What a Failed Vulnerability Scan Cost a Hong Kong Law Firm's Cyber Policy
A composite scenario from Hong Kong: a law firm's cyber-insurance broker returns the renewal questionnaire with one line highlighted — a forgotten, internet-facing service with a known vulnerability. What insurers and clients are actually asking for, and what a real scanning practice looks like.
Published
In short: A Hong Kong law firm's cyber-insurance broker sent back the renewal questionnaire with one line highlighted — an unpatched, internet-facing service the firm didn't know it was still running. The firm had a firewall, antivirus and a password policy. What it did not have was evidence of what was actually exposed, and that gap, not the finding itself, was what stalled the renewal.
Why Hong Kong law firms are being asked to prove this, not just claim it
A Hong Kong professional-services or legal firm — 40 to 80 people, partners on one floor, fee-earners and support staff spread across a few more, a client-document archive that has been digitised over the last decade — does not think of itself as a security target in the way a bank does. It handles client-confidential material, holds funds in trust in some practice areas, and runs the ordinary mix of email, document management and remote-access tools that every professional-services firm depends on. For most of the firm's history, "IT security" meant a firewall at the edge, antivirus on every laptop, and a password policy in the staff handbook. Nobody at the firm could have told you, with evidence, what an outsider could actually see and reach on the internet-facing side of the network — and until recently, nobody had asked.
That has changed on two fronts at once. Cyber-insurance renewal questionnaires — the annual form a broker sends before quoting the next year's policy — increasingly ask not "do you have a firewall" but "when did you last run a vulnerability scan, and what did it find." And corporate clients doing due diligence on their external counsel, particularly in finance and cross-border transaction work, now send their own security questionnaires before instructing a firm, asking similar questions in similar language. Both forms assume the firm has a recurring scanning practice and a report to hand over. A firm that has never run one is not being accused of anything — it is simply discovering that "we have a firewall" is not an answer to a question it is now being asked in writing.
The scenario: a renewal that stalled on one highlighted line
Here is a composite picture — a shape that recurs across Hong Kong's professional-services sector, not a named client.
A 55-person Hong Kong law firm, corporate and commercial practice with a smaller litigation team, has carried the same cyber-insurance policy for several years, renewing it each time as a formality alongside the firm's professional-indemnity cover. The firm's operations lead — not a security specialist, more the person who owns "IT" among several other responsibilities — fields the renewal questionnaire from the broker each year and answers it from memory and a quick check with the firm's IT support contact: yes to firewall, yes to antivirus, yes to a password policy, yes to offsite backup. It has always been enough.
This year the questionnaire comes back with a follow-up request attached: a dated vulnerability-scan report from within the last twelve months, or a written explanation of the firm's scanning cadence. Nobody at the firm has ever commissioned one. The operations lead's first instinct is that the firm's managed antivirus and firewall vendor must already be doing something like this — and a call to that vendor confirms they are not; endpoint protection and perimeter firewalls are a different function from an external assessment of what is reachable from outside.
Under some time pressure — the renewal has a date — the firm commissions a scan. It finds, among a handful of lower-severity items, one that matters: an internet-facing remote-access service, set up two years earlier for a partner who has since left the firm, still running and still reachable, with a known vulnerability that had a patch available for months. Nobody remembered it was there. It had not been part of any conversation about the firm's security posture because nobody had a way of seeing it.
The finding itself gets remediated within days once it is known. The part that actually delayed the renewal was not the vulnerability — it was the eleven days between the questionnaire's follow-up request and the firm having a report to send back, during which the broker's underwriters simply waited.
What "we have a firewall" doesn't answer
Four things this exposes, none of them exotic, all of them common in a firm this size that has never run a formal scan.
No CVSS-scored evidence to hand an insurer or a client's security team. A questionnaire response of "we take security seriously" or "we have a firewall" is not evidence in the sense a broker's underwriters or a corporate client's security team means it. What they are actually asking for is a dated, scored report — something that states, in a standard format, what was checked, what was found, and how severe each finding is. Without one, the firm's honest answer is unverifiable, and an unverifiable answer is treated, functionally, the same as no answer.
Exposed services nobody remembers standing up. The remote-access service in the scenario above is the common pattern: something stood up for a specific, time-bound reason — a departed partner's remote access, a vendor's temporary testing port, a file-transfer tool set up for one deal and never turned off — that outlives its reason and becomes invisible because nothing in the firm's normal operations ever looks at it again. A firm with no external inventory has no way to know these exist, let alone that one of them has an unpatched vulnerability.
A scan-once-a-year habit that misses what changed in between. Even a firm that does commission an annual scan is looking at a snapshot from whenever it was run. A new server, a new cloud service, a new remote-access tool stood up mid-year for a specific matter — none of it is covered until the next annual scan happens to catch it, which for a firm on a renewal-driven cadence can be eleven months away.
Confusion between scanning and penetration testing when a client specifically asks for one or the other. Some corporate clients' due-diligence questionnaires ask for a vulnerability scan; others ask for a penetration test; a few use the terms loosely and mean either. A firm that does not understand the distinction risks commissioning the wrong thing, or worse, answering "yes" to a question it has not actually satisfied. The two are related but not interchangeable — see the FAQ below — and knowing which one a given questionnaire is actually asking for is itself part of answering it correctly.
Brocent's perspective: a scan is a recurring discipline, not a one-off document
The instinct, once a renewal stalls or a client questionnaire lands, is to treat the scan as a document to produce once and file away — commission it, get the report, send it, move on. That solves this year's renewal. It does not solve the underlying gap, which is that the firm still has no ongoing way of knowing what is exposed on any given week.
The more durable way to think about it: a vulnerability scan is not a certificate the firm earns once. It is a recurring discipline — the same category of thing as a backup, not the same category as a licence. A backup that ran once, two years ago, is not "a backup" in any useful sense; the value is entirely in the fact that it keeps happening. A vulnerability scan works the same way. The remote-access service in the scenario above would have been caught within a month of being forgotten, not two years later, if scanning had been a standing schedule rather than an annual scramble.
The other half of the value is in the report itself, not just the finding. A raw scanner output — a list of CVE identifiers and severity numbers with no narrative — is not what an insurer's underwriter or a client's security reviewer actually wants to read, and handing one over often generates more follow-up questions than it answers. What they read is a report that maps findings to a recognised standard (PCI-DSS, ISO 27001) with a plain-language executive summary and a clear severity ranking, because that is the format their own process is built to accept without a second round of questions. The scanning tool is a commodity; the report format is the part that actually closes the renewal or clears the due-diligence question.
What this looks like in practice
Brocent runs vulnerability scanning as exactly that kind of recurring discipline rather than a one-off purchase. For a firm this size, three things about how it works matter more than the rest.
Scheduled external and internal scanning, not an annual event. The scans cover internet-facing assets — the firm's public-facing services, remote-access points, anything reachable from outside — on a recurring schedule, with managed tiers adding continuous scanning and emerging-threat alerts rather than a single point-in-time check. That is what would have caught the forgotten remote-access service inside weeks rather than years.
A CVSS-scored report an insurer or client will accept without follow-up questions. Every tier includes a prioritised, CVSS-scored findings report with a human-written executive summary, not a raw tool export. The higher tiers add authenticated internal scanning, web-application scanning and a cloud-posture check, and map findings directly to frameworks like PCI-DSS and ISO 27001 — the same standards a corporate client's own security due diligence, or a broker's underwriting questionnaire, is typically built around. That mapping is what turns a technical report into something a non-technical reviewer on the other side can actually sign off on.
A remediation loop that closes findings before the next renewal, not after. A scan that finds a problem and stops there just produces a longer version of the same eleven-day wait. The remediation call and re-scan built into the service confirm that what was found actually got fixed, so the firm has a closed loop to point to at next year's renewal rather than a document that raises as many questions as it answers.
For scale, Brocent's own pricing is structured in three tiers roughly matched to firm size and scope: an Essential tier for smaller perimeters, a Professional tier that adds internal, authenticated and web-application scanning for firms with a broader footprint, and an Enterprise/Compliance tier for firms that need findings formally mapped to a specific standard. None of that is the point of this article to sell on its own — see the next section for where it actually fits.
Three ways Hong Kong firms currently handle this
- No scanning — "we have a firewall." The firm has never commissioned an external assessment of any kind. Its honest answer to a renewal or due-diligence questionnaire is unverifiable, which functions the same as no answer, and there is no way to know what changed since the network was last configured.
- A one-off annual scan. The firm commissions a scan, usually reactively, around renewal time. It produces a report that is accurate on the day it was run and stale within months, because nothing stood up or changed in between is covered until the next annual scramble.
- Scheduled, managed scanning with CVSS-scored reporting. Scanning runs on a recurring schedule rather than a once-a-year event, findings are mapped to the standards an insurer or client actually reads, and a remediation loop confirms fixes before the next renewal. This is the model that turns a renewal stall into a five-minute report request.
Where this actually fits: inside a managed IT plan, not as a standalone purchase
The renewal-questionnaire problem above is a specific, sharp example of a broader pattern that shows up across every function a firm this size runs: security, backup, patching, helpdesk, device management, each one bought and managed separately, each one a relationship to maintain, a bill to reconcile and a gap to notice only when something goes wrong. A firm that commissions vulnerability scanning as a standalone, one-off purchase every time a renewal forces the question has solved this year's problem and left next year's exactly where it was.
The more durable fix is structural rather than transactional: bring recurring scanning inside the firm's managed IT plan as one of the security disciplines the plan is already responsible for, alongside patching, endpoint protection, backup and the helpdesk that fields the day-to-day IT questions. Brocent's managed IT plans are built as one engine covering a firm's IT operations rather than a stack of separately-bought tools, with transparent per-user, per-month pricing across tiers — Startup, Established, Growth and Enterprise — so a firm of 40 to 80 people can see the actual monthly cost of bringing security discipline in-house without a custom quote for every question. Recurring vulnerability scanning sits alongside the plan as one of its add-on security services, in the same family as the broader managed IT security services Brocent runs from its Security Control Centre — the point is not to buy scanning in isolation, but to have a single managed-IT relationship that already includes the discipline a renewal or a client's due diligence will eventually ask for, so the firm is never again the one scrambling for eleven days to produce a report it should already have on file.
That is also the more general shift a firm of this size and profile tends to make once it hits this kind of moment. A 40-to-80-person professional-services firm that has run IT reactively — one vendor for backup, another for the firewall, an internal person for the helpdesk, an ad-hoc scan when a renewal forces it — is exactly the profile that benefits from consolidating onto one managed IT plan, for reasons that go well beyond this one questionnaire. Brocent has made the same argument, in more general terms, in IT vendor consolidation for Hong Kong professional-services firms — the underlying logic is the same: a firm that has to remember to think about ten separate things is worse off than a firm with one plan that already thinks about all ten.
Frequently asked questions
What's the difference between vulnerability scanning and penetration testing?
A vulnerability scan is automated, broad and repeatable — it checks a large number of assets against a database of known weaknesses and produces a scored list of what it found. A penetration test adds a human tester who actively attempts to exploit findings to prove real-world impact, on a narrower scope. Scans are typically run monthly or on a recurring schedule; penetration tests are usually annual or tied to a specific event like a major system launch. Many firms do both — recurring scanning as the ongoing discipline, an annual penetration test for a deeper, manual check.
How often should a law firm run vulnerability scans?
Firms with no other regulatory driver typically settle on monthly scanning as a baseline, with continuous scanning and alerting on higher managed tiers for firms with a larger or more dynamic internet-facing footprint. The right cadence depends on how often the firm's own environment changes — a firm that stands up new services or remote-access points mid-year needs scanning frequent enough to catch those changes before the next scheduled review, not just before the next renewal.
Will a scan disrupt our systems or slow down the network?
Standard external and internal vulnerability scans are designed to be non-disruptive — they probe for known weaknesses rather than attempting to exploit them, unlike a penetration test, which is a different, more intensive engagement scoped separately. Scans are typically scheduled outside business hours for internal assets as a precaution, and a reputable provider will scope the engagement with the firm in advance rather than running an unannounced scan against production systems.
What does a CVSS score actually mean?
CVSS (Common Vulnerability Scoring System) is an industry-standard scale, roughly 0 to 10, used to rank how severe a given finding is based on factors like how easily it could be exploited and what an attacker could do with it. A CVSS-scored report lets a non-technical reviewer — a broker's underwriter, a client's security team — see at a glance which findings are urgent and which are minor, without needing to read raw technical detail. It is also the format most insurance and compliance questionnaires are built to expect.
Do insurers accept a vulnerability scan report as evidence, or do they want a penetration test?
This varies by insurer and by policy, and a firm should always confirm exactly what its own broker or underwriter is asking for rather than assume — this article describes the shape of the question generally, not a specific insurer's requirement. In practice, many renewal questionnaires ask for evidence of a recurring vulnerability-scanning practice as the baseline, with a penetration test sometimes requested additionally for higher coverage limits or higher-risk practice areas. Firms with the underlying practice already documented and reportable are able to answer either version of the question quickly, rather than starting from nothing under time pressure.
How much does vulnerability scanning cost in Hong Kong?
Brocent's vulnerability scanning is priced in transparent tiers — an Essential managed tier starting from US$150/month for a smaller perimeter, up to a Professional tier at roughly US$400-700/month for firms needing internal, authenticated and web-application scanning, with an Enterprise/Compliance tier custom-quoted for firms needing findings formally mapped to standards like PCI-DSS or ISO 27001. As part of a managed IT plan, it is scoped alongside the firm's other security services rather than quoted as an isolated line item — current tier ranges are on Brocent's pricing pages.
What happens if a scan finds something serious?
Every Brocent scanning tier includes a remediation call to walk through what was found and how to fix it, and a re-scan to confirm the fix worked — the finding is not just handed over as a document, it is closed out. For a firm mid-renewal or mid-due-diligence, this is the step that turns "we found a problem" into "we found it and already fixed it," which is a materially different answer to give a broker or a client's security team.
The renewal question a firm should never have to scramble for
The firm in this scenario now has what it did not have a year ago: a scheduled scanning practice, a CVSS-scored report mapped to the standards its insurer and its corporate clients actually read, and a remediation loop that closes findings before they turn into a stalled renewal. None of that required a bigger security budget in the way the firm initially feared — it required treating scanning as a recurring discipline inside its IT operations rather than a document to chase once a year.
That is the shift worth making before the next renewal cycle forces it: bring recurring vulnerability scanning inside a managed IT plan that already covers the firm's security, backup, patching and helpdesk needs on transparent per-user pricing, rather than treating it as a separate purchase to negotiate under time pressure every time a broker or a client asks the question. Talk to Brocent about what that looks like for a firm this size.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.