Stage One Is a Tenant and Two Laptops: Building IT for a Newly Licensed Hong Kong Asset Manager
For the COO or operations lead at a newly licensed 3-15 person Hong Kong asset manager in a serviced office. Why the commercial clock and the regulatory clock cause most IT rebuilds; the smallest defensible stage-one set that lets you trade tomorrow; how to keep your own audit trail while staff work inside a partner's or administrator's environment; what the full licensed estate adds; what deliberately not to buy yet; and how each stage maps to the evidence regulators and auditors typically ask for.
Published
The short answer: a newly licensed Hong Kong asset manager runs on two clocks — a commercial one that wants to trade next week, and a regulatory one that will ask for evidence later. Build a defensible cloud workspace first, an operating model that survives someone else's environment second, and the full licensed estate last. Build in the other order and you rebuild.
The licence letter arrives, and the first thing most small managers discover is that the calendar they planned around no longer exists. The mandate wants to start. The seed investor wants reporting. The serviced office has a desk for you but not yet a door with your name on it. And somewhere in the back of everyone's mind is the knowledge that, sooner or later, a regulator, an auditor or an allocator's due-diligence team will ask to see how all of this is controlled.
This article is about the order in which to build IT for that moment. It is written for the COO, the licensed representative who has ended up owning operations, or the operations lead at a Hong Kong asset manager with somewhere between three and fifteen people — usually in a serviced office, and sometimes working partly inside a partner's or an administrator's systems before its own environment is finished.
How is this different from the SFC articles already on this blog?
We have published two neighbouring pieces, and it is worth being precise about where this one sits. Our Type 9 application guide is about the application: how IT is described in the business plan and questionnaire, and what a case officer tends to probe. Our audit-readiness case study is about the audit: a firm leaving a parent company's shared network, organised into three workstreams — infrastructure, a management framework, then routine evidence — delivered in four to eight weeks.
That article is the application; the other one is the audit; this one is the build order. It also happens to use three stages, but they are cut differently. Those stages are workstreams, sequenced by what an auditor needs. The stages here are sequenced by the business clock: stage one is what you need to trade tomorrow, stage two is what keeps you in control while you work inside someone else's environment, and stage three is the full licensed estate. If you are already licensed, already trading and preparing for scrutiny, read the case study. If you are standing in a serviced office with a licence and two laptops, keep reading.
The scenario: a licence, three principals and a mandate that starts before the office does
The picture below is an illustrative composite, not a single client. It is assembled from the kind of situation we see repeatedly in Hong Kong, and every detail in it is ordinary rather than dramatic.
Three principals have spent the better part of a year on the licence. Two of them came from larger houses, where IT was something that happened to them — a laptop arrived, a helpdesk number existed, and access appeared when it was requested. The third handles operations and compliance and has, by default, become the person who owns "the IT question". There is a fund administrator, a prime broker or custodian relationship, an external compliance adviser, and a first mandate that is ready to go live within days of approval.
The office is a serviced office. The fit-out of the permanent space, if there is one, is months away. Two people are using personal laptops. One is still logging into a former employer's collaboration tools out of habit for personal contacts. A shared mailbox was set up on a consumer service during the application because somebody needed an address to put on a form. Nobody has written down who has access to what, because until last week there was nothing to have access to.
None of this is negligent. It is simply what a firm looks like on the day before it becomes a regulated business. The question is what to do in the next week, the next quarter and the next year — and, just as importantly, what not to do yet.
Why do a new manager's two clocks cause most IT rebuilds?
The commercial clock is fast. It measures days: when the first trade can be placed, when the first investor report goes out, when a new analyst can start. The regulatory clock is slower but less forgiving. It measures whether, when someone eventually looks, the firm can show that access was controlled, records were kept, data was recoverable and somebody was accountable.
Most of the expensive IT mistakes we see at this size come from letting one clock set the whole plan. When the commercial clock wins outright, the firm ends up on consumer accounts, personal devices and a shared password document, and spends its first real audit unpicking them. When the regulatory clock wins outright, the firm buys a server room's worth of equipment for an office it does not own, spends weeks on procurement, and still cannot onboard its second hire on time.
The staged approach is simply a way of letting each clock own the decisions it is good at. Stage one is chosen so that it is fast enough for the commercial clock but already defensible to the regulatory one. Stage two deals with the awkward middle period. Stage three is where the regulatory clock finally gets the full estate — built on foundations that did not need to be torn out.
Stage one: what IT do you need before you can trade tomorrow?
Stage one is the smallest set of things that is still defensible. The test for every item is the same: if an auditor asked about it in eighteen months, would you be glad you did it on day one, or would you be explaining why you did not? Anything that passes that test and can be done in days belongs here. Anything that fails it, or takes months, belongs later.
One tenant, one domain, owned by the firm
The first decision is the most consequential and the cheapest: a single business productivity tenant, on the firm's own domain, with the firm — not an individual principal, not a friend who set it up, not a supplier — as the registered owner. Every mailbox, calendar, file library and meeting lives here from the first day. The consumer mailbox used during the application gets migrated in and retired, not left running alongside.
This matters because almost everything a regulator or auditor later wants to see about communications, records and access is produced by that tenant. If the firm starts in one place, the history is complete. If it starts in three places and consolidates later, there is a gap in the record that someone will eventually have to explain.
Identity and multi-factor authentication from the first login
Every person gets a named account. Nobody shares one. Multi-factor authentication is switched on for everyone before the first email is sent, not after the first phishing attempt. Administrative rights sit with a small number of separate administrator accounts, not with the principals' everyday logins. Emergency "break-glass" access is documented and stored somewhere two people can reach.
This is dull, and that is the point. Identity is the control that nearly every other control depends on, and it is the one that is hardest to retrofit once people have got used to working without it.
Managed devices, even if there are only two of them
The two personal laptops are the most common stage-one compromise, and the one we push back on hardest. A device that is not enrolled in management cannot be shown to be encrypted, patched or wiped when someone leaves. Company-owned, enrolled devices — even if that means buying three laptops this week — close that gap at a cost that is small relative to everything else the firm is spending. Where a principal insists on a personal phone for email, it should at least sit behind an app-level policy that keeps firm data in a container the firm can remove.
Email and document records that are kept, not just stored
Stage one does not need a finished records policy, but it does need the retention settings switched on so that nothing is lost while the policy is being written. The retention periods themselves are a question for your compliance adviser, not for your IT provider, and we would be wary of anyone who quotes you a number from memory. The IT job is to make sure the tenant is set up so that whatever periods are agreed can actually be enforced, and so that deletion by an individual user does not mean deletion from the record.
Backup that a single compromised account cannot erase
Cloud productivity suites are resilient, but resilience is not the same as backup. Stage one includes an independent backup of mail and files, with at least one copy that cannot be altered or deleted from inside the tenant — so that a ransomware event or a compromised administrator account cannot take the backups with it. Managed cloud backup is built for exactly this, and the first test restore should happen in stage one, not in stage three.
A written record of who can do what
Finally, one page — genuinely one page is enough at this point — listing each system the firm uses, who administers it, who has access, and who approves changes. This is the seed of the access register an auditor will eventually ask for. At three people it takes an hour. At fifteen people, reconstructed after the fact, it takes weeks and is never quite trusted.
Why stage one does not start with network hardware
The audit-readiness case study on this blog recommends dedicated firewall, switching and Wi-Fi hardware, and in that situation it was right: the firm was sitting on its parent company's network, and the only way to give an auditor an unambiguous boundary was to draw one physically. It is worth being honest that this is a different situation from a new manager in a serviced office on day one.
In a serviced office you do not own the network, the comms cupboard or the internet circuit, and there is usually nowhere to put a firewall even if you bought one. The defensible boundary on day one is therefore drawn at the identity, the tenant and the device — the three things you do control. Traffic is encrypted end to end, devices enforce their own protections, and access decisions are made on who and what is connecting rather than which cable they are on. When you move to a permanent office, or if you find yourself sharing a parent's or partner's network, hardware segregation comes back onto the table — and that is exactly when the case study's approach applies.
Stage two: how do you stay in control when staff work inside someone else's environment?
Stage two is the period most plans ignore, because it is untidy. For a while — weeks, sometimes many months — some of your people will work inside systems you do not own. An analyst uses a workstation provided by an administrator. Trade support runs through a partner's order management platform. A principal still has an account in a group entity's environment. None of these is unusual, and none of them is automatically a problem. The problem is when the firm cannot say, afterwards, what its own people did there.
Your audit trail when you do not own the platform
The first rule of stage two is to keep your own record of anything that happens in someone else's system. That usually means three things. Instructions and approvals go through the firm's own mailbox or messaging, so there is a copy in your tenant even if the action happened elsewhere. The firm keeps a list of every external account its staff hold — which platform, whose account, what access level, who granted it. And the firm asks each provider, in writing, what logs they retain and how the firm can obtain them if needed.
You will not always get the answer you want, and at this size you will rarely be able to change a provider's platform. What you can do is document the arrangement, document the gap, and show that you knew about it. That is a far better position than discovering it for the first time when someone asks.
Access reviews that make the arrangement reversible
The second rule is that every external arrangement should be reversible on a known date. Stage two ends — the permanent office opens, a hire is made, a mandate moves — and when it does, the firm needs to be able to close the doors it opened. A monthly access review, even if it takes ten minutes, is what makes that possible: a short check that every external account on the list is still needed and still held by the right person.
This is also where offboarding discipline starts to matter. Small firms are rarely hurt by the person who leaves on bad terms; they are hurt by the account nobody remembered to close. We wrote about that failure mode in more detail in the brokerage offboarding article linked below this post.
The one thing not to do in stage two
Do not let staff move firm data into a partner's environment because it is more convenient there. Working inside someone else's system is fine. Keeping the firm's records only in someone else's system is how a firm loses the ability to produce its own history. The master copy lives in your tenant; the external environment is a place you visit, not a place you store.
Stage three: what does the full licensed estate add?
Stage three is where the firm stops being a start-up with good habits and becomes a regulated business with documented controls. It is also the stage where the audit-readiness case study becomes directly relevant, so we will stay at the level of what gets added rather than restate that article's method.
- Documented controls. Policies for access, acceptable use, change, incident response and data handling that describe what the firm actually does — written after stages one and two, so they describe reality rather than aspiration.
- Retention that is enforced and tested. The retention periods agreed with your compliance adviser, configured in the tenant, and checked by actually trying to retrieve an old record.
- Monitoring with someone watching. Alerts from identity, devices and backup routed to a person or a team who acts on them, with a record of what was done. Monitoring that nobody reads is worse than none, because it creates evidence that you were warned.
- A vendor register. Every provider that touches firm data — administrator, broker platforms, market data, IT, backup, communications — with what they hold, where, and what the contract says about access and exit.
- Incident and business-continuity testing. A tabletop exercise, a test restore, and a written note of what worked and what did not. The note is the evidence; the exercise is how you earn it.
- Network segregation, where it now applies. If the firm has moved into its own premises, this is when dedicated firewall, switching and Wi-Fi come in, sized for a real office rather than guessed for a hypothetical one.
Stage three has no single finish line. It becomes the firm's operating rhythm, and the evidence accumulates month by month rather than being produced in a rush before someone arrives.
What should you deliberately not buy in stage one?
Over-buying is a real failure mode at this size, and it is rarely discussed because the people selling equipment have little reason to raise it. The costs are not only financial. Every piece of infrastructure bought early has to be configured, patched, documented, monitored and — when the firm moves — decommissioned. Each one adds to the list of things an auditor can ask about.
In stage one, we would usually advise against:
- On-premises servers. A three-person manager in a serviced office has nowhere suitable to put one, and almost nothing that needs one. Files, mail and collaboration belong in the tenant.
- A firewall for an office you do not control. As above, the serviced office owns the network. A firewall with nowhere to sit is a box in a cupboard.
- Enterprise security tooling sized for fifty people. The controls that matter at three people are identity, device management, backup and patching. Tools that need a full-time analyst to be useful will not be used.
- Multi-year hardware commitments tied to the temporary office. Commitments should follow the permanent premises, not the serviced desk.
- A bespoke IT policy library before the IT exists. Policies written before stage one is running describe an imagined firm. Write the one-page access register now and the policies in stage three.
Comparison: three ways a newly licensed manager can build IT
- Build everything first: full hardware, servers and a policy library before trading starts. Looks thorough, but delays the first mandate, commits capital to an office that may be temporary, and usually has to be re-done when the firm moves. Evidence is plentiful but describes a firm that does not yet exist.
- Borrow everything: consumer accounts, personal devices and a partner's systems until "later". Fast and nearly free on day one, but leaves no clean record, no clear ownership and a painful migration exactly when the firm is busiest. The first serious review becomes an archaeology project.
- Staged build: a defensible cloud workspace in days, a controlled operating model for the shared period, then the full estate. Slightly more effort in week one than borrowing, far less than building everything, and the history is continuous from the first login. This is the approach this article recommends.
How do the stages map to the evidence a regulator or an auditor will ask for?
We are deliberately not going to paraphrase a specific rule, circular or code paragraph here — those change, and your compliance adviser is the right source for the current text. What we can describe is the kind of evidence that regulators, auditors and allocators' operational due-diligence teams typically ask to see, in general terms, and which stage produces it.
- Who has access, and who approved it. Stage one produces the named accounts and the one-page register. Stage two adds the external-account list and monthly reviews. Stage three turns them into a documented access-control process with a history.
- How records are kept and retrieved. Stage one switches retention on. Stage three sets and tests the agreed periods. Because the tenant existed from day one, the record has no gap.
- Whether data can be recovered. Stage one's independent backup and first test restore; stage three's scheduled restores and continuity test.
- How devices are protected. Stage one's enrolled, encrypted devices, with patch and encryption status available on request.
- How third parties are managed. Stage two's list of external platforms and what each provider logs; stage three's vendor register.
- What happens when something goes wrong. Stage three's incident process and tabletop record — built on alerts that have been flowing since stage one.
The pattern is the important part: nothing in stage three should require you to reconstruct stage one. If a reviewer asks when MFA was enabled or when a leaver's access was removed, the answer should come from a log, not from memory.
What does a serviced office quietly change?
Serviced offices are a sensible place to start a small regulated firm, and many do. Whether a particular premises arrangement is acceptable for your licence is a question for your compliance adviser, not your IT provider. What we can speak to is how the serviced office shapes the IT decisions in all three stages.
- The network is the landlord's. You share it with other tenants, you cannot inspect it, and you will not be given administrative access. This is why stage one draws the boundary at identity and device rather than at the network.
- There is no comms room. Anything that needs a rack, dedicated power or cooling has nowhere to go. Cloud-first is not a preference here; it is the only option that works.
- Wi-Fi is shared and managed by someone else. Treat it as untrusted transport, the way you would treat a hotel's. For how a well-run serviced-office operator manages its own wireless across sites — which is useful context when you are asking your operator questions — see our serviced-office wireless article.
- Printing and meeting rooms are shared too. Confidential documents left on a shared printer, and meeting-room screens that remember the last laptop connected, are small leaks that are easy to close in stage one with a policy and a setting.
- The move is coming. Everything bought in a serviced office should be something that moves with you in a laptop bag, or something delivered as a service you can re-point to a new address.
Frequently asked questions
What IT do we need before we can trade?
The stage-one list: a single tenant on your own domain owned by the firm, named accounts with multi-factor authentication for everyone, enrolled company devices, retention switched on for mail and files, an independent backup that a compromised account cannot erase, and a one-page register of who can access what. For most small managers this can be done in days, provided the devices are available.
Do we need our own servers?
Almost certainly not in stage one, and often not ever. Email, files, collaboration and most of the applications a small manager uses are delivered as services. Servers become a question only if a specific system requires one, and even then a hosted option is usually a better fit for a firm in a serviced office.
Can we operate from a serviced office?
Whether a serviced office is acceptable for your licence is a compliance question to settle with your adviser. From an IT perspective, yes — as long as you accept that you do not control the network, draw your security boundary at identity and device, and treat the building's Wi-Fi as untrusted. Many small firms run this way well.
What does the SFC actually require of IT?
We would rather not paraphrase the regulator from memory. In general terms, reviewers tend to look for evidence that access is controlled, records are kept and retrievable, data can be recovered, third parties are managed and incidents are handled. Our application guide, linked near the top of this article, discusses the application side in more depth; for the current wording of any requirement, rely on your compliance adviser.
How long does each stage take?
It depends on the firm, but as a planning shape: stage one is days to a couple of weeks, mostly waiting for devices. Stage two lasts as long as your staff work inside someone else's environment — sometimes a few weeks, sometimes most of the first year. Stage three is built over the first months and then never really ends, because it becomes the monthly operating rhythm.
What if our staff sit in a partner's environment?
That is stage two. Keep your own record of instructions and approvals in your own tenant, keep a list of every external account your staff hold, ask each provider in writing what they log, review that list monthly, and never let the only copy of firm records live in someone else's system. If you are sharing a partner's actual network rather than just its applications, network segregation moves forward — this is where the approach in our audit-readiness case study applies.
When should we do a first audit?
Not in the first weeks — there is not yet enough history for an audit to mean much. A sensible point is once stage three's controls have been running for long enough to produce a few months of evidence: access reviews, restore tests, patch reports. An earlier, lighter internal check at the end of stage one is worthwhile, mainly to confirm nothing was missed in the rush.
What does this cost per user per month?
Brocent's Hong Kong per-user managed IT plans are published: Startup, for firms of one to five people, is HK$855.14 per user per month; Established, for five to three hundred, is HK$1,247.40; Growth, for ten to five hundred, is HK$1,561.21; Enterprise is quoted. Plans are billed monthly per user or per device, with discounted annual and multi-year terms available. Device management is a priced add-on rather than part of the base plan, so budget for it separately in stage one.
Where the per-user plan fits into all three stages
A firm of three to fifteen people rarely needs an IT department. What it needs is for the stage-one decisions to be made correctly once, for the untidy stage-two period to be watched by someone, and for stage three's evidence to accumulate without the COO building it by hand every month. That is the job a per-user managed IT plan is designed to do, and it is why we think of it as the engine under all three stages rather than a stage-three purchase.
Every Brocent plan tier includes 24/7 NOC monitoring, a multilingual helpdesk, patch management, a managed firewall, base antivirus and EDR, backup and disaster recovery including an immutable copy, password and credential management, and a named vCIO with a technology roadmap. Every tier also includes customer-owned documentation and credentials — which matters more to a regulated firm than it might first appear, because it means the access register and the admin keys belong to you, not to your provider. Our BCS Beam endpoint agent adds consent-first remote support and a read-only security and health audit of each device, with vulnerability findings prioritised against public exploit data, and is hosted in Hong Kong.
In practice a three-person manager usually starts on Startup and moves to Established as it hires past five people, which also adds a dedicated account manager and onboarding hours. The security layer that sits on top — monitoring, response and the controls that stage three documents — is described on our managed IT security services page, and the way we work with regulated firms more broadly is on our financial services page.
Brocent has been doing this since 2007, has had a Hong Kong office since 2016, and has been headquartered in Singapore since 2021. If you are standing in a serviced office with a licence and two laptops, the most useful next step is to see what the per-user plan includes and compare the tiers on our pricing page — then build stage one this week, not stage three.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.