B BROCENT
ServicesManaged IT ServicesReport Central

Sooner or later, someone asks you to prove it.

Your investor's due-diligence team. Your auditor. Your regulator. Your own board. They don't want a dashboard screenshot — they want a dated document with an owner's name on it. Nine of them reach our managed clients every month and quarter, and all nine are published below in full.

9
Reports per cycle
5th
Working day issued by
11
Markets, one reporting standard
100%
Findings with owner and date
Typical due-diligence questions
Answered by
“How do you control access?”
Investor ODD questionnaire
No record Report 07 · Quarterly
“How do you know you are patched?”
Regulatory inspection
No record Report 02 · Monthly
“When did you last test a restore?”
Insurer / board risk review
No record Report 06 · Tested quarterly
“Who reviewed permissions, and when?”
External audit
No record Report 07 · Quarterly
Sample period · August 2026Anonymised · 41-person Hong Kong investment firm67 managed assets · 2 offices · 1 M365 tenantIssued by the 5th working day
Why this exists

Reporting is not a courtesy. It is the evidence someone will ask you for.

Every market we operate in has its own data-protection or supervisory regime, and they converge on the same demand: show that the control actually operated — on a date, with a named owner, for a period you can point to.

So the nine reports are the same nine everywhere. What changes market to market is only which regime your auditor happens to cite, and which of your entities it applies to. A group with offices in three of these countries gets one reporting standard across all three, not three different providers' formats.

Framework references below reflect how Brocent describes delivery in each market. Open a country page for what that means locally — entity, team, languages and contract.

Market · what firms here are asked to evidence
Hong Kong
PDPO · SFC-licensed firms · investor operational due diligence
Hong Kong
Singapore
PDPA · MAS Technology Risk Management guidelines
Singapore
Taiwan
PDPA (Taiwan) · cross-border data governance
Taiwan
Malaysia
PDPA
Malaysia
India
DPDP Act
India
Mainland China
MLPS (等保) · PIPL
Mainland China
United States
SOC 2 · HIPAA-advisory · CCPA awareness
United States
Japan
APPI · My Number Act
Japan
Vietnam
Decree 13/2023
Vietnam
Thailand
PDPA (2019)
Thailand
Poland & EMEA
GDPR · Polish UODO
Poland & EMEA
The nine reports

Nine questions you already get asked. Nine documents that answer them.

Find the question you can't currently answer, and read the document that does. Every sample opens in full — findings, missed service levels and all.

One revolution is one reporting cycle. Monthly reports land by the fifth working day; quarterly ones within ten working days of quarter close.

Inside every one of them

Eight sections. The bad news first.

Every report states what is wrong before what is right, names an owner and a date against each finding, and reports the service levels we missed as plainly as the ones we met. Where a control is not covered, it says so rather than leaving a gap where a number should be.

01
Executive summary
A management conclusion in plain words, not a metric dump.
02
Key indicators
Eight figures, each with movement against the prior period.
03
Key findings
Evidence, impact, recommendation, owner, date, reference.
04
Service level attainment
Met and missed, with the reason for each miss.
05
Trend
Three periods side by side with the direction of travel.
06
Detail data
The full inventory or log behind every figure above.
07
Risk register
Open items carried between periods until they close.
08
Sources and method
Where each number came from, and what it excludes.
How you get them

Reporting is not a product. It is what the service looks like from your side.

Which of the nine you receive follows your scope — a client without a SOC subscription does not get the log management report. Nothing here is billed separately.

Included with

Managed IT Support

Assets, patching, configuration, accounts, backup and availability reporting come with every managed plan. Per-market pricing for Hong Kong, Singapore and mainland China is published in full — no “contact us” wall.

See plans & pricing
Included with

Managed Cybersecurity

SOC log management, Microsoft 365 security posture and access review reporting come with the managed security service, delivered from our 24×7 Hong Kong SOC.

Explore MDR & SOC
Not a client yet

Free IT health check

We run the first edition of these reports against your real estate — whoever manages it today. About a week, a few hours of your team's time, no obligation to continue.

Book a health check
For regulated firms

Written to answer an ODD questionnaire, not to survive one

Hong Kong licensed firms are asked the same questions by investors and by the regulator: how do you control access, how do you know you are patched, when did you last test a restore, who reviewed permissions and when. These reports are the answer — dated, owned and produced on a cycle, which is the difference between evidence and assertion. Clients forward the relevant report as-is; nothing needs to be reformatted for a due-diligence pack.

Frequently asked

About Brocent reporting

Are these real client reports?

They are the real format and the real depth, produced against a representative estate. Client names, hostnames, user identifiers, addresses and third-party organisations have been replaced with fictitious values. We publish samples rather than redacted client documents, because redaction is never as safe as it looks.

Do we get the same reports outside Hong Kong?

Yes. The nine reports are one standard across all eleven markets we deliver in directly — the format, the sections and the cadence do not change with the country. What changes is the local entity you contract with, the languages your service desk speaks, and which data-protection or supervisory regime your own auditor cites. Each country page sets out the local specifics.

Is reporting included in the managed service, or an add-on?

Included. Every managed client receives the reports that apply to their scope at no separate charge, because a service you cannot inspect is not a service. Scope determines which of the nine apply — a client without a SOC subscription does not receive the log management report.

Can the reports be branded for our own board or investors?

Yes. Reports can carry your logo alongside ours, or be issued white-label with no provider branding for onward distribution. The content and the method do not change — only the signature block.

What if a report shows you missed a service level?

It says so, with the reason and the corrective action, on the same page as the ones we met. A provider whose reports never show a miss is either not measuring or not telling you.

We already have an IT provider. Can you review their reporting?

A free IT health check produces the first version of these reports against your current estate, whoever manages it. Most firms find the gap is not in the work being done but in what is never measured — restore testing, leaver timeliness and log coverage are the three that go unreported most often.

Get your own version of these nine reports
A free IT health check runs against your real estate and produces the first edition of the reports above — assets, patching, accounts, tenant security, backup and monitoring. About a week, a few hours of your team’s time, no obligation to continue.
Book a free IT health check