Do you need help ? Just call us!

+852 3588-3990

Services Provided

Penetration Tests and Ethical Hacking

Nothing will be better than hiring a skillful white-hat to penetrate your systems and tell you what weaknesses do you have.

Penetration Tests and Ethical Hacking - an exercise to simulate a hacker to exhaustively and rigorously finding the flaws and vulnerabilities of a target and perform everything a hacker could to penetrate the systems.

Our services are carefully planned, controlled and executed as safe tests such that potentially harmful actions must be approved and acknowledged by the clients first.

We offer the following categories of Penetration Test Services:


Wireless Network Penetration Test

Internal Network Penetration Test

External Network Penetration Test

Web Application Penetration Test

Mobile Application Penetration Test

Security Risk Assessment and Audit

Knowing your assets, the threats, the security risks and the effective controls would save you from many troubles.

Security Risk Assessment and Audit - The exercise to fully evaluate and understand the assets of the subjects and to evaluate and minimize the security risks threatening the assets.

From the concrete Physical Security to the logical System and Network Security, our consultants will understand and evaluate all of the security risks with objective, clear and fair justifications and provide the clients with recommended actions to minimize the identified risks.

Security Audit could also be performed to verify the effectiveness of the actions to minimized the identified risks.

Vulnerability Management

A single vulnerability could cost you greatly that you cannot afford to overlook.

Our Vulnerability Management services ranging from the consultancy, design and deployment of in-house Vulnerability Management Systems for regular compliance check and vulnerability discoveries to ad-hoc on-demand Vulnerability Assessment services.

Knowing the vulnerabilities in your environment timely and accurately with them will be essential to defend against unwanted malicious attacks.

Security Architecture Review

It is about whether you can make the most out of your current security controls and devices.

You have rigorous and well defined security policies and guidelines. You have cutting-edge security appliances in-place. You have the most advanced firewalls installed.

These things are great on their own but are you sure they are working as intended in harmony and are really efficiently complementing each other?

Security Architecture is about making sure all components, whether physical, technical or administrative, are appropriately designed and placed in a mutual-complementary position to maximize the security protection effect.

Cloud and Virtualization Security

Growing demand and shifting of business to Cloud and Virtualization platforms must face the challenge on Security.

Nowadays Cloud and Virtualization technologies are gradually becoming the major players in IT. Could you guarantee your data is securely protected in a Cloud or Virtualization multi-tenancy platform?

Our consultants have experienced in deploying large scale virtualization and cloud platform with rigorous security requirements such that we understand the risks and challenges faced by the new technologies.

ISMS and AIMS Consulting

Want to get ISO/IEC 27001 and ISO/IEC 42001 certified?

Our consultants have practical experience in helping clients to prepare for and acquire the ISO/IEC 27001 Information Security Management System and ISO/IEC 42001 Artificial Intelligence Management System Certification ranging from smaller scope of a business function to a large scope of whole company certification.

We communicate regularly with the certification bodies to understand the requirements of successfully passing the certification audit.

Incident Response Management

Overlooking the procedures set out in Incident Response Management could cost you dearly on financial assets and reputation.

When things are smooth everything is smooth.

However if an incident strikes, many companies are not ready to make quick and accurate responses such as containing and minimizing the impact of the incident and handling the public relations matters.

Incident Response Management is the formal process to classify what constitutes an incident and to define and communicate across different related departments the expected responses to minimize the impact and tangible or intangible asset loss.

Computer Forensics

To investigate and understand the root cause of a security breach.

After a security breach it will not be simply closing down the incident.

There is a need to understand what is the root cause of having the security breach or incident.

Computer Forensics is the professional exercise and techniques to investigate and retain evidence of a security breach for legal actions and root cause analysis to prevent the same breach from happening again.

Privacy Impact Assessment

What your systems and applications process PII (Personally Identifiable Information) then you have the responsibility to take care of the Privacy Risks.

There have been quite a number of incidents of intentional or accidental privacy breach.

Organizations have to be very conscious about the privacy risk of any new systems or applications before bringing them to production and the Privacy Impact Assessment would be the best exercise to evaluate the privacy risk and to take appropriate controls.

Baseline Security Configuration

Setting out the mutually understood minimum security requirements of different operating systems and applications across internal staff and external vendors will reduce many security problems arising from different people setting up the different machines.

Our consultants have been supplying the baseline security configurations of different platforms to different organizations with different business natures.

Baseline Security Configuration is not just setting a rigid and standard configuration for all organizations but rather every configuration setting needs to be justified and confirmed as applicable in the specific organization. Any configuration item that is not implemented should be risk assessed and the controls should be documented and evaluated.

We understand the needs of all business and we are strong in arriving an applicable yet secure baseline security configuration for the specific organization.

Security Product Integration

Got security products or appliances to be integrated in your environment? We will nail it for you.

Ranging from pieces of software like Anti-virus, Endpoint Protection, Mobile Device Managmenet to pieces of hardware like Web Application Firewall, Next-generation Firewall and Data Leakage Prevention appliance, we have the deep experience in integrating security products in a large practical environment.

Governance, Risk and Compliance (GRC)

Exercising proper internal controls is the key to success.

GRC is the collective set of tools and internal controls to make sure the organization is complied with the internal and regulatory requirements on security. We are able to integrate GRC application to automate and manage the internal controls such that the management would be easy to check the GRC status.

Advanced Persistent Threat (APT) Prevention

Heard about targetted attack on a senior management that could cost the company dearly if successful?

The emergence of APT attacks is causing a lot of alarming and catastrophic loss to some famous organizations.

APT attacks are very sophisticated, organized, stealth and hard to detect. We partner with security intelligence vendors to deploy true APT prevention deployment in your environment such that APT attacks could be stopped before any damage.

Security Policy and Documentations

Formal security requirements set out and communicated to all members of a community will greatly lift the security level.

Some organizations do not have a set of formal security policies and guidelines while some organizations have not updated their policy documents to adapt to the current environment.

We provide professional security policies and guidelines consultancy services such that a set of appropriate security policy documents covering all of the actual needs of the organization will be drafted and put in place.

Emergent Security Inspection

Need urgent help for a suspected break-in or undergoing a ferocious cyber attack?

We have been tackling and handling security incidents and break-in during the past 15 years. Sometimes we are engaged urgently because the clients are in deep troubles. We could help to provide professional advices on the best moves to safeguard the information and financial assets should an attack is in place or believed to be successful.

We would also provide emergent security incident handling services which require high level of techniques and broad experience of handling security incidents.

Security Training

Keep yourself up-to-date with the security knowledge.

Organizations would need regular security awareness or technical training because of internal or regulatory requirements.

We would provide tailor-made security training services for clients and the training could be ranging from general security awareness training to very technical topics such as penetration test and specific security product training.

How do you guarantee we could really help you?

Follow the button in the right section.