Too Small for Enterprise Security, Too Exposed to Skip It: A Hong Kong Design Studio's Starter Bundle
A composite scenario from Hong Kong: a fifteen-person design studio receives three security quotes, all scoped for a company several times its size, and concludes that real security is out of reach. What a fixed-price starter bundle changes about that decision — and why it is the first rung on the same ladder as a full managed IT plan.
Published
In short: A fifteen-person Hong Kong design studio kept receiving security quotes scoped for a two-hundred-person enterprise, and concluded that real security was out of reach at its size. It was not. A fixed-price starter bundle — four managed services at a published monthly price, from US$399/mo for up to 25 users — gives a small studio a real baseline without a scoping exercise, and it is the first rung on the same ladder as a full managed IT plan.
The industry: too small for an enterprise quote, too exposed to skip it
Hong Kong's boutique design and creative studios sit in an awkward gap. A studio of ten to twenty people has all the exposure of a much larger company and none of the apparatus for dealing with it.
Look at what actually passes through a studio that size. Client brand assets and unreleased campaign work, often under an NDA that was signed without much thought about how it would be honoured operationally. Photography and video files worth more to a competitor than to anyone else. Contracts and rate cards. Payment details for freelancers across several markets. Sometimes a client's own customer imagery or product data, handed over for a shoot and never formally returned. And all of it lives in a Microsoft 365 or Google tenant that someone set up in an afternoon four years ago, on laptops that go home every night and travel to client offices, with an external hard drive under a desk holding the only copy of an archive.
There is no IT department. There is a founder who is also the creative director, an operations person who is also the bookkeeper, and a "guy we call" who is quick and reasonable and shows up when a printer stops working.
That is not a criticism of how studios are run. It is a description of a business model where every hour of overhead is an hour not billed. The problem is that the security market, as this kind of business encounters it, is not built for them.
The scenario: three quotes, all sized for somebody else
Here is a composite picture — drawn from how studios of this size actually operate, not from any one named client.
A Hong Kong design studio has fifteen staff and a fifteen-year-old business. A client's procurement team sends over a security questionnaire before renewing a retainer. It is not aggressive — it asks about multi-factor authentication, how devices are patched, whether staff receive security training, and whether the studio has had its Microsoft 365 configuration reviewed. The founder cannot answer four of the questions honestly with a yes.
So she does the reasonable thing and asks around for quotes.
The first vendor sends a proposal for a managed SOC with 24×7 monitoring. The second wants to run a discovery workshop before quoting anything, at a day rate. The third produces a genuinely thorough security programme — endpoint detection and response, a SIEM, quarterly penetration testing, an incident-response retainer — priced somewhere in the region of a junior designer's annual salary.
None of them is dishonest. All three are correctly scoped for a company several times the studio's size. But the founder now has three data points, and the conclusion she draws from them is the wrong one: *security at this level is what security costs, and we cannot afford it, so we will deal with it when we are bigger.*
The quote goes in a drawer. The questionnaire gets answered vaguely. Nothing changes, and — this is the part that matters — the studio does not end up with "less security". It ends up with none: no MFA enforcement, no patch discipline, no phishing training, no idea what the Microsoft 365 tenant is currently configured to allow.
The gap between "enterprise-grade programme" and "nothing" is where most small studios actually live, and almost nobody sells into it.
What that gap actually costs a fifteen-person studio
A false choice becomes a permanent state. The founder framed the decision as enterprise spend versus nothing, and picked nothing — as a temporary measure. Temporary measures with no review date are permanent. Two years later the studio is twenty people, holds more client material, and still has the same answer.
Client due diligence questions get harder, not easier. Procurement questionnaires are becoming routine in Hong Kong, and they are increasingly a condition of renewal rather than a formality at onboarding. Larger clients ask because their own auditors ask them. A studio that cannot answer well does not usually get told it lost the work on security grounds; it just stops being shortlisted, and never learns why.
The exposure is not theoretical, and it is not sophisticated. Small creative firms are rarely the target of anything advanced. What they get is ordinary: a compromised mailbox used to send a fake invoice to a client, a shared link that was set to "anyone with the link" three years ago and never revisited, an unpatched laptop, a freelancer account that still has access eighteen months after the project ended. None of these require an attacker to be clever. They require nobody to have looked.
Insurance and contracts quietly assume controls exist. Cyber cover, and increasingly client contracts themselves, are written on the assumption that basic controls are in place. Nobody verifies this at signing. It gets verified at claim time, or at audit time, which is the worst possible moment to discover the assumption.
The founder is carrying a decision she has no way to make. This is the underrated cost. She is not an IT buyer, has no basis for comparing three proposals that describe different things, and every conversation ends with a request for a scoping call. The absence of a published price is not a minor inconvenience — it is the reason nothing happened.
Brocent's perspective: start somewhere real beats waiting for a bigger budget
Brocent has been running IT operations in Asia since 2007, from Beijing originally, with a Hong Kong office since 2016 and group headquarters in Singapore since 2021. A meaningful share of that work is with businesses well under a hundred people. The pattern above is not unusual; it is the norm.
The conclusion we have drawn is unglamorous. For a firm of this size, the difference between a perfectly-designed security programme and a plainly-adequate one is small. The difference between a plainly-adequate one and nothing is enormous. Most of the ordinary incidents that hit small firms are prevented by four unremarkable things: knowing how your Microsoft 365 tenant is actually configured, knowing what is exposed to the internet, patching machines on a schedule, and training people to recognise a phishing email. None of that is exotic, and none of it needs a two-hundred-person budget.
The reason it does not get bought is not price. It is scoping. Four services from four vendors means four procurement conversations, four contracts, four tools to run, and four bills — for a studio with no IT staff to run any of them. That is why the Security Starter Bundle exists as a fixed-price package: US$399/mo for up to 25 users, US$749/mo for 26–75, US$1,290/mo for 76–150, published on the page rather than quoted after a call. Above 150 users it becomes a tailored engagement under our CIS Benchmark Audit and Enterprise managed tiers.
The honest framing of the bundle is this: it is not a small managed IT plan, and it is not meant to look like one. It is a defined baseline at a published price, so that a founder can make a decision in an afternoon instead of scheduling three scoping calls she does not have time for.
What this actually looks like in practice
Four services, run as one coordinated programme by one team, with one bill.
A Microsoft 365 security audit, re-run annually. The Quick Security Check: a Microsoft Secure Score review, a CISA ScubaGear automated baseline check, an MFA and conditional-access quick check, the top-20 prioritised findings, and a one-hour walkthrough of what they mean. This is what answers "we have never had our tenant reviewed." Notably, this check is free standalone for teams up to 150 users — what the bundle adds is that it is re-run every year as part of a managed programme rather than being a one-off snapshot.
Managed vulnerability scanning, monthly. An essential-tier external scan, managed and re-run every month, with a CVSS-scored findings report. This is the "what is exposed to the internet" question, asked repeatedly rather than once.
A quarterly phishing simulation programme. Managed simulation campaigns with a per-department results report. For a fifteen-person studio "per-department" means something modest, but the value is the same: you find out who clicks before someone with bad intent does, and the trend improves.
Continuous patch management. OS and third-party patching, running continuously, with a monthly compliance report. This is the control that quietly closes the largest share of ordinary exposure, and the one most likely to be neglected without an agent and a report.
The reporting matters as much as the services. Every audit and scan produces a standard-format report — online, PDF and Excel — with a risk-score gauge and executive summary, per-module findings across Identity, Conditional Access, Endpoint and Defender, a prioritised remediation list, and a trend line across scans. It is the same structure every time, which is precisely what makes it useful when a client's procurement team asks the same question next year.
Getting started is deliberately not self-checkout. On day zero you submit the form and a Hong Kong-based team calls within one business day to confirm scope. A one-page Order Form under the standard MSA is e-signed around days three to five — no bespoke legal review. You then grant read-only Microsoft 365 consent, which takes about fifteen minutes, and share an endpoint list and an employee list for the training programme. By week two or three the programme is live: first audit report delivered, first scan run, patch agents deployed, phishing campaign built. After that it is one consolidated report each month, billed NET 30 from signing, on a monthly auto-renewing contract with one month's notice to change.
It is also worth being clear about what the bundle is not. It is remote-delivered — no on-site visits are included; that is a separate dispatch service. It hands you a prioritised remediation roadmap, but executing the fixes is scoped separately. It uses one standard report format, not a white-labelled one. And it does not include 24×7 emergency response — that belongs to a full managed IT plan. For a fifteen-person studio, none of those exclusions bites. They start to matter as you grow, which is the point of the next section.
Three ways a small studio handles this
No security spend at all
- The reasoning: "We are too small to be a target, and everything on offer is priced for someone much bigger."
- What it costs: nothing in cash.
- What you get: whatever Microsoft's defaults happen to be, plus whatever the last person to configure something decided. Nobody has looked at the tenant, nothing is patched on a schedule, and no one has ever been trained.
- The real problem: it is not a small amount of protection, it is zero, and it is invisible — you find out at the same moment a client or an insurer does.
An enterprise-scoped quote
- What it is: a genuinely good security programme — EDR, SIEM, 24×7 monitoring, periodic penetration testing, an IR retainer — correctly designed for a company several times your size.
- What you get: real, comprehensive protection, if you buy it.
- What it costs: a number that requires a scoping call to discover and a board-level conversation to approve, at a studio that has neither.
- The real problem: it is not wrong, it is mis-sized — and a mis-sized quote reliably produces no purchase at all rather than a smaller one. The studio ends up in the first category by default.
A fixed-price starter bundle scoped for SMEs
- What it is: four managed services — M365 audit, vulnerability scanning, phishing training, patch management — at a published monthly price banded by team size, from US$399/mo up to 25 users.
- What you get: a real baseline, one team, one bill, one monthly report, and a decision you can make without a scoping exercise.
- What it costs: more than nothing and far less than an enterprise programme. Assembled yourself from separate vendors, roughly comparable tooling typically runs US$250–420/mo in licences plus a multi-thousand-dollar audit fee — and leaves you operating four platforms with no one to call.
- What it does not do: 24×7 emergency response, hands-on remediation, or on-site work. Those live in a full managed IT plan, which is where a growing studio ends up next.
Frequently asked questions
What is actually included in the starter bundle?
Four services run as one programme: a Microsoft 365 security audit (Secure Score review, ScubaGear baseline, MFA and conditional-access check, top-20 findings, one-hour walkthrough, re-run yearly), managed external vulnerability scanning re-run monthly with a CVSS-scored report, a quarterly managed phishing simulation campaign with a results report, and continuous OS and third-party patch management with a monthly compliance report. Delivery is fully remote, every audit and scan produces a standard online/PDF/Excel report, and you get a prioritised remediation roadmap and a debrief call after each audit, with business-hours email and ticket support from a named engineer.
Is this enough protection for a fifteen-person studio?
For most studios of that size it is a genuine, defensible baseline — and it is dramatically more than the "nothing while we figure out something bigger" position most are actually in. It covers the four areas that account for the majority of ordinary incidents at small firms. What it does not give you is 24×7 monitoring and response, hands-on remediation, or on-site support. Whether you need those depends less on headcount than on what you hold: a studio doing pre-release work for listed clients under strict NDAs, or handling regulated client data, should be looking at a full managed plan rather than the baseline.
What happens when we outgrow it?
The bands are built to make growth a step rather than a re-scope. Up to 25 users, 26–75, and 76–150 are all published prices; past 150 users it becomes a tailored engagement under the CIS Benchmark Audit and Enterprise managed tiers. In practice most studios reach the limits of the bundle's *scope* — wanting round-the-clock response, someone actually doing the remediation, on-site help, a device standard, an offboarding process — before they reach the limits of its *bands*. That is the point at which the conversation becomes a managed IT plan, and it is a plan change rather than a vendor change.
Does this replace a full managed IT plan?
No, and it should not be sold as one. The bundle is a security baseline. A managed IT plan is an operating model — a named team, a service desk, device management, onboarding and offboarding, a named vCIO and a technology roadmap, and round-the-clock coverage. The bundle deliberately excludes 24×7 emergency response, hands-on remediation and on-site work precisely because those belong to the plan. The reason to buy the bundle from us specifically rather than from a point-solution vendor is that it is the first rung on the same ladder: same provider, same reporting, same account team, so moving up later is a plan change rather than a migration.
How is it priced as we add staff?
By band, not per head. Up to 25 users is US$399/mo, 26–75 is US$749/mo, and 76–150 is US$1,290/mo, with one user/endpoint count covering all four services. "Users" means distinct employees who need Microsoft 365 access, awareness training and endpoint coverage combined; endpoints beyond a one-to-one ratio, like a shared workstation, are scoped at signup rather than estimated in advance. Hiring your sixteenth person does not change your bill. Crossing 25 moves you a band.
Can this help answer a client's security questionnaire?
That is one of its more practical uses. The standard-format audit and scan reports give you documented answers on Microsoft 365 configuration, MFA and conditional access, patch compliance, external exposure and security awareness training — with dates, findings and a trend line rather than assertions. It will not answer every question on every questionnaire, and it is not a certification. But it moves you from "we think so" to "here is the report, dated last month," which is usually the difference that matters to a procurement team.
Is there a contract minimum?
It is monthly and auto-renewing, with one month's notice to change, under the same standard Master Service Agreement as our managed IT contracts. There is no charge to talk to us, and the first invoice is issued on NET 30 terms after the Order Form is signed. One thing worth flagging honestly: these are professional-services engagements, so there are no refunds once work has started — the corresponding upside is that a sample report is available before you buy, so you can see exactly what you are getting.
We are not on Microsoft 365. Is the bundle still relevant?
The audit component is specifically a Microsoft 365 and Entra ID assessment, so a studio running entirely on Google Workspace gets less from that quarter of the package. Vulnerability scanning, phishing simulation and patch management are platform-independent and apply either way. If you are in that position, the honest answer is to talk to us about what the right shape is rather than buying a package where one component does not apply — and in most mixed environments the answer looks more like a managed plan than a bundle.
Where the bundle fits: the first rung, not the destination
A studio with no security at all does not need a strategy. It needs a baseline it can actually buy, this month, without a scoping exercise. That is what the Security Starter Bundle is for, and it is a real product at a published price rather than a lead magnet.
But the reason to buy it from Brocent rather than from four point-solution vendors is what happens afterwards. A fifteen-person studio that grows into a thirty-person agency does not need a bigger bundle. It needs a service desk when a laptop dies before a pitch, a device standard so new hires are productive on day one, an offboarding process that actually revokes access when a freelancer's project ends, someone who owns the technology roadmap rather than reacting to it, and round-the-clock cover for the incident that does not respect office hours. That is a managed IT plan — and the underlying managed IT security services that sit inside it are the grown-up version of exactly what the bundle is doing at a smaller scale.
Because it is the same provider, that transition is a plan change rather than a migration. The audit history carries over, the same account team stays on the file, and the reporting continues in the same format. Our plans are priced per user and per market and published on the pricing page, so you can see today what the next step would cost rather than discovering it in a scoping call two years from now.
If you are the founder with a client questionnaire on your desk and three quotes in a drawer, the useful next step is not a fourth quote. It is to get in touch and start with the baseline you can actually buy — then let the plan follow the business rather than the other way round.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.