APIS Consulting

Shanghai · Cybersecurity & Compliance & IT · Est. 2021

Security and compliance,
engineered for international businesses in China.

APIS Consulting is an independent cybersecurity firm in Shanghai built around one goal: keeping international foreign-invested enterprises secure. We audit your defences, govern your compliance with People Republic of China (PRC)'s cyber law, and monitor what matters, to a standard your headquarters will recognise.

  • ISO/IEC 27001:2022 LA · LI
  • FR · EN · 中文
  • China & APAC

Who we work with

What do our clients look like?

Different industries, different team structures and different levels of maturity. We shape the engagement around the organisation you actually have.

From 5 to 500 people, and more

From a lean local operation to an established regional organisation, the scope grows with your people, systems and exposure.

With or without local IT staff

We can provide the capacity a local entity does not have, or add security and compliance depth to an IT team already in place.

Fully outsourced or side by side

Hand us a complete scope or have us work alongside your IT team, headquarters and existing providers under one clear operating model.

Multiple industries

Manufacturing, IT and technology, accounting, financial services, education, professional services and more. We adapt the work to each sector's operating model, risk profile and regulatory context.

Why a China specialist

The rules here are their own discipline.

China's cyber and data regime, PIPL, the Data Security Law, the Cybersecurity Law and MLPS 2.0, does not map cleanly onto GDPR or a European security programme. We translate between the two, so your local operation stays compliant without losing sight of group standards.

Talk through your situation →
  • PIPL
  • Data Security Law
  • Cybersecurity Law
  • MLPS 2.0 等级保护
  • Cross-border transfer
  • ISO/IEC 27001
  • Incident response
  • Vendor risk
  • Compliance
  • Audits

How we're built

Focused by design.

Independent

No products to resell, no vendor quotas. Our advice serves your risk, not a channel margin.

Certified

We hold ISO/IEC 27001:2022 ourselves, we run the controls we recommend to you.

Trilingual

French, English and Mandarin across every engagement, from board memo to on-site fieldwork.

Let's map your exposure.

A short conversation is usually enough to tell whether we're the right fit.