PUBLIC SECTOR

Company Profile

A Hong Kong government agency responsible for formulating policies on digital government, data governance, and information technology is driving the adoption of emerging technologies to enhance public services and operational efficiency. With AI increasingly integrated into core processes, maintaining data security, transparency, and compliance has become essential to sustaining public trust in digital transformation.


To support this mission, the organization initiated a security assessment of its AI-based log analytics and monitoring platform, a system that uses AI models to analyze large volumes of operational logs, identify anomalies, and detect potential cybersecurity threats. 

Challenges

The platform processes extensive system logs from multiple security monitoring platforms daily  , making manual analysis inefficient and prone to oversight. As AI systems became integral to security monitoring and alerting, prioritizing their resilience, accuracy, and compliance under stringent government standards became a key objective.


Challenges included validating the system’s security posture, managing the risks of data exposure or model bias, and ensuring compliance with the OWASP AI Top 10 and local policy standards, such as G3 and S17. The organization also needed to demonstrate adherence to the Protection of Critical Infrastructures (Computer Systems) Ordinance while operating in a high sensitivity environment.

Solutions

With support from LPS, a comprehensive AI Security Assessment was conducted to evaluate and enhance the system’s security, transparency, and governance controls. The assessment covered Security Risk and Assessment Analysis (SRAA), Privacy Impact Assessment (PIA), and penetration testing for both the AI log analytics and message push service platforms.


Using the OWASP AI Top 10 , an internationally recognized framework that outlines the most critical security risks in AI system, the initiative identified potential vulnerabilities in AI model logic, data integrity, bias handling, and explainability. The review also assessed alignment with government standards and CI policies.


A secure dashboard was developed to visualize AI-generated log insights, highlight priority security issues, and track remediation progress. The findings guided immediate architectural improvements and laid the foundation for continuous, automated compliance monitoring.


Value created

The AI Security Assessment enhanced visibility into system risks, strengthened data protection, and reinforced compliance with all government and CI regulations. By validating the system’s security controls and governance practices, the initiative fundamentally increased confidence in using AI to handle sensitive public sector data.


The resulting framework provides a repeatable, scalable model for assessing and securing AI systems, enabling safer, more transparent, and policy-aligned AI adoption across critical government environments.

 *fields are mandatory

DOWNLOAD PDF

contact us icon

Let's Connect!

Interested in LPS or seeking further details? We're here to help.

Please fill out the form below.

Name is required
Title is required
Company is required
Company Email is required
Tel is required
Enquiries is required

Submit