ABOUT
The practice behind your defenders
InfoSec Builder is a Hong Kong based cybersecurity practice, operated by a network of professionals who run defence, incident response and offensive testing inside a DFIR firm, banks, Big 4 advisory practices, crypto platforms and MSSPs.
WHO WE ARE
A Hong Kong based operator network
We are not a pyramid of consultants. InfoSec Builder is operated by a group of cybersecurity professionals based in Hong Kong who hold senior roles across industries: a digital forensics and incident response firm, retail and investment banks, Big 4 cyber advisory, crypto exchanges and Web3 platforms, MSSPs running detection and response as a service, and enterprise cloud teams.
That structure is deliberate. The people who scope your engagement are the people who run it, and they are still doing this work day to day. When a problem needs a specialist, a wallet-tracing analyst, a cloud identity engineer or a regulatory reporting lead, we bring that person in from the network instead of staffing the work with generalists.
Working across industries buys pattern recognition. The same intrusion technique, the same control failure and the same regulatory question show up in different sectors, so having seen them before shortens both the investigation and the fix.
Credentials across the network include GCFA, GCIH, GNFA, OSCP, OSEP, CISSP and CREST, alongside expertise earned in live operations rather than in a classroom.
One operating standard
DFIR, banking, Big 4 advisory, crypto and digital assets, MSSP operations, enterprise cloud.
APAC reach
Hong Kong based, delivering engagements across APAC, European and US working hours.
English, Cantonese, Mandarin
Briefings, workshops and reports delivered in the language your team works in.
WHERE OUR OPERATORS COME FROM
Six industries, one operating standard
DFIR and incident response
Live intrusions end to end: triage, containment under pressure, memory and disk forensics, root cause, and reporting that survives scrutiny from insurers, regulators and boards.
Banking and financial services
Retail, corporate and investment banking environments where uptime, regulatory reporting and third-party risk are not optional, and where change control, segregation of duties and audit evidence shape every decision.
Big 4 and advisory
Consulting-grade methodology: scoping, control mapping, evidence trails, quality review, and deliverables written to pass internal audit and external assurance without rework.
Crypto and digital assets
Exchanges, custodians and Web3 teams: key and wallet management, hot and cold architecture, on-chain tracing, smart contract review, and response to incidents where transactions cannot be reversed.
MSSP and SOC operations
Detection and response as a service: use-case libraries, tuning at scale, shift handover discipline, service levels and multi-tenant telemetry, the operational reality that turns a log platform into coverage.
Enterprise cloud and platform
Cloud-native estates, Kubernetes and identity platforms, where misconfiguration and credential sprawl cause most incidents rather than exotic exploits.
WHAT THIS MEANS FOR YOU
Pattern recognition you cannot buy inside one industry
We have probably seen your incident before
Cross-industry exposure means the attack path in your environment is rarely new to us. That shortens the distance between detection and a defensible conclusion.
We speak engineer, board and regulator
The same finding gets written three ways: the technical detail your team needs, the risk language your board uses, and the evidence your auditor or regulator expects.
Vendor-independent by design
No reseller quotas and no referral fees. Recommendations follow your constraints and budget, not a partner programme.
We still practise, every week
Every operator holds an active role in industry, so the advice comes from environments in production rather than from a methodology deck written years ago.
STANDARDS AND FRAMEWORKS
The standards our work is measured against
Incident response and forensics
- NIST SP 800-61 incident handling
- ISO/IEC 27035 incident management
- MITRE ATT&CK mapping for detection and reporting
- Evidence handling and chain of custody
- Reporting for insurers, regulators and boards
Governance and assurance
- ISO/IEC 27001 information security management
- SOC 2 trust services criteria
- PCI DSS 4.0
- NIST Cybersecurity Framework 2.0
- Third-party and supply chain risk review
Local and regional expectations
- HKMA supervisory expectations, including C-RAF and SA-2
- SFC requirements for licensed corporations
- PDPO, and GDPR where it applies
- Incident notification and reporting timelines
Technical and cloud baselines
- CIS Benchmarks
- NSA and CISA Kubernetes hardening guidance
- OWASP Top 10 and ASVS
- Detection engineering and SIEM content standards
ENGAGEMENT MODEL
Senior-led, scoped, discreet
Senior-led delivery
The person who scopes the work leads the work. No juniors learning on your engagement and no account-manager relay.
Fixed scope and price
Written scope, deliverables and price before anything starts. Change is agreed in writing, not discovered on an invoice.
Confidentiality and discretion
Mutual NDA as standard, data minimisation, controlled evidence handling, and no client names in our marketing.
Knowledge transfer built in
Documentation, playbooks, coaching and handover sessions are deliverables, not optional extras.
LEADERSHIP
Talk to the people who run the work
Engagements are led by an operator from the network who has run this work inside an organisation like yours. On the first call you speak to the person who will run the engagement, not to a sales team.
Named bios, certifications and reference engagements are shared during scoping, and the lead operator is introduced before work begins. We do not publish client names, and we do not substitute the team you met with a different one after signature.
Want to work with operators?
Tell us where your security program hurts. We will tell you honestly whether we can help, and who from the network you would be working with.