New Member Spotlight: APIS Consulting

Author: Shanghai BenCham

We are delighted to welcome APIS Consulting as one of the newest members of the Benelux Chamber of Commerce. Founded in Shanghai in 2021, APIS Consulting is a cybersecurity and compliance firm helping European companies operating in China manage their information security and data-protection risk. We sat down with founder and CEO Antoine Pilarczyk to learn more about the company and the market it operates in.

 

 

Who is APIS Consulting?

APIS Consulting is a cybersecurity and compliance firm I founded in Shanghai in 2021, we just celebrated our five-year anniversary. The idea came from my first job here, as head of cybersecurity, when I noticed how fast Chinese regulation was moving, and how few foreign companies were aware of it. A lot of them assumed being GDPR-compliant in Europe meant they were compliant in China too, which isn't true. That gap is why I started the company.

We mainly work with small and mid-sized European subsidiaries in China, real local operations without a large internal cybersecurity or compliance team. Companies usually come to us when headquarters starts asking questions that are hard to answer locally, or when they simply want reassurance that the China operation is properly protected. I'm a certified ISO 27001 Lead Auditor and Lead Implementer, so I make sure that the work stays practical. We don't just hand over a policy document, we help clients implement it from A to Z.

 

What are the key factors that set APIS Consulting apart from other cybersecurity consultancies operating in China?

Most companies already have access to different types of support: an IT provider, a legal adviser, a global security team, or sometimes all three. Each of them brings valuable expertise, but the difficulty for many smaller subsidiaries is connecting those different areas locally. An IT provider may manage the infrastructure, while a legal adviser focuses on regulatory requirements and the headquarters security team applies global standards. The challenge is making sure all of those pieces actually work together on the ground in China.

That is where APIS Consulting comes in. We combine technical security and compliance, and we work in French, English, and Mandarin, which helps us communicate effectively with headquarters, local management, IT teams, and external partners, without important information getting lost along the way. Because we are based in Shanghai, we also understand the local technology environment, regulatory expectations, and operational constraints.

The idea is simple: one local point of contact that can connect the technical, regulatory, and business sides of cybersecurity.

 

 

Can you walk us through APIS Consulting's core service offerings and how they come together to support your clients?

We work around three pillars that build on each other: audits, governance and compliance, and managed security services. First off, the audit shows where a company stands today, technically, procedurally, everything, and comes back with findings ranked by how critical and how costly they are to fix. From there, our governance and compliance work, like virtual CISO or DPO services, helps decide what needs to improve, often for just one day a week or a month rather than a full-time hire. Finally, managed services then keeps those protections running day to day, from help-desk support to full security monitoring.

These three areas are closely connected. An audit shows where the company is today, governance helps decide what needs to improve, and managed services help keep those protections running.

 

What are the most common misconceptions and blind spots you see among foreign companies operating in China?

The one we hear constantly is: "we're GDPR-compliant in Europe, so we must be compliant in China too." GDPR is a good foundation, but it doesn't carry over automatically. China has its own rules on personal information, data transfers and, in some cases, localization or security assessments.

On the ground, that often shows up as a lack of visibility into where data actually is and how it moves, including what's being transferred from China back to headquarters. Additionally there are tools and processes that grew informally over time, like business run over WeChat or procedures that only exist in English and were never really communicated locally.

There's also a belief that some companies are too small to be on the radar. That's changing fast, as since the start of this year penalties have increased roughly tenfold, and authorities are becoming much more strict. I have clients that despite having lower staff numbers, manage very large of personal data records, meaning that its not the size of the company that matters, but the size and the sensibility of what they handle.

 

 

Can you share a success story where APIS Consulting helped a client strengthen their security?

We worked with a manufacturing company after one of its own customers, a leading global smartphone manufacturer, started pushing them to strengthen their cybersecurity. We audited their systems, built a practical action plan prioritized by risk and business impact, and helped them improve procedures, train staff and put more formal controls in place. The goal wasn't just to produce a report, it was to help them show their customer that the risks were understood and there was a realistic plan to address them. In the end, their customer was satisfied, our client came away with a lot more confidence in their overall security approach, and secured in the end a multi-million dollar contract.

 

Looking ahead, what emerging cybersecurity trends or regulatory developments should companies in China be preparing for?

Three things stand out:

  • Stronger regulatory scrutiny, with companies increasingly expected to show documented controls rather than a policy sitting in a drawer;

  • Cross-border data transfers, which will keep mattering more for any company moving data outside China;

  • AI governance, since companies are rolling out AI tools faster than their internal policies can keep up, and AI can access almost everything in a system if it isn't properly controlled.

My advice is not to treat compliance as just a cost to minimize. Done properly, cybersecurity and compliance build trust with customers, headquarters and partners,and in China, that's increasingly becoming a competitive advantage.