APIS Consulting

Security Audit

Cybersecurity audits for businesses in China and APAC.

An independent, evidence-based assessment of your security and compliance posture, measured against ISO/IEC 27001, China's MLPS 2.0 (等级保护), PIPL and your own internal policy. You get findings you can act on and evidence your group can rely on.

What we assess

The full control surface, not a checklist.

Governance & policy

Whether your policies exist, match reality, and satisfy both group standards and local law.

Technical controls

Access, network, endpoint, logging and configuration; reviewed against recognised baselines.

Data & privacy

How personal and important data is collected, stored and moved, including cross-border transfer.

Regulatory readiness

MLPS 2.0 grading, PIPL and Data Security Law obligations, and where gaps carry real exposure.

Third-party risk

The vendors, cloud and integrators that quietly inherit your trust, and your liability.

Response readiness

Whether you could detect, contain and report an incident inside the windows the law allows.

Audit catalogue

Audits shaped around the decision you need to make.

From a rapid risk review to a standards-based internal audit, we define the scope, criteria and evidence required before fieldwork begins.

Information-system audit

A broad review of governance, architecture, operations, resilience, access, data and third parties across your information system.

PIPL red-flag audit

A focused review to identify material privacy exposure, including processing activities, notices, consent, vendors and cross-border transfers.

MLPS compliance assessment

Readiness and gap assessment for MLPS 2.0 classification, required controls, evidence and remediation before formal evaluation.

ISO 27001 implementation & internal audit

ISMS implementation support, certification readiness and independent internal audits against ISO/IEC 27001:2022.

Technical audit

Targeted assessment of infrastructure, networks, cloud, identity, endpoints, configurations and other technical control areas.

What you receive

A report written to be used.

Every engagement ends with a report structured to ISO 19011, prioritised findings, the criteria each was measured against, and remediation you can hand straight to a team. No jargon wall, no filler.

  • Executive summary for leadership and HQ
  • Findings rated by risk, mapped to control references
  • Concrete, prioritised remediation plan
  • Evidence log supporting each conclusion
  • Optional re-test once fixes are in place

Frequently asked

Which standards do you audit against?

We measure your posture against ISO/IEC 27001:2022, China's MLPS 2.0 (等级保护), the PIPL and Data Security Law, and your own group policies. Findings are reported to the ISO 19011 auditing standard.

How long does a security audit take?

A focused scoping audit typically runs one to three weeks depending on size, scope and access. A full ISMS assessment takes longer. We agree the scope and timeline with you before any fieldwork begins.

Will the report satisfy our European headquarters?

Yes. Reports are trilingual-ready (French, English, 中文) and map each local finding to the relevant group standard, so HQ, group auditors and your China team can all act on the same document.

What types of audit can APIS Consulting perform?

We perform information-system audits, PIPL red-flag audits, MLPS compliance assessments, ISO/IEC 27001 implementation reviews and internal audits, and targeted technical audits covering infrastructure, networks, cloud, identity, endpoints and configurations.

What is a PIPL red-flag audit?

It is a focused review designed to identify the most material privacy risks quickly. We examine processing activities, legal basis and consent, privacy notices, sensitive personal information, third parties, retention and cross-border transfers, then prioritise the issues requiring deeper work.

Can you support MLPS classification and compliance?

Yes. We can help determine the likely MLPS scope and classification, assess readiness against the applicable requirements, organise evidence and build a remediation plan. Formal classification, filing and testing remain subject to the relevant Chinese authorities and accredited bodies.

Can you help implement ISO 27001 and conduct the internal audit?

Yes. We support ISMS design and implementation, certification readiness and internal audit. Where we have supported implementation, responsibilities are separated so the internal audit remains objective and does not audit a consultant's own work.

What is included in a technical audit?

The scope can cover infrastructure, network architecture and segmentation, cloud configuration, identity and access, endpoints, logging, backup, resilience and vulnerability management. We agree the systems, testing boundaries and safe methods before starting.

Start with a scoping call.

Tell us your size, sector and what's prompting the review, we'll propose a fit.

Contact APIS Consulting