looks forward to his continued contributions to information security governance, technology risk management, and cyber resilience.

 

Hong Kong China Network Security Association

8/F, 208 Johnston, Wan Chai, Hong Kong

+852 9169 0693

  • LinkedIn
  • WeChat

Copyright © 2026 HKCNSA. All rights reserved.

Thank you for your enquiry. HKCNSA Secretariat will contact you soon.

bottom of page