Support
Frequently asked questions
Everything you need to know about Brocent's IT services, contracts, SLAs, pricing — and security. Can't find what you're looking for? Contact our team.
Cybersecurity & IT Security
FeaturedWhat we check
What does a Microsoft 365 security audit actually check?
We review Entra ID identity & MFA posture, conditional access policies, privileged role assignments, app permissions, and Intune device compliance — mapped against the CIS Microsoft 365 Benchmark, not just your Secure Score. See M365 Security Audit pricing →
How often should we run phishing simulations?
Quarterly is the effective baseline for most SMEs; higher-risk teams (finance, HR) benefit from monthly campaigns. Our Security Awareness Starter runs either cadence, managed for you. See Security Awareness Starter pricing →
What's the difference between vulnerability scanning and a penetration test?
A scan finds and lists known vulnerabilities across your assets; a pentest has a human actively try to exploit them. Most SMEs should run managed scanning continuously and reserve pentests for compliance-driven or high-risk moments. See Vulnerability Scanning pricing →
Do you patch third-party software, or just Windows updates?
Both. Patch Management Essentials covers OS-level updates and commonly-exploited third-party software (browsers, Java, Adobe, etc.), with a monthly compliance report — most self-run tools only handle OS patching well. See Patch Management pricing →
Is remediation included, or do you just hand us a report?
Every audit and scan ships with a prioritised, severity-ranked remediation roadmap and a debrief call, not just a raw findings dump. Hands-on remediation work itself is scoped separately if you want us to execute the fixes rather than your own IT team. See M365 Security Audit pricing →
Pricing, payment & getting started
How much does this cost, and do we pay anything upfront?
Every security service has a published, fixed price by team size — no "send us your user count for a quote" required. The Security Starter Bundle runs US$399–1,290/mo across three bands (up to 25 / 26–75 / 76–150 users); the Quick Security Check one-time audit is free for teams up to 150 users. Above 150 users, pricing moves to a tailored quote. Recurring packages bill NET 30 from signing, the same terms as our existing managed-IT contracts. See all security pricing →
How long until we get our first report?
An M365 audit report is typically delivered 5–7 business days after kickoff; a first vulnerability scan completes within 3–5 business days of access being granted. The Security Starter Bundle's full programme (audit, scan, patch agents, and phishing campaign) is live within 3–4 weeks of signing. See the full buyer journey →
What do we need to do on our side to get started?
One technical point of contact, ~15 minutes to grant Microsoft 365 read-only access, an endpoint list for patching, and an employee list for phishing training. That's materially less setup than self-running Qualys, KnowBe4 or Automox yourself. See what's included in the Bundle →
Can we buy just one service, or do we have to take the whole bundle?
Either. M365 Audit, Vulnerability Scanning, Security Awareness Starter and Patch Management Essentials are all sold standalone with their own fixed pricing — the Bundle exists because buying all four together costs less than the sum of the parts, not because it's required. Compare individual services →
Scope, support & limitations
Is this an onsite service, or remote only?
Remote only — the audit, scanning, phishing training and patch agents are all delivered without a site visit, the same way Action1, Qualys and KnowBe4 operate. If you need physical/onsite work, that's our separate on-site IT dispatch service, quoted independently. See on-site IT dispatch →
Is there a money-back guarantee?
No. These are professional-services engagements — an audit is delivered, a scan runs, a training campaign is sent — not a software trial you can return. You can review a sample report before you buy to know exactly what you're getting.
What technical support comes with the service?
Business-hours email/ticket support from a named engineer, under our standard SLA tiers (P2 ≤ 1 hour, P3 ≤ 4 business hours first response). This covers questions about your findings and report — it isn't 24×7 emergency incident response, which is part of our Managed IT plans. See our SLA →
Does the price cover fixing the issues we find (remediation)?
No. The price covers the audit/scan/training/patching and a prioritised roadmap. Hands-on remediation — us doing the fixes rather than your own team — is scoped and quoted as a separate line item.
Can we get a custom report format, or is it standard?
Standard format only — the same structure every time (risk score, executive summary, per-module findings, remediation roadmap, trend line), delivered online, as PDF and as Excel. We don't white-label or restructure reports per client.
Where can I see a sample report before buying?
A redacted sample of the standard report — the same one produced by our BCS IT Security Auditor engine — is linked from every security pricing page, so you can see exactly what you'll receive before signing. View a sample report →
Red Team & Phishing Testing
How is a Red Team Engagement different from your Penetration Testing service?
A penetration test finds vulnerabilities across a defined set of systems, disclosed and scheduled with your IT team. A Red Team Engagement pursues one real objective, undisclosed to your defenders, and measures whether they'd detect and respond to a genuine intrusion — not just whether a hole exists. See Red Team Engagement →
Will our own IT/security team know a Red Team Engagement is happening?
No — by design. Only a small "white cell," usually the CISO or one executive, knows the engagement is underway. That's what makes the detection-and-response test meaningful.
What if the red team finds something that looks like a real attack in progress?
The Rules of Engagement, agreed before the engagement starts, include a safe-word and stop conditions precisely for this. The white-cell contact can pause or end the engagement immediately if needed.
Do we need a working penetration-testing programme before booking a Red Team Engagement?
Yes, generally. Red teaming assumes foundational vulnerability hygiene already exists — the value is in testing detection of an attacker who's already gotten past the easy stuff.
What do we get at the end of a Red Team Engagement — a report, or a live walkthrough?
Both: a written executive summary, attack-path timeline, and MITRE ATT&CK-mapped findings, plus a live purple-team debrief session with your team. See Red Team Engagement →
How long does a Red Team Engagement take?
Typically several weeks to a couple of months, depending on the objective and environment — most of that time goes into the lateral-movement phase, not initial access.
Why isn't Red Team Engagement pricing published?
Every engagement is scoped to a real objective and environment, so a published price list would be misleading rather than useful — the market for this service is quote-driven industry-wide. See Red Team Engagement →
Is a Phishing Test the same as Security Awareness Training?
No — Phishing Test is a single benchmark campaign with no subscription. Security Awareness Training is the ongoing managed programme you'd move to if the results show you need one. See Phishing Test →
What happens after a one-time Phishing Test?
You get the full results report and a debrief call. If the numbers point to a real gap, we'll recommend the right cadence — but there's no obligation to continue into a managed programme.
Does the Phishing Test use generic templates, or something realistic?
A named engineer selects the pretext based on your actual business context — the goal is a realistic test, not a canned template that's easy to spot.
Can a Phishing Test target specific departments only?
Yes — finance, HR, and executive teams are common starting points given their typical exposure to targeted attacks.
Is a Phishing Test different from the social-engineering testing in your Penetration Testing service?
Penetration Testing includes social engineering as one vector within a broader technical assessment. Phishing Test is a focused, standalone benchmark on human risk alone — useful on its own or alongside a pentest.
Why isn't Phishing Test pricing published?
Pricing depends on team size, department scope, and channel (email vs. SMS/voice), so we quote it after a short scoping call rather than publish a number that wouldn't apply to most teams. See Phishing Test →
Service Requests
How can I request a service?
Send an email to accounts@brocent.com. For managed service clients, you can also raise tickets directly via the client portal or contact your dedicated account manager.
Can we request immediate support for urgent incidents?
Yes. Priority 1 incidents require immediate response. Contact your Service Delivery Manager (SDM) or account manager directly to initialise P1 service. Our P1 first-response SLA is 15 minutes.
What if there is no response to my ticket — how do I escalate?
You can escalate at any time to accounts@brocent.com or contact your account manager directly. We commit to service quality and will act on every escalation.
Service Windows
Is service available outside of business hours?
Yes. Our Service Command Center operates 24 hours, 7 days a week. If you are a new client who needs out-of-hours emergency support, contact accounts@brocent.com to activate your service account.
What are the standard service windows?
Standard Business Hours: Monday–Friday, 9am–6pm local time. 24×7 support is available for clients on the appropriate service plan (Managed IT Services or 24×7 Add-on). Token Service clients can select Normal or Emergency (24×7) SLA per request.
Service Coverage & Scope
What countries do you cover?
Brocent provides IT services across 100+ countries globally. Direct field delivery is available in 12+ countries including Singapore, Hong Kong, China (mainland), Japan, South Korea, Malaysia, Thailand, Vietnam, India, Philippines, Indonesia, and Poland. Remote managed services and helpdesk are available worldwide.
Do you provide cloud services?
Yes. We manage and support cloud platforms including Microsoft Azure, Microsoft 365, Google Workspace, Alibaba Cloud, Tencent Cloud, AWS, and multi-cloud hybrid environments. Services include design, migration, implementation, and ongoing 24×7 management.
Do you offer warehouse and hardware spare parts services?
Yes. Brocent operates 50+ warehouse locations globally for staging, spare parts storage, and hardware logistics. Warehouses are operational in China (mainland), Hong Kong, Singapore, Malaysia, Japan, Thailand, and India. All hardware warehouses support 24×7 parts availability.
What are your main service categories?
Our core services include: On-site IT support (desktop, network, server), Managed IT Services (full outsourced IT department), Cloud solutions, Cybersecurity, Professional IT services (office setup, relocation, Wi-Fi survey, DC deployment), Hardware maintenance & ITAD, and Token Service (flexible pay-as-you-go).
Do all your engineers speak English?
Yes, the majority of our engineers communicate in English. Our multilingual team also covers Mandarin, Cantonese, Japanese, Korean, Thai, Vietnamese, and other languages — matched to the markets they serve.
BCS Warehouse & Stock Manager (WMS)
Can we buy or license the BCS Warehouse & Stock Manager (WMS) as standalone software?
No. BCS Warehouse & Stock Manager is not sold or licensed as a standalone product. It is the operational tool layer of Brocent's warehousing service: when Brocent operates warehousing for you under Warehouse as a Service, the WMS — including its supplier and customer portals — is included as part of that service. See Warehouse as a Service →
How do our team and our suppliers get access to the BCS WMS portals?
Access is provisioned by Brocent as part of warehouse service onboarding. Customers receive read-only customer-portal accounts covering their own inventory and delivery history. Suppliers operating under a WMS contract receive supplier-portal accounts scoped strictly to their authorized warehouses — never another supplier's data.
Can our own systems integrate with the BCS WMS?
Yes, scoped per engagement. The platform already runs token-based authentication for its external portals, fine-grained permission scoping for integration accounts, and a live courier-tracking API. Webhook-style event notifications (for example inbound received or outbound shipped) are proven elsewhere on the platform. Integration design — push vs. pull, real-time vs. batch, order-level vs. serial-number granularity, API keys and rate limits — is agreed in a discovery call. See the WMS integration walkthrough →
SLA & Quality
What SLA options do you offer?
Brocent offers tailored SLAs with three standard components: (1) Service Desk First Response Time, (2) Field Service Response Time, and (3) Problem Resolution Time. Standard SLAs include P1 first response ≤ 15 minutes, P2 ≤ 1 hour, P3 ≤ 4 business hours. 4-hour on-site response is available in major cities. See our SLA page for full details.
What happens if you miss an SLA commitment?
Brocent commits to penalty and compensation provisions for any SLA breach, as documented in the Master Service Agreement. We take accountability seriously and report SLA performance monthly.
Contracts & Pricing
What is the credit term for new clients?
Brocent offers 30-day credit terms for new clients. Clients with a strong 6-month payment track record may be eligible for extended terms of 45–60 days.
Can you issue VAT invoices?
Yes. Brocent is a certified VAT taxpayer and can issue VAT invoices. Applicable VAT rates by jurisdiction: China (mainland) — 6% IT services, 13% hardware; Singapore — 9% GST; Japan — 10%. Hong Kong has no VAT.
What is the minimum engagement for dedicated engineer (FTE) service?
The minimum period for a dedicated FTE engineer is one month. We also support short-term engagement under a Master Service Agreement.
What is the minimum charge for remote support?
The minimum charge for remote support is 0.5 hours.
What are the standard ad-hoc on-site rates?
Indicative 2026 business-hours on-site rates (per mid-level engineer, same-business-day response), fully loaded — first hour / additional hour / full day: mainland China USD 79 / 71 / 315; Hong Kong USD 94 / 79 / 440; Singapore USD 94 / 71 / 370; Japan USD 142 / 110 / 629; Taiwan USD 102 / 79 / 409; India USD 35 / 19 / 71. Minimum 2 hours per visit, with a 10-minute tolerance per increment thereafter. After-hours: evening/night ×1.5, weekend/public holiday ×2; rates also scale by engineer skill level (L1–L3) and SLA tier. These fully-loaded rates already absorb local cost-of-living, bilingual and qualified engineers, training and resource-qualification effort, cross-border banking, FX and double-taxation handling, credit-term financing cost, and 24×7 service-desk coordination overhead — and fall significantly at higher service volumes as that management overhead is shared across more work. Figures are indicative only; contact the Brocent sales team for a firm quote.
Do you support English contracts and USD billing?
Yes. We support contracts in both English and Chinese, and billing in USD, SGD, HKD, CNY, JPY, and other major currencies depending on the contracting entity.
Can contracts auto-renew?
Yes. IT service contracts typically include auto-renewal based on the agreed terms. Clients may suspend or change the service duration with one month's advance notice.
Do you price-match or beat quotes from other providers?
Our published Managed IT rates already run 20–70% below typical published Hong Kong and Singapore market ranges. For Enterprise and other custom-scoped deals, show us a comparable like-for-like quote from a licensed regional MSP and we'll beat it by at least 10%. See current plan pricing.
Compliance
China labor law — full-time engineers
Is a 1-month notice period required to terminate a full-time employee in China?
It depends on the reason. A no-fault termination initiated by the employer under PRC Labor Contract Law Article 40 (e.g. the employee is unfit for the role even after training/reassignment, is unable to resume work after medical treatment, or the objective circumstances the contract relied on have materially changed) requires either 30 days' written notice or one month's salary paid in lieu of notice (代通知金) — the employer's choice. For-cause termination under Article 39 (serious violation of company rules, serious dereliction of duty, criminal conviction, etc.) requires no notice and no notice pay. Mutual-agreement termination follows whatever the parties agree. An employee who resigns must give 30 days' notice (3 days during probation) — this notice obligation runs the other direction.
When a fixed-term employment contract expires and won't be renewed, is severance compulsory in China?
Yes, in most cases. Under Article 46 of the Labor Contract Law, if a fixed-term contract expires and the employer decides not to renew it, or offers renewal on materially worse terms that the employee reasonably declines, the employer must pay statutory severance (economic compensation). The one exception: if the employer offers to renew on the same or better terms and the employee is the one who declines, no severance is owed. Model the termination cost →
How is severance pay calculated in China?
Statutory severance (经济补偿金) is N months' average wage, where N is based on length of service and the average is the employee's average monthly salary over the 12 months before termination:
a. During probation — if terminated for cause (e.g. genuinely failed to meet the job's hiring criteria), no severance is owed. If it's a no-fault termination, ordinary length-of-service rules below still apply based on actual time worked.
b. Less than 6 months' service — 0.5 month's average salary.
c. 6 months to 1 year — rounds up to 1 month's average salary.
d. Over 1 year — 1 month per full year worked, plus 1 additional month if the remainder is 6 months or more, or 0.5 month if the remainder is under 6 months.
For high earners, monthly salary is capped at 3x the local average wage, and N is capped at 12 years.
How long can the probation period be in China?
It scales with the employment contract's term (Labor Contract Law Article 19): under 3 months — no probation permitted; 3 months to under 1 year — up to 1 month probation; 1 year to under 3 years — up to 2 months probation; 3 years or open-ended (unfixed term) — up to 6 months probation. Only one probation period is permitted per employer per employee, and it must be stated in the written contract to be enforceable.
Is it compliant to skip social insurance and housing fund contributions for a freelancer in China?
Only if the relationship is a genuine freelance/independent-contractor arrangement with no employment relationship in substance — i.e. the individual controls their own hours, tools, and how the work gets done, and isn't managed day-to-day like staff. If in practice the company directs their daily schedule, integrates them into its org structure, and treats them like an employee, Chinese authorities and courts can deem it a de facto labor relationship (事实劳动关系) regardless of the contract's label — triggering retroactive social insurance and housing fund liability, fines, and employee-protection obligations like severance. This is a common misclassification trap, and enforcement has tightened: since September 2025, PRC judicial interpretation has made void any agreement where an employee agrees to forgo social insurance in exchange for cash.
What is the definition of the "actual employer" in China?
The actual employer (实际用工单位) is the entity that uses the worker's labor and controls their day-to-day schedule and job assignments — regardless of which entity signs the paperwork, runs payroll, or issues invoices. That entity carries the employer's legal liability for social insurance, severance, and other labor obligations. This matters most in secondment, outsourcing, and engineer-placement arrangements, where the paper structure and the operational reality can diverge.
Example: a full-time employee works 5 years and 7 months in China — how is severance calculated?
Length of service is 67 months: 5 full years plus a 7-month remainder. Since the remainder is 6 months or more, it rounds up to a full year, giving N = 6. Severance = N × average monthly salary over the last 12 months. Assuming an average monthly salary of CNY 25,000 (and below the local high-earner cap), severance = 6 × CNY 25,000 = CNY 150,000. If the termination is also a no-fault dismissal under Article 40, add either 30 days' notice or 1 month's salary in lieu (CNY 25,000) on top. Run your own numbers in the calculator →
If an international customer contracts a China service supplier for a full-time engineer, do they need a compliant contract — and can the end customer be liable for a compliance dispute?
Yes to both. The service agreement between the international customer and the China supplier needs to be structured so the China supplier is genuinely the engineer's actual employer — properly licensed, running payroll, social insurance, and housing fund contributions, and exercising real day-to-day management of the engineer. If instead the end customer directs the engineer's daily schedule, tasks, and discipline the way it would its own staff, Chinese authorities can find a de facto employment relationship between the end customer and the engineer, exposing the end customer to labor liabilities (back social insurance, severance, wage claims) despite having no direct contract with the individual. Using an unlicensed labor-dispatch arrangement compounds this risk: Article 92 of the Labor Contract Law imposes joint liability on the receiving company. See how Brocent structures compliant full-time engineer placement →
Is this compliance information legal advice?
No. These answers summarize general PRC labor-law principles as background for planning purposes and reflect our understanding as of 2026 — they are not legal advice and don't account for local implementation rules, which vary by city and province. Always confirm specifics with qualified local counsel or your HR/legal advisor before acting.
Token Service
How does the Token Service work?
Token Service is a pre-purchased hours model — one token equals one hour of on-site engineering time during business hours. You buy a block of tokens and consume them as needed — on-site or remote support, normal business hours or 24×7 emergency, across 100+ countries. Minimum charge per on-site visit is 2 tokens (2 hours). After 2 hours, each additional increment is 60 minutes with a 10-minute tolerance.
What is the payment term for Token Service?
30 days credit term upon purchase order. Tokens do not expire within the contract validity period.
What is the minimum token purchase and how long are they valid?
The minimum purchase is 20 tokens per zone. Token validity is 12 months from the purchase date — a one-time goodwill extension is available each contract year via your account manager. Clients are notified 60 days before expiry.
Which service types can tokens be used for?
Tokens cover the full service catalogue: on-site Smart Hands dispatch, remote helpdesk (L0–L3), IMAC tasks, office buildout and relocation, WLAN surveys, hardware logistics and spare parts management, ITAD, and compliance documentation support. A single token pool applies across all service types and all covered countries.
How is on-site billing calculated for Token Service?
Working hours (Mon–Fri 09:00–18:00): minimum 2 tokens, then 1 token per additional 60 minutes (10-minute tolerance). Evening (18:00–22:00): minimum 3 tokens, increments at 1.5 tokens. Weekends / late night (22:00+): minimum 4 tokens, increments at 2 tokens. Public holidays: minimum 6 tokens, increments at 3 tokens. Travel within the service city is included; remote-site surcharges apply for distances over 30 km.
Is there an SLA on token requests?
Yes — token requests follow Brocent's standard P1–P5 priority system: urgent issues (P1/P2) get a 4-hour onsite response, available 24×7 on request, while lower-priority requests are handled next business day. See the full SLA & priority definitions for all five levels.
Can Token Service be used across multiple countries under one agreement, and can multiple offices share one balance?
Yes. A single Token Service agreement covers all zones included in the purchase. Offices within the same zone share one balance; a group with offices in different markets (e.g. Hong Kong and Singapore) holds one balance per market, each billed at local rates. You can use tokens interchangeably across Hong Kong, mainland China, Singapore, Japan, Malaysia, Vietnam, India, EMEA (via Warsaw), and USCA (via New York) without separate contracts or invoices per country.
How much does IT support cost per hour in Hong Kong, Singapore or Mainland China?
Brocent's prepaid tokens work out to different effective hourly rates per market and pack size — see the current per-market pricing and effective per-hour rate for each pack on the Token Service pricing page.
What is the difference between a Managed IT plan and a token pack?
A Managed IT plan is a fixed monthly fee per user that includes 24/7 monitoring, help desk, patching and a security baseline — you pay for prevention and ongoing coverage. A token pack is prepaid hours you spend only when something needs fixing — no subscription, no per-user fee. As a rule of thumb: above roughly 4 tickets a month, a Managed IT plan is usually cheaper; below that, tokens are. See Managed IT pricing and Token Service pricing to compare.
Can I top up my token balance before running out?
Yes — you'll receive a low-balance alert before your tokens run out, and a top-up purchase lands the same day. A weekly balance statement shows your consumption so depletion is never a surprise.
Do you issue local tax invoices — fapiao, GST?
Yes. Mainland China purchases receive a fapiao (发票); Singapore invoices itemise GST; Hong Kong invoices are issued by our HK entity.
Dispatch & On-site Rates
What's the difference between a dispatch rate and a Token Service pack?
A dispatch rate is a straight per-visit USD price with no prepayment — you're billed after the job, at the published rate for that country. A token pack is prepaid hours bought upfront at a lower effective rate, then drawn down as you use them. For an occasional, first-time or unpredictable need, dispatch rate is usually simplest; for recurring, predictable use, tokens are usually cheaper. See Dispatch & On-site Rates and Token Service pricing to compare.
What is an on-site dispatch rate?
An indicative, fully-loaded hourly rate for sending an engineer to your site — published per country for Level 1 EUC (end-user computing) support, next-business-day, standard 9×5 coverage. It covers a 1st-hour minimum plus travel within the metro/CBD area, with each additional hour billed at a lower published rate. Rates fall significantly at higher volumes.
What is a dedicated engineer (FTE) placement?
A full-time, bilingual engineer assigned to one site under Brocent management — for campus HQs or high-touch locations that need a permanent on-site presence rather than per-visit dispatch. Priced monthly (indicative, entry level, no backfill), and scales by skill tier (L1–L3). See current rates on the Dispatch & On-site Rates page.
Do dispatch and FTE rates get cheaper at volume?
Yes, significantly. Fixed coordination and management overhead is shared across more work, so multi-site or multi-country programs price well below the single-ticket rates published on the pricing page. Multi-FTE and multi-country placements are quoted separately — ask a consultant for a volume-based quote.
How does billing and invoicing work for dispatch and FTE, since there's no prepayment?
Dispatch visits are billed after the job on standard 30-day credit terms upon purchase order, itemised by ticket. Dedicated engineer (FTE) placements are invoiced monthly in advance for the coming month. Local tax invoices are issued the same way as for Token Service — a fapiao (发票) for Mainland China, GST-itemised invoices for Singapore, and Hong Kong-entity invoices for Hong Kong.
Network, Server & Wireless Maintenance
What's the difference between the add-on rates and the standalone monitoring plans?
They're two genuinely different products for two buying situations. The add-on rates (Network & Wireless per 10 devices, Virtual Server per server) are per-market monthly rates that require an active Managed IT Support plan — they extend a plan you already have. The standalone plans (Starter/Pro/Enterprise) are monitor-count-based 24×7 NOC monitoring that need no Managed IT plan at all. If you have a plan, the add-ons are usually the right path; if you only want your infrastructure watched, go standalone. See Network, Server & Wireless Maintenance pricing for both side by side.
Can I buy NOC monitoring without a Managed IT plan?
Yes. The standalone monitoring plans (from US$9/month) are deliberately independent — no Managed IT subscription required. You get 24×7 monitoring from 10+ global checkpoints, bundled support tickets, and remote/hotline service. Many clients start standalone and add a Managed IT plan later; nothing is lost in the transition.
What does the NOC actually monitor?
Brocent's Network Operations Centre monitors network devices, servers, cloud workloads and applications around the clock from 10+ global checkpoints, with 1-minute health checks. Any unnatural condition triggers an immediate ticket and technician investigation. Onboarding takes about 4 days from intake survey to full coverage, with Brocent handling all monitoring-agent deployment.
How is the standalone monitoring service billed?
Three transparent components: A — a one-time onboarding charge at activation; B — monitoring tool licences, charged annually by plan and monitor count; C — the recurring monthly plan price, which includes the 24×7 monitoring and the bundled support tickets. All three are published per tier on the pricing page — no hidden platform fees.
How do I add Network & Wireless or Virtual Server maintenance to my Managed IT plan?
Through the quote builder on Managed IT Support — the add-ons appear alongside your plan tier with live per-market rates (Hong Kong, Singapore, Mainland China), the same figures shown on the maintenance pricing page. Existing clients can also just ask their account manager to add them mid-contract.
Managed UniFi wireless controller
What exactly is a UniFi controller, and why does it need hosting?
UniFi access points are configured and monitored centrally by the UniFi Network controller — it holds your SSIDs, VLANs, policies, topology and statistics. The software is free, but it has to run somewhere continuously: either a server you build and maintain (Java + MongoDB, ports opened, upgrades and backups yours), or a hardware Cloud Key on site, or a hosted controller like ours. Brocent already runs one on the BCS platform, so you register the access points you bought and skip the build entirely.
Do the access points have to be bought from Brocent?
No. UniFi access points you already own can be adopted directly. If you do need new units we can supply them at published pricing and handle deployment, but that is a separate hardware purchase — controller hosting is priced per access point regardless of where the unit came from.
Can Brocent supply the access points as part of the service, instead of us buying them?
Yes — that is Model B. Rather than a hardware purchase, the access points come as part of the subscription: no capital investment to build enterprise-class wireless, the network ready within an hour, and hardware maintenance and replacement included, with a spare delivered and swapped within the agreed SLA at no extra cost for the repair. Everything behind the hardware — controller, 24×7 NOC monitoring, change process, monthly availability report — is identical to Model A. It is custom-quoted, since it scopes by sites and access-point count.
Is my network data separated from other clients?
Yes, by logical isolation. The platform runtime is shared — which is part of why the per-access-point price is what it is — but the tenant is a hard boundary: your sites, devices, data, credentials and logs are scoped to your tenant, your accounts resolve only that scope, and Brocent engineer access is granted per client and logged. If your compliance requires a dedicated instance or a specific data jurisdiction, raise it before the quote so a consultant can scope it.
The controller is in the cloud — if the office loses internet, can staff still use Wi-Fi?
Yes. UniFi access points keep forwarding traffic using the configuration already pushed to them when the controller is unreachable. What is affected is management and statistics, not staff connectivity. The controller service itself runs highly available with a 99% availability commitment, and configuration is backed up daily with three-year retention.
Will a firmware upgrade suddenly take the network down?
Upgrades run in batches inside an agreed maintenance window, with a configuration backup taken beforehand, and never across a whole estate at once during working hours. Each upgrade goes through the same change process as any other change: assessed, confirmed with you, executed, verified and recorded — and the outcome appears in that period's report.
Can you host UniFi Protect (video) and Access (doors) too?
No — and neither can anyone else. Ubiquiti allows Protect, Access and Talk to run only on its own UniFi OS console hardware; they are not available as self-hosted or third-party-hosted software, and Ubiquiti's own UniFi OS Server package covers Network, InnerSpace and Identity rather than these. Access additionally needs an Access Hub on site for each door. If you need either, a UniFi OS console goes in your office and Brocent can specify, supply, deploy and maintain it — that is a hardware purchase, not a change to controller-hosting pricing.
Can I move off the service later?
Yes. The access points are your assets throughout. On termination the configuration can be exported and the devices adopted back into a controller you run yourself, or into a hardware Cloud Key. We host the control plane; we do not hold ownership of your network.
Professional Services
What does "from" pricing mean for professional services — what moves the final quote?
The published figure is the genuine starting point for the smallest common scope. What moves it: scope size (sites, headcount, racks, floors), the delivery market, timeline pressure and out-of-hours windows, and technical complexity. Whatever the final number is, it's fixed in a signed SOW before work starts — no time-and-materials drift. See Professional Services pricing for every published starting price.
Can project work be paid with Token Service packs instead of a per-project quote?
Often, yes — prepaid token packs cover on-site, remote, cloud and project work, so smaller project tasks can simply draw down a token balance you already hold. Larger, defined-outcome projects (an office build-out, a relocation) are usually better as a fixed SOW quote. A consultant will price both paths side by side; compare Token Service pricing with the published project rates.
Do you deliver projects outside Hong Kong, Singapore and Mainland China?
Yes. Project work is delivered across Brocent's direct-entity markets, with wider reach through the field dispatch network for on-site tasks. Travel and logistics for overseas dispatch are quoted separately in the SOW — the published starting prices assume in-market delivery.
What does a professional-services SOW include?
The signed statement of work fixes: the scope and deliverables, a fixed price built from the published starting rates, the timeline and milestones, acceptance criteria you sign off against, and what counts as out-of-scope (with how changes are priced). It is the same document our consultants quote from — the website price and the sales price are one and the same.
Third-Party Software & Hardware
Can I buy these tools and self-manage them, or do I need a Brocent plan?
Either. Licenses and hardware on the third-party pricing page are priced and sold standalone — no Managed IT plan required. Deployment, configuration and ongoing management (monitoring a firewall, patching a backup job, running an M365 tenant) are quoted and delivered separately if you want Brocent to run it for you.
Is pricing through Brocent different from buying direct from the vendor?
For most software licenses, no — published rates track the vendor's own list price; Brocent's value is bundled deployment, configuration and support, not a markup on the license itself. Ubiquiti and Synology hardware is priced at public list; Fortinet publishes no public list price, so its figures are indicative reseller/street pricing instead. Either way, installation and ongoing management are quoted separately.
Do I still get the vendor's own support and updates if I buy through Brocent?
Yes. Standard vendor support, updates and warranty terms apply exactly as if you'd bought direct — buying through Brocent adds deployment and Brocent-side support on top, it doesn't replace or restrict what the vendor already provides.
Is Brocent an authorised partner for these vendors?
Yes for several: Microsoft Solutions Partner (Modern Work and Azure), Veeam Gold Partner, and a Fortinet partner for NGFW, SD-WAN, FortiEDR and FortiSIEM deployments — see full certifications on our Partners page. For the others we resell (Bitdefender, CrowdStrike, ESET, Webroot, Okta, 1Password, NordPass, ITGlue, Acronis, MSP360, Ubiquiti, Synology, NordLayer, NordStellar, DigiCert, Sectigo, SSL.com, Splashtop, TeamViewer, Fleet, MeshCentral, RustDesk, Hexnode, Microsoft Intune, Jamf, Adobe Acrobat, Foxit, Microsoft 365 Copilot, KnowBe4, Action1), we don't currently hold a named partner tier — we deploy and support them as an experienced reseller, not as a certified partner.
Are third-party prices in USD?
All indicative prices default to USD. Use the currency switcher in the site header to view estimates in CNY, EUR, HKD, SGD, JPY or TWD at approximate exchange rates — actual invoicing is available in HKD, SGD, CNY, JPY, or EUR depending on your legal entity and billing location.
How much does managed cloud hosting cost?
Platform list prices on the Cloudways platform start at US$11/month for a 1 GB DigitalOcean server, rising with server size and cloud provider — Vultr, Linode, AWS and Google Compute Engine are also available. Autoscaling WordPress hosting (Cloudways Autonomous) starts at US$99/month. Brocent's management — provisioning, migration, patching, monitoring, backup and support — is quoted separately on top of the platform price. See Cloud Hosting & Application Services pricing →
Do you manage the hosting, or do we get our own account?
Brocent runs it for you as a managed service: we provision the servers on the Cloudways platform (a DigitalOcean company), migrate your sites or applications, and handle patching, monitoring, backup and day-to-day support — under one Brocent contract and invoice, rather than you administering a hosting account yourself. The platform's public list prices are published on the pricing page; Brocent's management is quoted separately, and your final quote is confirmed by Brocent at order time.
Which applications can you host on managed cloud hosting?
WordPress and WooCommerce, Magento 2, Laravel, Joomla, Drupal, and custom PHP applications (PHP 7.4–8.4). The autoscaling Autonomous plans are WordPress/WooCommerce only — every other stack runs on the standard Flexible plans. See supported applications and pricing →
For Small & Growing Businesses
IT budget under $50,000? There's a dedicated guide for you.
Our SME Buyer's Guide covers flexible Token Service packages, no-contract options, and 10 plain-language Q&As tailored for IT managers at growing companies.
Still have questions?
Our team is here to help. Send us a message and we'll get back to you within one business day.