IT & information security
Penetration test findings, cloud configuration, access review evidence, AI tool usage, and incident reporting routes.
What you are likely asking
- What evidence will the auditor actually ask to see?
- What is the difference between a scan and a penetration test?
- How do we stop staff pasting client data into AI tools?
You are handed the questionnaire and asked to answer it.
Written for you
AI governance
What the agent sandbox escape means for your AI governance
AI governance
Does Hong Kong have an AI law? What actually applies in 2026
AI governance
What the PCPD AI framework asks you to do, in practice
IT audit
ITGC explained for finance teams who have just been asked for evidence
AI governance
The PCPD's guidance on agentic AI: what it asks you to control
AI governance
ISO 42001 or ISO 27001 — which comes first?
AI governance
A practical AI use inventory: what to record and why
Hong Kong regulatory
SFC sets a July 2027 deadline for phishing-resistant authentication
Hong Kong regulatory
Cap. 653: what the code of practice asks designated operators to evidence
Hong Kong regulatory
Cap. 653 is in force: are you a critical infrastructure operator?
Not sure which applies to you?
Tell us what triggered this and we will tell you whether we are the right firm.