How much does it cost?
Managed services are priced per user, per month, scoped to your headcount and environment — because a 12-person fund and a 90-person firm need very different things. Rather than a misleading headline rate, we run a short discovery, then send a written, costed proposal within two business days. As a guide, fully managed services in Hong Kong typically run within the market band for per-user monthly pricing; we'll show you exactly where you land.
Do we have to sign a long contract?
Our standard term is 12 months, billed quarterly in advance — long enough to do the work properly, not a multi-year lock-in. We also run alongside your current setup for the first 30 days: if you don't see the difference, you can walk away.
We already have an IT person or provider. Can you still help?
Yes — in two ways. We can take over completely, or extend and support your existing team (co-managed IT), covering the areas they don't have time or tooling for, such as security, backup and SFC compliance. The free assessment works either way and often simply confirms what your current provider has covered well and what's slipping.
What exactly is the free assessment?
A complimentary review of your IT and cybersecurity across the ten areas the SFC examines — a remote configuration scan plus a short on-site visit. You receive a written, RAG-rated findings report you keep regardless of whether you engage us. It's genuinely no-obligation; the report is useful on its own.
What does switching providers involve?
Less disruption than most firms expect. Our 30-day onboarding documents your environment, deploys monitoring and security, remediates the urgent gaps and hands over — usually with no downtime for your staff. We manage the transition from your current arrangement; you don't have to project-manage it.
Do we need to change our current systems or Microsoft 365?
No. We work with what you have — your Microsoft 365 tenant, your devices, your line-of-business apps. We secure and manage them properly rather than forcing a rip-and-replace. Where something is genuinely end-of-life or a security risk, we'll flag it and plan the change with you.
Who owns our data and documentation?
You do — always. Your Microsoft 365 tenant, your data and the documentation of your environment remain yours. If you ever leave, we hand everything over cleanly.
How does this help with the SFC and investor due diligence?
Our Compliance+ tier maps directly to the SFC's cybersecurity expectations and produces the evidence — asset inventory, tested backup, vendor due-diligence pack, incident-response plan — that both an SFC inspection and an investor's operational due diligence ask for. See the
SFC Compliance page for the full mapping.
How quickly do you respond when something breaks?
Every agreement carries a written SLA. Critical issues (P1) get a 30-minute response and continuous work until resolved; lower-severity issues have defined targets too. We measure and report against these monthly. Full table on the
Services page.
How do we get started?
Book the free assessment. We'll have a short discovery call, run the review, and send your findings report — then you decide. No pressure, no sales deck.
Get in touch →
Isn't a managed service more expensive than what we do now?
Usually not, once you count the hidden costs. Break-fix bills, staff downtime waiting for fixes, and one big incident add up fast — often more than a predictable monthly fee. The
downtime calculator on this page lets you see your own numbers; we'll show you exactly where you'd land.
We're a small firm — isn't this overkill?
No. Attackers and the SFC don't scale their expectations down for a smaller firm — and most breaches hit small businesses precisely because they assume they're too small to be a target. Our plans are right-sized and priced for a firm your size, not enterprise rates.
Why not just buy the security tools ourselves?
Tools only help if someone configures, watches and acts on them. Unmanaged tools give a false sense of safety — the licence is bought, but no one is minding it. We run them, prove they're working, and keep the evidence for your next inspection or investor review.