Built for SMEs. Ready for regulation.
Most of our clients have between 10 and 250 people and no full-time IT team. Some answer to a regulator, most don't. All of them get the same engineers, the same security baseline and the same attention.
Proper IT without an IT department.
Everything a growing team needs to work safely and reliably, with security built in from the start and room to scale.
Startups and scale-ups
Laptops, Microsoft 365, Wi-Fi and security set up right from day one, so you never have to unpick a messy setup later.
Typical needs · Device setup · M365 · Onboarding · Cyber insurance
Trading, retail and manufacturing
Warehouses, shops and factories that depend on ERP, point of sale, CCTV and networks staying up every day.
Typical needs · ERP servers · Networks · CCTV · Backup
Events, hospitality and creative
Fast-moving teams that need cloud platforms stood up quickly, reliable remote working and support that responds when deadlines are tight.
Typical needs · Cloud hosting · Remote access · Large file sharing
Professional services
Accounting, tax, consulting and advisory firms growing across borders who want one partner for every office, and client data kept confidential.
Typical needs · Secure file sharing · Multi-office · Client audits
Regional offices of international groups
Asian branches that need local engineers to deliver to head-office standards and work smoothly with a global IT team.
Typical needs · Local hands · Global standards · Integration
Where a breach is a regulatory event.
Small and mid-sized firms that carry big-firm obligations: client confidentiality, record keeping, and regulators who ask hard questions.
Asset and wealth managers
Fund managers, family offices and advisers who need trading systems up, communications archived and cyber controls that satisfy licensing conditions.
Typical needs · Licensing controls · Records · MDR · Pen testing
Brokers and banks
Regional branches of global institutions that need local engineers to meet head-office standards without interrupting client service.
Typical needs · Resilience · Change control · Audit evidence
Law firms
Partnerships that hold privileged client data and need secure document management, strict access control and fast support for fee earners.
Typical needs · Document security · Access control · Data loss prevention
Controls your regulator will accept.
Licensed and authorised firms get everything in our standard service, plus the controls, records and reporting that supervisors and auditors expect to see.
Controls mapped to your rulebook
Access control, monitoring, change management and incident handling aligned to SFC, HKMA, MAS, Bank Negara, BSP or JFSA expectations.
Audit-ready evidence
Reports, logs and documentation prepared for internal audit, external auditors and regulator inspections.
Communications and records
Email and Teams retention and archiving set up to support your record-keeping obligations.
Incident and notification support
Containment, recovery and help preparing notifications to regulators, clients and insurers.
Outsourcing and vendor oversight
Documentation for your outsourcing register and due diligence on the technology vendors we manage for you.
CISO-level reporting
Regular cyber risk reporting for directors, responsible officers and compliance teams.
The rulebooks our clients answer to.
Our controls, documentation and reporting are mapped to the regulatory and privacy frameworks in each market where we work.
| Market | Framework | How we help |
|---|---|---|
| Hong Kong | SFC | Cyber and IT controls expected of licensed corporations, including access control, monitoring and incident handling. |
| Hong Kong | HKMA C-RAF | Technology and cyber resilience controls for authorised institutions and their branches. |
| Singapore | MAS TRM | Technology risk management controls, resilience testing and outsourcing oversight. |
| Malaysia | Bank Negara RMiT | Risk management in technology requirements for financial institutions. |
| Philippines | BSP | Information technology and cyber risk management expectations for BSP-supervised financial institutions. |
| Japan | JFSA | Cybersecurity expectations for financial firms operating in Japan. |
| Region | PDPO · PDPA · APPI · DPA · GDPR | Personal data protection in Hong Kong, Singapore, Malaysia, Japan, the Philippines and for EU clients. |
| Any sector | ISO 27001 · Cyber insurance | Readiness for certification, insurer questionnaires and client security reviews. |
Not sure where your gaps are?
Book a free IT and security review with a senior consultant.