Services Catalogue

Detailed information for all 52 services across 3 domains — click any card to expand details.

AI-Powered
AI-Powered
Advanced AI accelerates initial analysis, drafting and pattern detection, reducing turnaround time and cost while maintaining depth and accuracy throughout the engagement.
Expert Human Review
Expert Human Review
Every deliverable is reviewed and refined by seasoned consultants with deep industry and domain expertise, ensuring accuracy and practical relevance.
Service Guarantee
Service Guarantee
Payment is held in escrow and released only upon your acceptance; if the work falls short of the standard, we assign a replacement consultant at no additional cost.
AI Advisory

AI Advisory & Development

AI strategy, governance, risk and ethics services to help you deploy artificial intelligence responsibly and effectively.

12 services
AI-01 · AI Management
AI Governance Assessment
HK$13,800
AI governance is moving from voluntary to mandatory. Organisations deploying AI without governance frameworks face regulatory, ethical and reputational risk.
Order →
What We Do

Assessment of AI governance maturity against NIST AI RMF, ISO 42001 and PCPD AI Guidance. Covers: AI inventory, risk classification, accountability structures, transparency mechanisms, human oversight and bias management.

Deliverable

AI governance maturity report with scored assessment, gap analysis, governance framework recommendations and board-ready executive summary.

AI-02 · AI Management
AI Risk & Bias Audit
HK$14,800
Algorithmic bias can lead to discrimination, regulatory penalties and brand damage. An independent audit demonstrates due diligence and responsible AI practices.
Order →
What We Do

Technical audit of AI/ML models: bias testing across protected characteristics, fairness metrics (equal opportunity, demographic parity), explainability analysis and robustness testing against adversarial inputs.

Deliverable

AI audit report with bias findings, fairness metrics dashboard, model card documentation and remediation recommendations.

AI-03 · AI Management
AI Employee Usage Policy
HK$5,800
Shadow AI – employees using unapproved AI tools – is one of the fastest-growing enterprise risks. A policy establishes boundaries before incidents occur.
Order →
What We Do

Development of a comprehensive AI Employee Usage Policy covering: approved AI tools, prohibited use cases (sensitive data, IP, customer PII), data classification rules, review and approval processes and consequences for violations.

Deliverable

AI Usage Policy document (editable), quick-reference staff guide, department head briefing notes and implementation checklist.

AI-04 · AI Management
AI Security Testing
HK$16,800
AI systems introduce novel attack surfaces: prompt injection, model inversion, data poisoning and adversarial examples. Traditional security testing does not cover these.
Order →
What We Do

AI-specific security testing following OWASP Top 10 for LLM Applications and MITRE ATLAS framework. Covers: prompt injection, jailbreaking, training data extraction, model theft, supply chain vulnerabilities and plugin security.

Deliverable

AI security assessment report with vulnerability findings, threat modelling output, attack scenarios and remediation guidance.

AI-05 · AI Management
AI Vendor Selection Support
HK$8,800
The AI vendor market is crowded and opaque. Most vendors promise more than they deliver. Structured evaluation reduces the risk of expensive procurement mistakes.
Order →
What We Do

Development of AI vendor evaluation criteria: security requirements, data handling, model transparency, SLA review, exit strategy. Assessment of up to 3 shortlisted vendors against the criteria, with scoring and recommendations.

Deliverable

Vendor evaluation framework document, scored vendor comparison matrix, recommendations report and due diligence checklist.

AI-06 · AI Management
Agentic AI Risk Assessment
HK$16,800
Agentic AI systems that can take autonomous actions (execute code, send emails, access databases) represent an entirely new risk category. The potential blast radius is orders of magnitude larger.
Order →
What We Do

Risk assessment of agentic AI deployments: autonomy boundaries, action approval chains, credential management, sandbox effectiveness, logging and audit trail completeness and rollback capability. Aligned to emerging regulatory guidance.

Deliverable

Agentic AI risk assessment report, threat model, control framework recommendations and board-ready risk summary.

AI-07 · AI Management
Gen AI Guideline Compliance
HK$13,800
Regulators worldwide are issuing generative AI guidelines. Organisations using or developing Gen AI must demonstrate alignment with these evolving standards.
Order →
What We Do

Compliance assessment against key Gen AI regulatory frameworks: EU AI Act (provisional), China Gen AI Measures, PCPD AI Guidance and Singapore AI Verify. Covers training data governance, content labelling and transparency requirements.

Deliverable

Gen AI compliance report with regulatory mapping, gap analysis, compliance roadmap and staff Gen AI usage guidelines.

AI-08 · AI Management
AI Ethics Framework Development
HK$14,800
Ethics frameworks operationalise responsible AI principles into actionable policies. Without one, "responsible AI" remains a slogan, not a practice.
Order →
What We Do

Development of a bespoke AI Ethics Framework covering: fairness, transparency, accountability, privacy, safety and human-centric values. Includes stakeholder workshops, principle definition, operational guidelines and governance structures.

Deliverable

AI Ethics Framework document, principle-to-practice mapping, ethics review board terms of reference and implementation roadmap.

AI-09 · AI Management
AI Governance Training
HK$8,800
AI governance is new territory for most boards and management teams. Targeted training builds the competency needed to provide effective oversight.
Order →
What We Do

Half-day or full-day AI governance training for board members and senior management. Covers: AI risk landscape, regulatory developments, governance frameworks (NIST AI RMF, ISO 42001), board oversight responsibilities and case studies.

Deliverable

Training slide deck (editable), participant workbook, case study materials, completion certificates and a management briefing report.

AI-10 · AI Management
AI Procurement Framework
HK$9,800
Procuring AI systems without a framework leads to inconsistent vendor assessment, hidden risks and compliance blind spots.
Order →
What We Do

Development of an AI Procurement Framework: pre-procurement risk classification, mandatory due diligence checklist, contract clause library (data rights, model access, audit rights, termination) and post-procurement monitoring process.

Deliverable

AI Procurement Framework document, due diligence template, contract clause library and procurement workflow diagram.

AI-11 · AI Management
AI Incident Response Plan
HK$13,800
AI systems introduce attack surfaces that traditional incident response does not cover: prompt injection, model compromise, training data poisoning and AI-enabled fraud. When an AI incident hits, a pre-agreed playbook decides the damage.
Order →
What We Do

Assess exposure to AI-specific incident scenarios and review current response capability against them. Develop a tailored AI Incident Response Plan aligned with your existing IR framework, covering roles, escalation, evidence handling and regulatory notification. Validate the plan with a facilitated online tabletop exercise.

Deliverable

AI Incident Response Plan document (editable), AI incident scenario register with severity classification, detection and escalation playbooks per scenario, online tabletop exercise (half-day) and after-action report.

AI-12 · AI Management
AI Adoption Strategy
HK$8,800
Most organisations adopt AI without a plan - tools multiply, governance is improvised and value is hard to prove. A short strategy engagement prevents wasted spend and sets measurable success criteria.
Order →
What We Do

Identify where AI adds most value for your business: efficiency, product or customer experience. Assess current AI usage, data readiness and staff capability to set a realistic baseline. Develop a phased adoption roadmap with quick wins in the first 90 days, governance touchpoints and success metrics. Deliverables are agreed at kick-off and vary with your starting point.

Deliverable

AI Adoption Strategy document with phased roadmap, AI opportunity map (quick wins vs strategic bets), data and tool readiness checklist, 90-day action plan with success metrics.

Governance

Governance & Risk Assessment

Governance frameworks, risk assessments and compliance services to keep your organisation secure and accountable.

14 services
GOV-01 · Governance & Risk
Strategic Advisory (Board)
HK$20,000/session
Boards face increasing pressure to demonstrate technology and cyber governance competency. Independent strategic advisory bridges the knowledge gap between technology and governance.
Order →
What We Do

Board-level strategic advisory on an on-demand basis. Covers: technology strategy alignment, cyber risk appetite definition, digital transformation governance, regulatory horizon scanning and technology investment prioritisation.

Deliverable

Board briefing pack per session, action items log, risk dashboard update and follow-up advisory note.

GOV-02 · Governance & Risk
Management Consulting (On-Demand)
HK$8,000/day
SMEs often need senior-level technology and security advice without the overhead of a full-time hire. On-demand consulting provides flexible, high-impact advisory.
Order →
What We Do

On-demand management consulting across technology, security and privacy domains. Typical engagements: strategy development, operating model design, transformation roadmap, vendor negotiations advisory and organisational design.

Deliverable

Agreed deliverables per engagement – typically a strategy document, roadmap or assessment report with executive summary.

GOV-03 · Governance & Risk
IT Vendor Selection Support
HK$8,800
IT procurement decisions have multi-year implications. A structured vendor selection process reduces the risk of lock-in, hidden costs and capability mismatches.
Order →
What We Do

End-to-end vendor selection support: requirements definition, RFP document creation, vendor shortlisting, proposal evaluation against weighted criteria, demo/presentation scoring and final recommendation report.

Deliverable

Requirements specification, RFP document, vendor evaluation matrix with scores and final recommendation report with rationale.

GOV-04 · Governance & Risk
RFP / Tender Document Creation
HK$4,800
Well-structured RFP documents attract better responses and simplify evaluation. Poorly written RFPs lead to misaligned proposals and procurement delays.
Order →
What We Do

Creation of professional RFP/tender documents for technology, security or privacy services. Covers: scope definition, technical requirements, evaluation criteria, pricing structure, service levels and contractual terms.

Deliverable

Complete RFP/tender document (Word/PDF), evaluation criteria matrix and proposer Q&A template.

GOV-05 · Governance & Risk
Post-Implementation Review
HK$7,800
Most IT projects fail to deliver expected benefits. A post-implementation review identifies what went well, what did not and how to improve future delivery.
Order →
What We Do

Independent post-implementation review of technology, security or privacy projects. Covers: delivery against scope, budget and timeline; benefits realisation; user adoption; lessons learned; and recommendations for future projects.

Deliverable

Post-implementation review report, benefits realisation assessment, lessons-learned register and improvement recommendations.

GOV-06 · Governance & Risk
IT Cost Optimisation Assessment
HK$9,800
IT costs often grow unchecked across shadow IT, unused licences and inefficient architectures. A structured review typically identifies 15–30% in savings opportunities.
Order →
What We Do

Review of IT spend: software licensing, cloud consumption, SaaS subscriptions, hardware maintenance and managed services. Benchmarking against industry peers and identification of consolidation, renegotiation and optimisation opportunities.

Deliverable

IT cost optimisation report with saving opportunities ranked by impact and effort, total cost of ownership models and an implementation roadmap.

GOV-07 · Governance & Risk
System Architecture Review
HK$16,800
Legacy system architectures accumulate technical debt. An independent architecture review identifies scalability, security and maintainability risks before they become incidents.
Order →
What We Do

Review of system architecture covering: scalability, resilience, security, data architecture, integration patterns, technology stack fitness and alignment with business goals. Produces a modernisation roadmap.

Deliverable

Architecture assessment report with current-state and target-state diagrams, risk register, modernisation roadmap and executive summary.

GOV-08 · Governance & Risk
Industry Risk Appetite Advisory & Assessment
HK$15,000/session
Regulators and boards increasingly expect explicit risk appetite statements tailored to the industry. Generic wording fails in scrutiny; industry-specific tolerance levels are what auditors and directors look for.
Order →
What We Do

Establish risk appetite in industry-specific terms, aligned to regulatory expectations and board accountability. Facilitate board-level workshops to define risk tolerance statements across technology, cyber and AI risk. Assess current posture against the agreed appetite and produce a gap view with escalation triggers.

Deliverable

Industry risk appetite statement (board-approved wording), risk tolerance matrix for technology, cyber and AI domains, board workshop facilitation (one session) and minutes, posture vs appetite gap report with escalation triggers.

RM-01 · Governance & Risk
Business Impact Analysis (BIA)
HK$18,800
A BIA is the foundation of business continuity. It identifies which processes are critical, what the impact of disruption would be and what recovery priorities should be.
Order →
What We Do

End-to-end Business Impact Analysis: process identification, impact assessment (financial, operational, regulatory, reputational), recovery time objectives (RTO) and recovery point objectives (RPO) definition and criticality ranking.

Deliverable

BIA report with process criticality matrix, RTO/RPO recommendations per process, dependency map and executive summary.

RM-02 · Governance & Risk
Business Continuity Plan
HK$11,800
A documented and tested BCP is a regulatory requirement under multiple frameworks. Without one, a single incident can escalate into an existential threat.
Order →
What We Do

Development of a comprehensive Business Continuity Plan covering: crisis management structure, communication protocols, recovery procedures for critical processes, alternate site arrangements and resource requirements. Aligned to ISO 22301.

Deliverable

BCP document, crisis communication templates, team contact cards and a BCP maintenance schedule.

RM-03 · Governance & Risk
Crisis Communication Plan
HK$7,800
Poor communication during a crisis amplifies damage. A pre-prepared crisis communication plan ensures stakeholders receive accurate, timely information when it matters most.
Order →
What We Do

Development of a Crisis Communication Plan: stakeholder mapping, communication channels, message templates for different scenarios (data breach, service outage, regulatory action), spokesperson designation and media handling guidelines.

Deliverable

Crisis Communication Plan document, message template library, stakeholder contact matrix and spokesperson briefing guide.

RM-04 · Governance & Risk
Security Risk Assessment & Audit (SRAA)
HK$16,800
Regulated industries and government contracts increasingly mandate independent security risk assessments. An SRAA provides a defensible, standards-based risk picture.
Order →
What We Do

Comprehensive security risk assessment following ISO 27005 methodology: asset identification, threat and vulnerability assessment, risk analysis (likelihood × impact), risk treatment recommendations and residual risk acceptance.

Deliverable

SRAA report with asset register, threat catalogue, risk register with risk ratings, risk treatment plan and executive summary.

RM-05 · Governance & Risk
Ransomware Preparedness Assessment
HK$8,800
Ransomware is the most disruptive cyber threat facing SMEs. A preparedness assessment identifies gaps in prevention, detection, response and recovery before an attack occurs.
Order →
What We Do

Assessment of ransomware preparedness across the NIST CSF functions: Identify (asset inventory, risk assessment), Protect (backups, access control, awareness), Detect (monitoring, alerting), Respond (IR plan, containment), Recover (restoration, communications).

Deliverable

Ransomware preparedness report with maturity scores per NIST function, gap analysis, prioritised improvement roadmap and board-ready summary.

CP-01 · Governance & Risk
PCIDSS Readiness Assessment
HK$15,800
PCI DSS v4.0 introduces significant new requirements. A readiness assessment identifies gaps before a formal assessment, saving time, cost and the risk of non-compliance findings.
Order →
What We Do

Assessment against PCI DSS v4.0 requirements: scoping validation, gap analysis across all 12 requirements, compensating control evaluation and remediation planning. Covers both merchant and service provider requirements.

Deliverable

PCI DSS readiness report with requirement-by-requirement findings, gap analysis, remediation plan with priorities and SAQ determination guidance.

Cybersecurity

Cybersecurity & Privacy

Cyber resilience, data protection and privacy services to defend against modern threats.

26 services
CS-01 · Cybersecurity
Cybersecurity Health Check
HK$4,800
Many SMEs lack visibility into their security posture. This is a low-risk, high-value entry point that identifies critical gaps before they become incidents.
Order →
What We Do

A structured assessment covering 12 security domains: access control, network security, endpoint protection, patch management, backup, incident response, third-party risk, physical security and more. Includes automated scans and manual review by a certified practitioner.

Deliverable

Executive summary report with risk ratings (High/Medium/Low), a prioritised remediation roadmap and a one-page dashboard for board presentation.

CS-02 · Cybersecurity
Vulnerability Assessment
HK$6,800
Unpatched vulnerabilities are the number one attack vector. Regular assessments are required by most compliance frameworks and cyber insurance policies.
Order →
What We Do

Automated vulnerability scanning of internal and external network assets, web applications and cloud configurations. Manual validation of findings to eliminate false positives. Includes CVSS scoring and exploitability analysis.

Deliverable

Detailed vulnerability report with CVSS scores, affected assets inventory, remediation steps ranked by criticality and an executive summary.

CS-03 · Cybersecurity
Penetration Test (Web Application + API)
HK$12,800
OWASP Top 10 web testing plus API endpoint testing included in the standard scope. A manual penetration test simulates real attacker behaviour and finds logic flaws that automated scanners miss.
Order →
What We Do

Manual penetration testing following OWASP Testing Guide v4. Covers injection flaws, broken authentication, sensitive data exposure, XXE, broken access control, security misconfiguration, XSS, insecure deserialisation and more. Performed by CREST-certified or OSCP-certified testers.

Deliverable

Full penetration test report with proof-of-concept exploits, risk impact analysis, remediation guidance per finding and a stakeholder presentation deck.

CS-04 · Cybersecurity
Security Policy Review & Creation
HK$6,800
Policies are the foundation of any security program. Without clear, enforceable policies, technical controls lack organisational authority.
Order →
What We Do

Review of existing security policies against ISO 27001 / NIST standards or creation of new policies from templates tailored to your business. Covers: Acceptable Use, Access Control, Password, Incident Response, Data Classification and more.

Deliverable

Gap analysis of existing policies, updated or newly drafted policy documents in editable format, implementation checklist and staff communication templates.

CS-05 · Cybersecurity
Security Architecture Review
HK$16,800
Architecture decisions made early compound over time. A flawed architecture creates systemic risk that no amount of patching can fix.
Order →
What We Do

End-to-end review of your security architecture: network segmentation, identity and access management architecture, data flow diagrams, cloud security controls, logging and monitoring architecture. Aligned to TOGAF and SABSA frameworks.

Deliverable

Architecture assessment report with risk-annotated diagrams, a prioritised remediation roadmap and executive summary.

CS-06 · Cybersecurity
Supply Chain / Vendor Risk Management
HK$8,800
Third-party breaches are surging. Your security is only as strong as your weakest vendor. Regulators increasingly demand vendor due diligence.
Order →
What We Do

Vendor risk assessment framework implementation: classification criteria, risk tiering, due diligence questionnaires, ongoing monitoring process. Review of up to 10 critical vendors. Includes contract clause templates for security requirements.

Deliverable

Vendor risk management framework document, vendor risk register, sample completed assessments for up to 3 vendors and a board-ready summary.

CS-07 · Cybersecurity
Cloud Security Assessment
HK$14,800
Cloud misconfigurations are the leading cause of cloud data breaches. Most organisations use only a fraction of available cloud security controls.
Order →
What We Do

Assessment of cloud environment (AWS/Azure/GCP) against CIS Benchmarks and cloud provider Well-Architected Frameworks. Covers IAM, network security, encryption, logging, backup and cost optimisation. Includes automated scanning where applicable.

Deliverable

Cloud security posture report with misconfiguration findings, compliance mapping, remediation playbook and architecture improvement recommendations.

CS-08 · Cybersecurity
Phishing Simulation & Awareness Campaign
HK$7,800
Humans remain the weakest link. Phishing is the initial access vector in over 90% of data breaches. Regular simulation measurably reduces click rates.
Order →
What We Do

Design and execution of a phishing simulation campaign: 3 staged emails over 2 weeks with increasing sophistication. Includes landing page capture, click-rate metrics and a post-campaign awareness training session for all staff.

Deliverable

Campaign results report with click rates by department, benchmark comparison, lesson-learned summary and training completion certificates.

CS-09 · Cybersecurity
Data Backup & Recovery Assessment
HK$6,800
Ransomware attacks target backups first. Many organisations discover their backups are unusable only during an actual incident – when it is too late.
Order →
What We Do

Review of backup strategy, retention policies, off-site storage, recovery time objectives (RTO) and recovery point objectives (RPO). Includes restore testing of a sample dataset to verify recoverability.

Deliverable

Backup maturity assessment report, gap analysis against 3-2-1 backup best practices, RTO/RPO recommendations and a tested restore procedure document.

CS-10 · Cybersecurity
Endpoint Security Review
HK$7,800
Endpoints are the frontline of defence. With remote and hybrid work, the endpoint attack surface has expanded dramatically.
Order →
What We Do

Review of endpoint protection configuration across Windows, macOS and mobile devices. Covers: EDR/XDR deployment, patch management, device encryption, USB control, application whitelisting and MDM policies.

Deliverable

Endpoint security assessment report, configuration hardening guide and a prioritised remediation plan.

CS-11 · Cybersecurity
Email Security Assessment
HK$6,800
Email is the primary delivery mechanism for malware, phishing and business email compromise (BEC). SPF/DKIM/DMARC misconfiguration leaves your domain open to spoofing.
Order →
What We Do

Assessment of email security controls: SPF, DKIM, DMARC configuration review, email gateway configuration, anti-spam and anti-malware effectiveness and BEC protection maturity.

Deliverable

Email security report with DMARC compliance score, configuration gaps, impersonation risk rating and step-by-step remediation guide.

CS-12 · Cybersecurity
Incident Response Plan + Tabletop Exercise (Online)
HK$10,800
The average cost of a data breach is 40% lower for organisations with a tested IR plan. Most plans fail on first contact with reality.
Order →
What We Do

Development or review of an Incident Response Plan aligned to NIST SP 800-61. Includes a half-day tabletop exercise (TTX) simulating a ransomware scenario with key stakeholders. Debrief and after-action report.

Deliverable

Updated IR Plan document, TTX scenario pack, after-action report with findings and recommendations and an improvement roadmap.

CS-13 · Cybersecurity
Security Awareness Training
HK$8,800
Compliance frameworks (ISO 27001, PCI DSS, PDPO) mandate regular security awareness training. Well-trained staff are your best defence.
Order →
What We Do

Customised security awareness training session (half-day or full-day) covering: phishing, password hygiene, social engineering, clean desk policy, remote work security and incident reporting. Includes interactive quizzes and scenarios.

Deliverable

Training slide deck (editable), attendance records, quiz results summary, training completion certificates and a management report.

CS-14 · Cybersecurity
CISO-as-a-Service (Monthly Retainer)
HK$18,000/mo
Not every SME can afford a full-time CISO. CISO-as-a-Service provides strategic security leadership on a fractional basis – board-ready, on-demand.
Order →
What We Do

Monthly retainer including: virtual CISO attendance at management meetings, security strategy development, policy oversight, vendor security reviews, incident response advisory and board reporting. Minimum 3-month commitment.

Deliverable

Monthly security dashboard report, board presentation deck, policy updates as needed and ad-hoc advisory (up to 10 hours/month).

CS-15 · Cybersecurity
Penetration Test (Mobile App)
HK$18,000
Mobile apps handle sensitive data and integrate with backend APIs – creating a unique attack surface that web assessments do not cover. Requires rooted Android and jailbroken iOS devices for deep runtime testing; both platforms are covered. Requires rooted Android and jailbroken iOS devices for deep runtime testing; both platforms are covered. Requires rooted Android and jailbroken iOS devices for deep runtime testing; both platforms are covered.
Order →
What We Do

Security assessment of iOS and Android applications following OWASP Mobile Top 10. Includes static analysis, dynamic runtime testing, API security testing, local storage review and SSL/TLS validation.

Deliverable

Mobile security assessment report with vulnerability findings, risk ratings, proof-of-concept where applicable and remediation guidance per platform.

DP-01 · Data Privacy
PDPO Compliance Assessment
HK$13,800
The Personal Data (Privacy) Ordinance applies to all organisations operating in Hong Kong. Non-compliance risks investigation, enforcement notices and reputational damage.
Order →
What We Do

Comprehensive assessment against all 6 Data Protection Principles (DPPs) of the PDPO: purpose and collection, accuracy and retention, use, security, transparency and access/correction. Includes document review, staff interviews and gap analysis.

Deliverable

PDPO compliance report with DPP-by-DPP findings, risk ratings, gap analysis and a prioritised remediation plan with timelines.

DP-02 · Data Privacy
Data Privacy Impact Assessment (DPIA)
HK$11,800
DPIAs are a regulatory requirement under PDPO and GDPR for high-risk processing. They demonstrate accountability and reduce the risk of regulatory action.
Order →
What We Do

End-to-end DPIA following PCPD guidelines: data flow mapping, necessity and proportionality assessment, risk identification and mitigation, stakeholder consultation and documentation of residual risks.

Deliverable

Complete DPIA report with data flow diagrams, risk assessment matrix, mitigation measures and sign-off recommendations.

DP-03 · Data Privacy
Data Mapping & Inventory
HK$7,800
You cannot protect what you do not know you have. Data mapping is the prerequisite for any privacy program – without it, compliance is guesswork.
Order →
What We Do

Discovery and documentation of personal data flows across the organisation: what data is collected, where it is stored, who has access, how it is shared and when it is deleted. Includes stakeholder workshops and system reviews.

Deliverable

Data inventory register, data flow diagrams (Visio/PDF), Record of Processing Activities (ROPA) template and gap analysis against PDPO DPP1.

DP-04 · Data Privacy
Privacy Policy Drafting
HK$5,800
A compliant privacy policy is a legal requirement under PDPO. Generic templates rarely address the specifics of your data processing activities.
Order →
What We Do

Drafting or review of external Privacy Policy, Personal Information Collection Statement (PICS) and internal data handling procedures. Tailored to your actual data processing activities and aligned with PDPO requirements.

Deliverable

Bespoke Privacy Policy and PICS documents (bilingual EN/TC), implementation guide and staff briefing notes.

DP-05 · Data Privacy
Cross-Border Data Transfer Review
HK$13,800
Cross-border data transfers trigger additional compliance obligations under PDPO (s.33) and PIPL. Many organisations are unaware their cloud services constitute a transfer.
Order →
What We Do

Review of cross-border personal data flows: identification of all data transfers (including cloud storage, SaaS tools, group company sharing), assessment of legal basis for transfer, adequacy review and recommended safeguards (SCCs, BCRs, contractual clauses).

Deliverable

Cross-border data transfer register, risk assessment per transfer, legal basis documentation and recommended safeguard measures.

DP-06 · Data Privacy
Data Breach Response Planning + TTX
HK$12,800
PCPD expects organisations to have a data breach response plan. Mandatory breach notification requirements are tightening across Asia-Pacific.
Order →
What We Do

Development of a Data Breach Response Plan covering: detection, containment, investigation, notification (PCPD, data subjects, media) and remediation. Includes a half-day tabletop exercise simulating a personal data breach scenario.

Deliverable

Data Breach Response Plan document, TTX scenario pack, after-action report, PCPD notification template and staff communication templates.

DP-07 · Data Privacy
PCPD AI Compliance Gap Assessment
HK$13,800
The PCPD has issued specific guidance on AI and personal data. Organisations deploying AI systems must assess compliance with the AI Ethical Governance Framework.
Order →
What We Do

Assessment against PCPD AI guidance: transparency, accountability, data minimisation, bias mitigation, human oversight and data subject rights in AI decision-making. Covers both in-house and third-party AI systems.

Deliverable

AI compliance gap report mapped to PCPD guidance, risk register, policy recommendations and staff AI usage guidelines.

DP-08 · Data Privacy
Employee AI Usage Policy + Training
HK$6,800
Uncontrolled employee use of AI tools (ChatGPT, Copilot, etc.) creates data leakage, IP and compliance risks. A clear policy is the first line of defence.
Order →
What We Do

Drafting an Employee AI Usage Policy covering: approved tools, prohibited uses, data classification rules, confidentiality obligations and disciplinary measures. Includes a 2-hour training session for all staff.

Deliverable

Employee AI Usage Policy document, training slide deck, attendance record and a management compliance checklist.

DP-09 · Data Privacy
Biometric Data Privacy Assessment
HK$11,800
Biometric data is classified as sensitive personal data under most privacy laws. Its collection and use trigger heightened compliance obligations and consent requirements.
Order →
What We Do

Assessment of biometric data processing: fingerprint, facial recognition, voiceprint. Covers: legal basis for collection, consent mechanisms, retention periods, security safeguards and compliance with PDPO and international standards.

Deliverable

Biometric data assessment report, consent form templates, retention and deletion policy and gap analysis against regulatory requirements.

DP-10 · Data Privacy
DPO-as-a-Service (Monthly Retainer)
HK$15,000/mo
Many SMEs lack the resources for a full-time Data Protection Officer. DPO-as-a-Service provides ongoing privacy oversight and regulatory liaison.
Order →
What We Do

Monthly retainer including: virtual DPO representation, PCPD liaison, privacy impact assessment oversight, data breach advisory, staff training coordination and quarterly compliance reporting. Minimum 3-month commitment.

Deliverable

Monthly privacy dashboard, quarterly compliance report, PCPD correspondence handling and ad-hoc privacy advisory (up to 10 hours/month).

DP-11 · Data Privacy
PIPL (China) Compliance Assessment
HK$15,800
The Personal Information Protection Law applies to organisations processing personal information of individuals in mainland China, regardless of where the organisation is based.
Order →
What We Do

Assessment against PIPL requirements: legal basis for processing, consent mechanisms, data localisation, cross-border transfer assessment, data subject rights, DPO appointment and impact assessments for sensitive data.

Deliverable

PIPL compliance report, gap analysis with remediation roadmap, data localisation assessment and cross-border transfer documentation.

Looking for a corporate plan?
Volume pricing, centralized billing and tailored programs for organizations and SMEs.
Contact Us