Sooner or later, someone asks you to prove it.
Your investor's due-diligence team. Your auditor. Your regulator. Your own board. They don't want a dashboard screenshot — they want a dated document with an owner's name on it. Nine of them reach our managed clients every month and quarter, and all nine are published below in full.
Reporting is not a courtesy. It is the evidence someone will ask you for.
Every market we operate in has its own data-protection or supervisory regime, and they converge on the same demand: show that the control actually operated — on a date, with a named owner, for a period you can point to.
So the nine reports are the same nine everywhere. What changes market to market is only which regime your auditor happens to cite, and which of your entities it applies to. A group with offices in three of these countries gets one reporting standard across all three, not three different providers' formats.
Framework references below reflect how Brocent describes delivery in each market. Open a country page for what that means locally — entity, team, languages and contract.
Nine questions you already get asked. Nine documents that answer them.
Find the question you can't currently answer, and read the document that does. Every sample opens in full — findings, missed service levels and all.
One revolution is one reporting cycle. Monthly reports land by the fifth working day; quarterly ones within ten working days of quarter close.
Every managed device and cloud item by category, with owner, warranty and lifecycle position.
Compliance by device class, critical-patch latency against a 14-day target, and every exception with an expiry date.
Baseline compliance per device class, drift since last period, and every change made outside change control.
Joiner, mover and leaver evidence account by account, privileged identities individually justified, dormant accounts named.
Every entitlement certified by a named business approver, separation-of-duties conflicts tested, revocations evidenced.
Secure score by control area against your licensed maximum, conditional access, mail threats blocked, sharing and retention gaps.
Log source coverage including the sources still missing, detection and triage times, every escalated alert with its conclusion.
RPO and RTO attainment per workload, restore tests with validation evidence, and an honest statement of immutability coverage.
Uptime per monitored item, trading-hours attainment stated separately, the outage record, and capacity headroom in weeks.
Eight sections. The bad news first.
Every report states what is wrong before what is right, names an owner and a date against each finding, and reports the service levels we missed as plainly as the ones we met. Where a control is not covered, it says so rather than leaving a gap where a number should be.
Reporting is not a product. It is what the service looks like from your side.
Which of the nine you receive follows your scope — a client without a SOC subscription does not get the log management report. Nothing here is billed separately.
Managed IT Support
Assets, patching, configuration, accounts, backup and availability reporting come with every managed plan. Per-market pricing for Hong Kong, Singapore and mainland China is published in full — no “contact us” wall.
See plans & pricing →Managed Cybersecurity
SOC log management, Microsoft 365 security posture and access review reporting come with the managed security service, delivered from our 24×7 Hong Kong SOC.
Explore MDR & SOC →Free IT health check
We run the first edition of these reports against your real estate — whoever manages it today. About a week, a few hours of your team's time, no obligation to continue.
Book a health check →Written to answer an ODD questionnaire, not to survive one
Hong Kong licensed firms are asked the same questions by investors and by the regulator: how do you control access, how do you know you are patched, when did you last test a restore, who reviewed permissions and when. These reports are the answer — dated, owned and produced on a cycle, which is the difference between evidence and assertion. Clients forward the relevant report as-is; nothing needs to be reformatted for a due-diligence pack.
About Brocent reporting
They are the real format and the real depth, produced against a representative estate. Client names, hostnames, user identifiers, addresses and third-party organisations have been replaced with fictitious values. We publish samples rather than redacted client documents, because redaction is never as safe as it looks.
Yes. The nine reports are one standard across all eleven markets we deliver in directly — the format, the sections and the cadence do not change with the country. What changes is the local entity you contract with, the languages your service desk speaks, and which data-protection or supervisory regime your own auditor cites. Each country page sets out the local specifics.
Included. Every managed client receives the reports that apply to their scope at no separate charge, because a service you cannot inspect is not a service. Scope determines which of the nine apply — a client without a SOC subscription does not receive the log management report.
Yes. Reports can carry your logo alongside ours, or be issued white-label with no provider branding for onward distribution. The content and the method do not change — only the signature block.
It says so, with the reason and the corrective action, on the same page as the ones we met. A provider whose reports never show a miss is either not measuring or not telling you.
A free IT health check produces the first version of these reports against your current estate, whoever manages it. Most firms find the gap is not in the work being done but in what is never measured — restore testing, leaver timeliness and log coverage are the three that go unreported most often.