The Board Asked Who Owns Cybersecurity: A Hong Kong Firm's vCISO Answer
A composite scenario from Hong Kong: a professional-services firm's board asks who actually owns cybersecurity, and the honest answer is that it's split across the office manager, the outsourced IT vendor, and nobody in particular. Why a fractional CISO — not a full-time hire, and not leaving it with the IT vendor — closes that gap, and what the engagement actually looks like alongside a managed IT plan.
Published
TL;DR: A Hong Kong professional-services firm's board asked a simple question during its annual review — "who owns cybersecurity here?" — and the honest answer was that it was split across the office manager, an outsourced IT vendor, and nobody in particular. That's not an answer a board accepts twice. The fix wasn't a full-time hire the firm couldn't justify at its size; it was a fractional CISO who could own the answer without the full-time cost.
Hong Kong Professional Services Firms Have Outgrown "IT Handles It"
This is a composite scenario, not a named client, but it's a common one across Hong Kong's mid-market professional-services sector — law firms, accounting and audit practices, corporate advisory shops, insurance brokers — in roughly the 60-to-100-staff range. These firms are past the point where a two-person IT desk quietly keeping the lights on is a credible answer to a board's questions about cybersecurity. They're big enough to be a real target: client files, deal documents, personal data covered by the Personal Data (Privacy) Ordinance (PDPO), and often financial or legal information worth more to an attacker than the firm's own revenue would suggest. They're also big enough that clients — especially regulated ones — now ask pointed due-diligence questions before signing an engagement letter.
But they're not big enough to justify a full-time Chief Information Security Officer. A full-time CISO in Hong Kong's market typically costs somewhere in the US$5,000–15,000-a-month range in fully loaded compensation, before factoring in the tooling, certifications, and team that role usually expects around it. For a 60-to-100-person professional-services firm, that's a hard number to defend to a partnership vote, especially when the security function itself doesn't generate revenue. So the role doesn't get created — and the firm keeps operating without anyone who's actually, formally accountable for it.
There's also a slower-moving pressure building underneath this. Professional indemnity insurers are asking sharper questions at renewal than they were three years ago. Clients in regulated sectors — banks, funds, insurers, and the corporates they in turn serve — increasingly push security-posture clauses into engagement letters, not because the professional-services firm itself is licensed, but because the firm handles data and documents on the client's behalf and the client's own regulator expects that chain to hold. None of this is unique to any one firm; it's a general shift in how professional-services relationships are underwritten and contracted across the market, and it lands hardest on exactly the size of firm this article is about — big enough to be asked the question, not yet big enough to have staffed an answer.
Who Actually Owns Security? For Most Firms, the Honest Answer Is "Everyone and No One"
Here's what that looks like in practice, and it's a pattern that repeats across firms this size. Security decisions get made ad hoc, by whoever happens to be in the room when a question comes up. The office manager fields a phishing-simulation vendor's cold call and decides whether to book a demo. The outsourced IT provider pushes patches and manages the firewall, but nobody asked them to own a security roadmap — that was never in their statement of work, and most IT-support arrangements aren't built to do it. A partner reads an article about a competitor's ransomware incident and asks IT to "look into it," and IT does something reasonable but ad hoc, because there's no standing plan to check the request against.
None of this is negligence. It's what naturally happens when a firm has outsourced the *doing* of IT and security — patching, monitoring, help-desk tickets — without ever assigning the *owning* of it. There's no one who sets a security roadmap for the year, no one who can walk into a partners' meeting and give a straight answer about the firm's actual risk posture, and no one whose job it is to represent that posture to a client's due-diligence questionnaire or a regulator's inquiry. The work gets done, mostly. The ownership doesn't exist.
It's worth being precise about what's missing, because it isn't technical capability. The outsourced IT vendor is usually perfectly capable of patching a server or resetting a password. What's missing is judgment applied at the level of the whole firm, over time: deciding that this year's priority is closing off remote-access gaps rather than buying a new monitoring tool, or that the firm's biggest real exposure is a handful of partners' email accounts rather than the file server everyone assumes is the risk. That kind of prioritisation call is exactly what a security leadership role is for, and it's exactly the layer that gets skipped when "IT handles it" is the whole plan.
What This Ambiguity Actually Costs a Firm
The scenario that forces the issue is usually a board or partnership-level question, not a technical incident. A client's procurement or compliance team sends a security questionnaire as part of an engagement review, and the answers required — "who is responsible for your information security programme," "what's your incident response plan," "when was your last risk assessment" — don't have a clean owner to draft them. A cyber-insurance renewal asks for evidence of a named security function, not just antivirus and backups. An audit committee, prompted by a competitor's breach making the trade press, asks management directly who's accountable for cybersecurity, and "our IT vendor handles that" doesn't land the way it used to.
Three real problems come out of this, and they compound each other. First, there's no strategic security direction — the firm reacts to whatever the most recent alarming news story or vendor pitch happens to be, rather than working from an actual risk-based plan. Second, compliance and client due-diligence questions arrive and nobody is well-positioned to answer them credibly, which is a real commercial risk when a growing share of professional-services engagement letters now include a security-posture clause. Third, the firm keeps coming back to the same dead end: a full-time CISO hire it genuinely can't justify at this size, so the gap just stays open, quarter after quarter, until something forces the question — usually a board asking it directly.
The awkward part is that none of these three problems are solved by simply asking the outsourced IT vendor to try harder. They were never scoped to own a roadmap, and most IT-support contracts at this size are priced and staffed around keeping systems running, not around strategic risk ownership — asking them to informally absorb that role either strains the relationship or produces a thin, ad hoc version of it that doesn't actually satisfy a board, a client's due-diligence team, or an insurer. The gap isn't a vendor-performance problem. It's a structural one: nobody was ever given the mandate.
A Fractional CISO Gives the Board a Name, Without a Full-Time Salary
Brocent's answer to this gap is a fractional CISO engagement — listed as the "vCISO" add-on alongside the firm's other managed-security services, and labelled "Fractional CISO" on the Homepage B pricing overview. It sits in the same add-on tier as vulnerability scanning, patch management, security awareness training, MDR/EDR, and SOC-as-a-Service — a real, quoted line item, not a marketing concept. The idea is straightforward: a firm this size doesn't need a full-time security executive on payroll; it needs someone with that level of judgment and accountability, engaged for the portion of a CISO's actual workload that a firm its size genuinely generates.
A fractional CISO owns the security roadmap the way a full-time hire would — setting priorities, tracking risk, deciding what gets fixed first — without the firm carrying a full-time executive's salary, benefits, and retention risk for a role that, honestly, doesn't need 40 hours a week at this scale. And because the engagement is explicitly mapped to the compliance questions a Hong Kong professional-services firm actually faces — PDPO obligations around client and employee personal data, and the client-side due-diligence questionnaires that increasingly gate new engagements — it's not generic security consulting bolted onto the firm from outside. It's built to answer the specific questions this kind of firm gets asked. Firms whose client base skews toward regulated sectors — banks, funds, insurers — see an even sharper version of this: Brocent's work with financial-services clients in Hong Kong is built around exactly the kind of SFC/HKMA-adjacent compliance and PDPO-compliant data handling that a professional-services firm's own security posture increasingly gets measured against, whether or not the firm itself is a regulated entity.
The vCISO isn't a standalone consultant parachuted in with a generic framework. Sitting inside Brocent's managed IT security services means the fractional CISO has an actual operational team to direct — ISO 27001- and CISSP-certified security staff already running preventive checks, patch review, and 24×7 incident response for the firm — rather than handing the board a slide deck of recommendations with no one accountable for carrying them out. The strategy and the execution sit inside the same relationship, which is precisely what a firm this size is missing when the roles are split across an internal generalist and an outsourced vendor with no formal security mandate.
What a vCISO Engagement Actually Looks Like Day to Day
In practice, a fractional CISO engagement gives the firm a named person — not a shared inbox, not a rotating account manager — who owns the security roadmap and is accountable for it. That person sets the year's priorities based on the firm's actual risk profile, not a generic checklist: which systems and data matter most, where the realistic gaps are, and what gets fixed in what order. They represent the firm's security posture externally — to a client's due-diligence team, to an auditor, to a cyber-insurance underwriter — with the credibility of someone whose job is specifically to know the answer, rather than a partner improvising in a meeting or an IT vendor answering questions outside their contracted scope.
Crucially, a fractional CISO doesn't replace day-to-day managed IT — it works alongside it. The vCISO sets direction and owns strategy and reporting; the firm's managed IT security services — the ISO 27001- and CISSP-backed team running 24×7 security monitoring, patch review, incident response, and compliance-ready reporting — does the operational work the roadmap calls for. One without the other leaves a gap: strategy with no one executing it, or execution with no one setting direction and answering for the outcome to the board. Together, they're the two halves of an actual security function, built at a cost that fits a 60-to-100-person firm rather than an enterprise budget.
A realistic quarter under this model looks less dramatic than the "board question" framing suggests, and that's the point. The vCISO reviews open risk items and closes out or reprioritises them against what actually changed in the business — a new office lease, a new client onboarded in a regulated sector, a new SaaS tool the finance team adopted without going through procurement. They check in with the managed IT team on what the monitoring and patch data are actually showing, sign off on (or push back on) whatever the most recent vendor pitch was trying to sell the firm, and prepare a short, board-readable update rather than a technical report nobody outside IT can parse. When a client's due-diligence questionnaire lands, or a cyber-insurance renewal asks for evidence of a named security function, the vCISO is the person who fills it in — not a scramble the week it's due.
No Named Owner vs. a Full-Time CISO vs. a Fractional CISO
Three real options exist for a firm in this position, and it's worth being honest about what each one actually delivers:
- No named security owner ("our IT vendor handles that") — the cheapest option on paper, and the one most firms this size default into by not deciding. No one sets a roadmap, no one is accountable to the board, and no one is positioned to answer a client's due-diligence questionnaire or an auditor's question with real authority. The gap doesn't show up on a budget line, but it shows up the first time someone with power — a board, a major client, an insurer — asks the direct question.
- A full-time CISO hire — real, dedicated ownership, and the "correct" answer at enterprise scale. At Hong Kong market rates of roughly US$5,000–15,000 a month in fully loaded cost, it's genuinely hard to justify for a 60-to-100-person firm, and a full-time hire at this scale is often under-utilised — a security executive's real workload for a firm this size rarely fills 40 hours a week, which is its own kind of waste.
- A fractional CISO (Brocent's model) — a named, accountable owner who sets the roadmap, represents the firm to clients and regulators, and works alongside the managed IT team executing it — sized and priced to the actual workload a firm this size generates, not to an enterprise headcount assumption.
Frequently Asked Questions
What does a fractional CISO actually do day to day?
A fractional CISO sets and owns the firm's security roadmap — deciding priorities based on real risk rather than whichever vendor pitched most recently, reviewing the firm's security posture on a regular cadence, and representing that posture to clients, auditors, and insurers when asked. Day-to-day technical execution — monitoring, patching, incident handling — is carried out by the managed IT and security team the vCISO directs, not by the vCISO personally running tickets.
How is a fractional CISO different from an IT manager or outsourced IT vendor?
An IT manager or outsourced IT vendor is generally responsible for keeping systems running — patching, help-desk support, network uptime. A fractional CISO is responsible for the firm's security *strategy and accountability*: setting the roadmap, owning risk decisions, and answering for the firm's posture to the board, clients, and regulators. Most IT-support arrangements were never scoped to include that ownership layer, which is exactly the gap a fractional CISO closes.
How much does a fractional CISO cost compared with hiring a full-time CISO?
A full-time CISO in Hong Kong typically runs roughly US$5,000–15,000 a month in fully loaded compensation. A fractional CISO engagement is scoped and quoted to the actual workload a firm this size generates — a fraction of that commitment, without carrying a full-time executive's salary, benefits, and retention risk for a role that doesn't need 40 hours a week at this scale. Brocent's vCISO add-on is quoted per engagement rather than listed at a flat rate, since the right scope genuinely depends on firm size and risk profile.
Can a fractional CISO represent us to clients and auditors?
Yes — that's a core part of the role. A named fractional CISO can respond to a client's security due-diligence questionnaire, walk an auditor or cyber-insurance underwriter through the firm's actual security posture, and do so with the standing of someone whose job is specifically to know the answer, rather than a partner or IT contact improvising outside their usual scope.
Is a fractional CISO enough on its own, or does it need a managed IT team behind it?
A fractional CISO sets strategy and owns accountability; it doesn't, by itself, run daily monitoring, patching, or incident response. It's designed to work alongside a firm's managed IT security services — the team that executes the roadmap the vCISO sets. Strategy without execution, or execution without a named owner setting direction, both leave a real gap; the two are meant to function together.
How many hours a month does a typical engagement involve?
This varies with firm size and risk profile, which is why Brocent's vCISO add-on is quoted per engagement rather than sold at a flat monthly rate. The point of the fractional model is that the commitment is sized to what a firm this size actually generates in security-leadership work — meaningfully less than a full-time role, but enough for genuine ownership rather than an occasional check-in.
Does this help with PDPO compliance specifically?
A fractional CISO engagement is mapped to the compliance questions Hong Kong professional-services firms actually face, and PDPO obligations around client and employee personal data are one of the most common. Having a named owner accountable for the firm's data-handling posture — rather than an ad hoc response whenever a question comes up — is a meaningfully stronger position to be in if a PDPO-related question, complaint, or audit ever reaches the firm.
Where This Fits Inside a Managed IT Plan
The honest answer to the board's original question isn't "hire a full-time CISO" and it isn't "leave it with the IT vendor" — it's that a fractional CISO works *alongside* managed IT, not instead of it, which makes the plan built around per-user managed IT the natural place this actually lives. Brocent's managed IT support plans are built around exactly this idea: four tiers — Startup, Established, Growth, and Enterprise — priced per user per month, with the operational backbone (24/7 monitoring, help desk, managed firewall, patch management, backup) included at every tier, and security add-ons like vCISO, SOC-as-a-Service, and MDR/EDR layered on as the firm's risk profile calls for them.
For a Hong Kong professional-services firm whose board just asked who owns cybersecurity, the practical next step isn't a standalone security purchase — it's a conversation about what a per-user managed IT plan looks like for a firm this size, with a fractional CISO as one of the add-ons that closes the specific gap the board flagged. That's a deliberately different starting point from shopping for a vCISO consultant in isolation: the roadmap the vCISO sets is only as good as the team executing it day to day, and buying the two separately is how firms end up with a strategy document nobody implements, or an IT team executing tickets against no strategy at all.
Full pricing details are here, covering all four plan tiers and how add-ons like the fractional CISO, SOC-as-a-Service, and vulnerability scanning layer onto them. The fastest way to scope what a fractional CISO and managed IT plan would actually look like for a firm your size — including what the board can expect to hear back in the first board cycle after the engagement starts — is to talk to Brocent directly rather than trying to reverse-engineer it from a pricing page alone.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.