About Risk3 Consulting

Three decades of protecting Asia's most sensitive conversations.

Risk3 Consulting Limited is an independent Hong Kong consultancy specialising in Technical Surveillance Countermeasures, electronic privacy assurance and counter-espionage investigations. We have done one thing, in one region, since 1992.

Who we are

Risk3 was founded in Hong Kong in 1992, at a time when the region's rise as a financial centre was matched by a corresponding rise in commercial intelligence collection against the firms and families driving it. The founding premise has not changed. Companies in Asia needed countermeasures built on professional intelligence tradecraft, delivered with a private bank's discretion.

Today we serve corporate boards, general counsel, family offices, investment funds, law firms, government bodies and foreign missions across eleven jurisdictions. Our consultants are drawn from technical intelligence, counter-intelligence, digital forensics and investigative backgrounds, and operate under strict confidentiality obligations that survive every engagement.

What we believe

Eavesdropping is a business risk, not a gadget problem. The question that matters is never "is there a device?" but "can the conversations that determine our valuation, our litigation position or our family's safety be overheard, and by whom?" We scope, execute and report accordingly. Clients receive risk findings and business decisions, not equipment read-outs.

Independence is a control. We sell no hardware, install no systems, and accept no commissions or referral fees. A provider who profits from selling you equipment has an incentive to find problems that equipment solves. Our only deliverables are assurance, evidence and advice, which is why our findings are trusted by boards, insurers and courts.

Discovery is the beginning, not the end. A discovered device raises immediate questions of attribution, exposure and response. Because Risk3 combines TSCM with investigations, digital forensics and eDiscovery capability, the same team that finds a compromise can determine what was taken, who benefited, and how to support legal action, without briefing a second firm into your most sensitive matter.

How we work

Every engagement begins with a confidential consultation, usually with a principal, director or counsel. We establish what information is at risk, where it is discussed, and who would benefit from collecting it. From that threat model we scope a proportionate engagement, a single pre-meeting inspection, a multi-site electronic privacy audit, or a standing regional programme.

Fieldwork is conducted by senior consultants using professional-grade detection equipment and a documented methodology, typically outside business hours and under cover arrangements where required. Engagements conclude with a written report drafted for decision-makers: findings, exposure assessment, and prioritised remediation, in language a board can act on and a court can rely on.

Where we operate

Risk3 is headquartered in Hong Kong and operates throughout Asia-Pacific: Singapore, Macau, Mainland China, Japan, South Korea, Thailand, Malaysia, Indonesia, the Philippines and Australia. Regional work is coordinated from Hong Kong to a single standard of methodology, confidentiality and reporting, whether the environment is a Central boardroom, a Tokyo deal room or a family compound in Jakarta.

Principles of Engagement

The standards every client can expect.

/ 01

Absolute Discretion

No client lists, no logos, no references without written consent. Cover arrangements, unmarked equipment and after-hours work as standard. What we learn on an engagement stays inside it, permanently.

/ 02

Senior-Led Delivery

The consultant who scopes your engagement is the consultant who leads it. We do not subcontract fieldwork or delegate sensitive matters to junior staff.

/ 03

Defensible Method

Documented methodology, evidential handling standards and reporting designed to withstand cross-examination. Several of our consultants have given expert evidence in commercial disputes.

/ 04

Proportionate Scope

We recommend the engagement your threat model justifies, no more. Clients are told when a concern does not warrant our involvement.

/ 05

Counsel Compatibility

We routinely work under direction of external counsel, preserving privilege and ensuring technical findings integrate cleanly into legal strategy.

/ 06

Regional Consistency

One methodology, one confidentiality standard and one reporting format across all eleven jurisdictions, coordinated centrally from Hong Kong.

What we will not do

A countermeasures practice should be judged by its refusals as much as its capabilities. Risk3 does not conduct surveillance of any kind, for anyone. We do not sell, install or take commission on equipment. We do not accept work requiring unlawful access to premises, devices or data in any jurisdiction. We do not act against existing clients, and we do not act for sanctioned parties. Enquiries that ask for any of these are declined, and the enquiry itself stays confidential.

The full statement of governance, vetting, insurance and conflict-check practice is on The Firm page, written so that a general counsel can verify it before the first call.

Thirty years, briefly

  • 1992

    Practice established in Hong Kong, as the region's growth as a financial centre drew a matching growth in commercial intelligence collection.

  • 2000s

    Regional expansion across Southeast and North Asia, following clients' deal flow, disputes and family footprints.

  • 2010s

    Capability deepened alongside affiliated specialist practices in digital forensics, eDiscovery and expert witness services.

  • Today

    Eleven jurisdictions, one methodology, one standard of discretion. The work has changed instruments; it has never changed purpose.

Next Step

If the conversation matters, protect it before it happens.

Consultations are free, confidential and answered by a senior consultant.

Detect · Defeat · Nullify

Call now Confidential enquiry