Subscribe

Social Media Links

Experts & Advisors

Xiangrui Kong

Managing Director

Photograph of Xiangrui Kong

Suite 1901, Two Taikoo Place, 979 King’s Road
Quarry Bay, Hong Kong SAR, China

+852.3002.2000 Main
+852.3002.2009 Direct

Get in touch

Xiangrui Kong is a Managing Director at Ankura based in Hong Kong, advising organizations across APAC on digital forensics, incident response, and cyber investigations. He leads complex, cross-border matters including ransomware, network intrusions, large-scale data breaches, intellectual property theft, and business email compromise, translating technical findings into clear, defensible conclusions for executives, boards, counsel, insurers, and regulators. Xiangrui helps clients contain incidents, restore operations, strengthen controls, and support civil, criminal, and regulatory proceedings when required. He is a frequent speaker on digital forensics, incident response and delivers training workshops for professional communities.

Experience

Xiangrui is a Certified Information Systems Security Professional (CISSP), EnCase Certified Examiner (EnCE), and a CREST Practitioner Intrusion Analyst (CPIA). He holds the Cellebrite Mobile Forensics Fundamentals (CMFF) and Certified Physical Analyst (CCPA) certificates, alongside the following SANS GIAC certificates: Certified Forensic Analyst (GCFA), Certified Incident Handler (GCIH), Certified Defending Advanced Threats (GDAT), and Certified Reverse Malware Engineering (GREM).

Xiangrui has delivered on notable projects in many different industries and for a variety of investigations, including:

  • Led proactive cyber risk engagements and threat-led reviews, surfacing previously undetected compromises and enabling early containment.
  • Directed incident response for organizations targeted by organized cybercrime, coordinating investigation, stakeholder communications, and remediation planning.
  • Oversaw complex, multi-workstream investigations, aligning technical activity with legal, regulatory, and executive reporting requirements.
  • Managed sensitive internal investigations involving suspected data or intellectual property misappropriation, supporting leadership and counsel with clear, defensible findings.
  • Advised on account compromise and payment diversion matters, helping clients strengthen identity controls and reduce business email compromise exposure.
  • Delivered enterprise data security reviews, prioritizing practical improvements to governance, controls, and monitoring.
  • Supported organizations through high-impact ransomware and extortion events, guiding containment, recovery, and post-incident resilience enhancements.
Education
  • MSc, The University of Hong Kong
Certifications
  • Certified Information System Security Professional (CISSP)
  • CREST Practitioner Intrusion Analyst (CPIA)
  • SANS GIAC Certificate – GCFA, GCIH, GDAT, GREM
  • EnCase Certified Examiner (EnCE)
  • Cellebrite – CMFF and CCPA
Affiliations
  • High Technology Crime Investigation Association (HTCIA)

Let’s Connect

We solve problems by operating as one firm to deliver for our clients. Where others advise, we solve. Where others consult, we partner.

I’m interested in
I need help with