APIS Consulting

Frequently asked questions

Clear answers, all in one place.

Browse the most common questions about our security audits, governance support, and managed IT and security services.

Security Audit

Which standards do you audit against?

We measure your posture against ISO/IEC 27001:2022, China's MLPS 2.0 (等级保护), the PIPL and Data Security Law, and your own group policies. Findings are reported to the ISO 19011 auditing standard.

How long does a security audit take?

A focused scoping audit typically runs one to three weeks depending on size, scope and access. A full ISMS assessment takes longer. We agree the scope and timeline with you before any fieldwork begins.

Will the report satisfy our European headquarters?

Yes. Reports are trilingual-ready (French, English, 中文) and map each local finding to the relevant group standard, so HQ, group auditors and your China team can all act on the same document.

What types of audit can APIS Consulting perform?

We perform information-system audits, PIPL red-flag audits, MLPS compliance assessments, ISO/IEC 27001 implementation reviews and internal audits, and targeted technical audits covering infrastructure, networks, cloud, identity, endpoints and configurations.

What is a PIPL red-flag audit?

It is a focused review designed to identify the most material privacy risks quickly. We examine processing activities, legal basis and consent, privacy notices, sensitive personal information, third parties, retention and cross-border transfers, then prioritise the issues requiring deeper work.

Can you support MLPS classification and compliance?

Yes. We can help determine the likely MLPS scope and classification, assess readiness against the applicable requirements, organise evidence and build a remediation plan. Formal classification, filing and testing remain subject to the relevant Chinese authorities and accredited bodies.

Can you help implement ISO 27001 and conduct the internal audit?

Yes. We support ISMS design and implementation, certification readiness and internal audit. Where we have supported implementation, responsibilities are separated so the internal audit remains objective and does not audit a consultant's own work.

What is included in a technical audit?

The scope can cover infrastructure, network architecture and segmentation, cloud configuration, identity and access, endpoints, logging, backup, resilience and vulnerability management. We agree the systems, testing boundaries and safe methods before starting.

Governance, Risk & Compliance

What is a virtual CISO (vCISO)?

A virtual CISO gives you senior security leadership on a fractional basis — strategy, governance, risk decisions and board-ready reporting — without the cost of a full-time hire. We act as your CISO for China and APAC.

Can you act as our data protection officer for China?

Yes. Our virtual DPO (vDPO) service covers PIPL obligations, records of processing, data-subject requests and cross-border transfer governance, coordinated with your group DPO in Europe.

How is a GRC mandate structured?

Mandates are scoped to your size and risk and run monthly, quarterly or per-project. You get defined deliverables and a named senior consultant, not an open-ended retainer.

What does a virtual CIO do?

A virtual CIO provides senior technology leadership without a full-time executive hire. The role can cover IT strategy and roadmap, budgets, architecture, suppliers, service performance, project priorities and alignment between the China operation and group IT.

What is the difference between a virtual CIO and a virtual CISO?

The virtual CIO owns the broader technology agenda and how IT enables the business. The virtual CISO focuses on information-security strategy, risk and assurance. We can provide either role or coordinate both under one mandate with clear responsibilities.

Can you work alongside our local IT team and headquarters?

Yes. We can fill a missing leadership role, strengthen an existing local team or coordinate execution between local IT, headquarters and service providers. The governance model and decision rights are agreed at the start.

What happens during the first months of a GRC mandate?

We establish stakeholders and reporting lines, review the current environment, confirm priority risks and obligations, and agree a practical roadmap. The precise first deliverables depend on whether the mandate is CIO, CISO, DPO, PMO or a combination.

Can the mandate cover both China requirements and group policies?

Yes. A core part of the role is translating PIPL, the Data Security Law, the Cybersecurity Law and MLPS requirements into controls and evidence that also align with your group policies and recognised standards.

Managed IT & Security Services

What do your managed IT and security services cover?

We coordinate day-to-day IT operations, security monitoring, incident response and systems hardening, with clear reporting to your China team and headquarters. Coverage is designed around what you already operate.

Do you work with our existing IT provider or MSSP?

Yes. We work alongside your in-house IT and, where useful, partner MSSPs — coordinating rather than replacing, so you keep continuity while gaining security depth.

How is this different from a generic SOC?

Every engagement is run by senior consultants who understand both European group expectations and PRC cyber law, so monitoring and response are tied to your actual compliance obligations, not a one-size template.

Do you provide a Security Operations Centre (SOC)?

Yes. We design and oversee SOC coverage with vetted security-operations partners, while APIS Consulting remains your independent and accountable point of contact. The service can connect local operations with your existing regional or global security model.

Is SOC monitoring available 24×7?

Yes, 24×7 coverage can be included where the risk and response model require it. Business-hours or extended-hours coverage may be more proportionate for other environments. Monitoring windows, response targets and escalation paths are defined in the service scope.

Which systems and log sources can the SOC monitor?

Depending on your environment, coverage can include identity platforms, endpoints, servers, firewalls, network devices, cloud services, security tools and critical applications. We confirm useful log sources, retention and connectivity during onboarding.

What happens when the SOC detects an incident?

The SOC validates and triages the alert, follows the agreed playbook and escalates according to severity. APIS Consulting coordinates communication, containment and follow-up with your IT team, providers and management under the responsibilities set in advance.

Can you work with our global SOC or existing security tools?

Yes. We can integrate with existing tooling and clarify the hand-off between local, regional and global teams. The objective is to close coverage and accountability gaps, not duplicate controls that already work.

Still have a question?

Tell us about your situation and we’ll give you a direct answer.

Contact APIS Consulting