Security and compliance, engineered for international businesses in China.
Shanghai cybersecurity, compliance and managed IT services for international businesses operating across China and APAC.
Shanghai · Cybersecurity & Compliance & IT · Est. 2021 Security and compliance, engineered for international businesses in China. APIS Consulting is an independent cybersecurity firm in Shanghai built around one goal: keeping international foreign-invested enterprises secure. We audit your defences, govern your compliance with People Republic of China (PRC)'s cyber law, and monitor what matters, to a standard your headquarters will recognise. Explore services Start a conversation Run a free audit ISO/IEC 27001:2022 LA · LI FR · EN · 中文 China & APAC From 5 to 500 people, and more From a lean local operation to an established regional organisation, the scope grows with your people, systems and exposure. With or without local IT staff We can provide the capacity a local entity does not have, or add security and compliance depth to an IT team already in place. Fully outsourced or side by side Hand us a complete scope or have us work alongside your IT team, headquarters and existing providers under one clear operating model. Multiple industries Manufacturing, IT and technology, accounting, financial services, education, professional services and more. We adapt the work to each sector's operating model, risk profile and regulatory context. Recognise your organisation? Contact APIS Consulting Security Audit An independent review of your security, showing you where you're exposed, what to fix first, and giving your top management evidence it can trust. → Governance, Risk & Compliance Senior security and compliance leadership on demand: CIO, CISO, DPO and PMO expertise without the cost of hiring full-time. The oversight of a large team, sized for a foreign-invested entity in China. → Managed IT & Security Services Day-to-day IT and security operations: monitoring, response and hardening; run for you and reported in language your stakeholders understand. → Why a China specialist The rules here are their own discipline. China's cyber and data regime, PIPL, the Data Security Law, the Cybersecurity Law and MLPS 2.0, does not map cleanly onto GDPR or a European security programme. We translate between the two, so your local operation stays compliant without losing sight of group standards. Talk through your situation → PIPL Data Security Law Cybersecurity Law MLPS 2.0 等级保护 Cross-border transfer ISO/IEC 27001 Incident response Vendor risk Compliance Audits Independent No products to resell, no vendor quotas. Our advice serves your risk, not a channel margin. Certified We hold ISO/IEC 27001:2022 ourselves, we run the controls we recommend to you. Trilingual French, English and Mandarin across every engagement, from board memo to on-site fieldwork. Let's map your exposure. A short conversation is usually enough to tell whether we're the right fit. Contact APIS Consulting Run a free audit