B BROCENT

cybersecurity

Cover image for Brocent IT blog post: The Report Has to Satisfy Their Bank: Penetration Testing for a Hong Kong Fintech Under Counterparty Review

September 25, 2026 | 20 min

The Report Has to Satisfy Their Bank: Penetration Testing for a Hong Kong Fintech Under Counterparty Review

For the founder or head of engineering at a 15-40 person Hong Kong fintech whose banking counterparty has made a penetration test report a condition of onboarding. Who actually reads the report and what they need to write down, the four things that make a report acceptable, how to scope the test to the relationship, why the cheapest scan fails and the biggest engagement overshoots, planning backwards from the deadline, the re-test small teams forget to negotiate, handling findings you cannot fix in time, and reusing the report for the next counterparty.

Cover image for Brocent IT blog post: The Rising Cost of Cybersecurity Incidents: What It Means for IT Service Providers and the Companies That Hire Them

September 16, 2026 | 23 min

The Rising Cost of Cybersecurity Incidents: What It Means for IT Service Providers and the Companies That Hire Them

A research report on the economics of cybersecurity incident cost: why the headline breach-cost figure and the average insurance claim differ by two orders of magnitude and both are correct, what Hong Kong and Singapore's own published data does and does not contain, why cyber premiums are falling while breach costs rise, and how to budget security into an IT decision without quoting the wrong population's number.

Cover image for Brocent IT blog post: Too Small for Enterprise Security, Too Exposed to Skip It: A Hong Kong Design Studio's Starter Bundle

September 11, 2026 | 15 min

Too Small for Enterprise Security, Too Exposed to Skip It: A Hong Kong Design Studio's Starter Bundle

A composite scenario from Hong Kong: a fifteen-person design studio receives three security quotes, all scoped for a company several times its size, and concludes that real security is out of reach. What a fixed-price starter bundle changes about that decision — and why it is the first rung on the same ladder as a full managed IT plan.

Cover image for Brocent IT blog post: Ten Employees Clicked the Fake Invoice: Phishing Simulation at a Singapore Trading Company

September 11, 2026 | 15 min

Ten Employees Clicked the Fake Invoice: Phishing Simulation at a Singapore Trading Company

A composite scenario from Singapore: a 70-person trading company runs its first phishing simulation almost as an afterthought, and ten people click a fake supplier invoice in a single afternoon. How to read a first click-rate, why zero reports is a worse signal than ten clicks, and why the programme — not the platform licence — is the thing that changes outcomes.

Cover image for Brocent IT blog post: The Board Asked Who Owns Cybersecurity: A Hong Kong Firm's vCISO Answer

September 04, 2026 | 14 min

The Board Asked Who Owns Cybersecurity: A Hong Kong Firm's vCISO Answer

A composite scenario from Hong Kong: a professional-services firm's board asks who actually owns cybersecurity, and the honest answer is that it's split across the office manager, the outsourced IT vendor, and nobody in particular. Why a fractional CISO — not a full-time hire, and not leaving it with the IT vendor — closes that gap, and what the engagement actually looks like alongside a managed IT plan.

Cover image for Brocent IT blog post: Who's Watching at 3 AM? A Hong Kong Retailer's SOC Decision

September 04, 2026 | 14 min

Who's Watching at 3 AM? A Hong Kong Retailer's SOC Decision

A composite scenario from Hong Kong: a multi-outlet retail chain's ops director asks a simple question during a security review — who is actually watching our systems at 3 AM — and the honest answer is nobody. Why the fix isn't another tool, and how SOC as a service closes the gap between detection and response.

Cover image for Brocent IT blog post: The Invoice That Almost Went Through

September 04, 2026 | 15 min

The Invoice That Almost Went Through

A composite scenario from Hong Kong: a small marketing agency nearly pays a fraudulent supplier invoice, caught only because a staff member happens to phone to confirm. Why the one cybersecurity video every new hire watches once isn't training, and what a managed, measured awareness programme changes instead.

Cover image for Brocent IT blog post: Three Weeks to Launch, No Pen Test Booked

September 04, 2026 | 17 min

Three Weeks to Launch, No Pen Test Booked

A composite scenario from Hong Kong: a tech startup's public launch date is set, and someone finally asks whether the app has been pen-tested three weeks before go-live. What actually fits into the time that's left, and why the test needs to be planned against the launch date, not squeezed in after it.

Cover image for Brocent IT blog post: The Patch That Was Three Months Overdue: A Hong Kong Firm's Ransomware Near-Miss

September 04, 2026 | 14 min

The Patch That Was Three Months Overdue: A Hong Kong Firm's Ransomware Near-Miss

A composite scenario from Hong Kong: a backup catches a ransomware attempt mid-way through, and the post-incident review traces the entry point back to a server patch that had been sitting overdue for three months on a system nobody was tracking. What changes when patching becomes a managed, visible discipline instead of a task someone has to remember.

Cover image for Brocent IT blog post: The Password Reuse Nobody Flagged: MFA Rollout at a Hong Kong Accounting Firm

September 04, 2026 | 15 min

The Password Reuse Nobody Flagged: MFA Rollout at a Hong Kong Accounting Firm

A composite scenario from Hong Kong: a routine IT review at an accounting firm finds a staff member reusing the same password across email and the practice-management system, with no MFA on either. Why the fix isn't a stricter password policy, and what a properly designed MFA and conditional access rollout actually looks like alongside a managed IT plan.

Cover image for Brocent IT blog post: The Router From the Telco Wasn't Enough: A Hong Kong Manufacturer's Managed Firewall Upgrade

September 04, 2026 | 15 min

The Router From the Telco Wasn't Enough: A Hong Kong Manufacturer's Managed Firewall Upgrade

A composite scenario from Hong Kong: a light-manufacturing SME had run for years on the router its telco bundled in with the internet line, until a routine security review found no real firewall policy at all — just factory defaults on a network that had grown to include production-floor equipment alongside office PCs. Why a managed, SME-scale next-gen firewall — not an enterprise offering, and not the telco's bundled router — closed that gap, and what it looks like bundled into a managed IT plan.

Cover image for Brocent IT blog post: Why Hong Kong Companies Are Bundling MSP, MSSP, and HKMA/C-RAF Support Into One Contract

August 28, 2026 | 22 min

Why Hong Kong Companies Are Bundling MSP, MSSP, and HKMA/C-RAF Support Into One Contract

A research report on why Hong Kong companies — especially HKMA-regulated authorized institutions and their vendors — are bundling managed IT (MSP), managed security (MSSP), and HKMA cybersecurity/C-RAF regulatory support into a single RFP, what C-RAF's three components actually require, and where a vendor's honest role ends and the institution's own non-delegable regulatory accountability begins.

Cover image for Brocent IT blog post: Why a Singapore Fintech's Cyber-Insurance Renewal Came Down to One Vulnerability Scan

August 28, 2026 | 15 min

Why a Singapore Fintech's Cyber-Insurance Renewal Came Down to One Vulnerability Scan

A composite scenario from Singapore's fintech sector: a cyber-insurance broker asks for a current, dated vulnerability-scan report, and nobody in the office has one. What insurers are actually asking for, and what a real recurring scanning practice looks like.

Cover image for Brocent IT blog post: How to Run an Incident-Response Tabletop Exercise Using ChatGPT-Generated Scenarios

August 18, 2026 | 12 min

How to Run an Incident-Response Tabletop Exercise Using ChatGPT-Generated Scenarios

How to build and run an incident-response tabletop exercise with AI-generated scenarios: the four inputs, timed injects, a worked 120-person ransomware run, and why the debrief is the deliverable.

Cover image for Brocent IT blog post: How to Use Grok to Track Emerging Security Threats and Vendor Advisories

August 18, 2026 | 12 min

How to Use Grok to Track Emerging Security Threats and Vendor Advisories

A practical daily workflow for AI-assisted threat monitoring: build the watchlist from your own estate, verify every hit against the vendor advisory and CISA KEV, then act.

Cover image for Brocent IT blog post: How to Use Claude to Flag Phishing Attempts in Business Email

August 09, 2026 | 12 min

How to Use Claude to Flag Phishing Attempts in Business Email

A practical guide to AI-assisted phishing triage: what to feed the model, how a "report suspicious" mailbox workflow works, and the hard limits that keep it a supplement to real email security.

Cover image for Brocent IT blog post: IT Disaster Recovery Hong Kong: A Brokerage's Wake-Up Call

August 07, 2026 | 14 min

IT Disaster Recovery Hong Kong: A Brokerage's Wake-Up Call

How a Hong Kong insurance brokerage discovers the gap between having backup and having real disaster recovery, and what monitored backup and restore drills actually look like.

Cover image for Brocent IT blog post: KnowBe4 Alternative for APAC Teams: What to Look for in a Security Awareness Program

July 14, 2026 | 9 min

KnowBe4 Alternative for APAC Teams: What to Look for in a Security Awareness Program

Comparing KnowBe4 against APAC-native security awareness training options — contract terms, localization, support timezones, pricing, and bundling with a broader security baseline.

Cover image for Brocent IT blog post: Vulnerability Management vs. Penetration Testing: What APAC SMEs Actually Need

July 14, 2026 | 14 min

Vulnerability Management vs. Penetration Testing: What APAC SMEs Actually Need

A practical guide for APAC SMEs on the difference between continuous vulnerability management and point-in-time penetration testing, when each is required by SFC, MAS, HKMA, or PCI-DSS, and how to decide which to invest in first.

Cover image for Brocent IT blog post: 5 Cybersecurity Mistakes Hong Kong SMEs Are Still Making in 2025

April 18, 2025 | 2 min

5 Cybersecurity Mistakes Hong Kong SMEs Are Still Making in 2025

Despite increasing awareness, most cyber incidents affecting SMEs come down to the same handful of preventable mistakes. Here is what we see most often and how to fix them.