TecSec has completed a rigorous three-day assessment through the British Standards Institute and was awarded the certification on the 16th of May.

 

What is the ISO 27001 certification?

The ISO 27001 certification is an internationally recognised standard to protect vital information assets, such as financial, employee and customer data.

To achieve this aim, the ISO 27001 standard mandates requirements for establishing, maintaining, and continually improving an Information Security Management System (ISMS).

At the core of the ISO27001 standard is understanding and documenting what data is being protected, the risks to that data, and how you intend to minimise those risks. The standard also helps firms to review and refine these methods, protecting them in the future.

The accreditation covers a wide scope of I.T. and security services, including managed IT and professional services, cyber security and training, the protection of personal information, and backup and disaster recovery.

We’ve held ISO27001 for three years, first by passing the initial certification audit, two of BSI’s surveillance audits, and now a re-certification audit.

The audit itself, which takes place over three days, involves the British Standards Institute assessment board examining all aspects of our information security management system.

The ISO 27001 has been adopted by many major international organisations across the world, most commonly with companies that provide I.T. services or carry sensitive data. Examples include Microsoft, Amazon, and Dropbox.

Compliant or Certified?

Compliance simply means that an organisation adheres to the standard, whereas certification means the provider’s processes and data controls are regularly and independently audited.

Not all certifications are the same. TecSec has always made sure to be accredited by BSI, an auditing company certified by UKAS (the United Kingdom Accreditation Service). UKAS is appointed by the government to be the official agency authorised to assess the ability and competence of organisations that provide certification, testing, inspection, and calibration services.

Phill McManus, our technical director, has made this statement following our recent re-accreditation:

We are thrilled to have achieved this important certification for another three years. We want to demonstrate our commitment to the highest standards of information security, especially given the evolving risks posed by worldwide changes and the recent rise in threat actors. Accreditations like this attest to our skills and expertise from many years of experience in the industry, and are why our clients place their data and trust in the hands of our organisation“.

Why are TecSec certified?

Choosing a provider with UKAS accredited ISO27001 will give you the highest levels of assurance that your information will be protected. Due to the increasing demand from organisations to get ISO certified, many “one-stop-shop” certification businesses have emerged to fulfil this demand. These companies promise low prices and quick certification. However, many clients will not recognise an ISO certification if it comes from a non-UKAS accredited company, which means missing out on potential contracts or lengthening tender processes.

Going through the ISO process proves that TecSec consistently delivers an excellent standard of customer satisfaction. Getting our UKAS accredited certification announces to our clients that we are taking the standards seriously.

The certification is also an effective way to validate ourselves as a provider and identify that we offer high quality and trustworthy data security practices. At TecSec we use this certification to provide our clients with a trust assurance that not only demonstrates that their data is being handled with integrity but also proves that our security strategies and policies are continually developed and tested to further enhance the protection of their data.

ISO 27001 also reduces the risks faced by TecSec. There are substantially reduced risks of security breaches under the certification, with damages from breaches also being mitigated and potential breakthroughs being tracked faster and eliminated earlier.

We at TecSec firmly believe that implementing and operating an Internet Security Management System continues to have a real and tangible effect on our business.

We know that ISO27001 isn’t appropriate for all businesses, but we do recommend that every business have at least an ISMS in place.

If you’re interested in implementing an ISMS in your business, IAMSE is the best place to start and is designed with SMEs in mind, both in terms of price and structure.

TecSec is an IAMSE certification body and can help you implement and maintain a bespoke ISMS for your business. This will give you appropriate security against most cyber threats to your business, give you public attestation that your business takes data seriously, and will give you peace of mind that your business is protected.

TecSec are qualified providers of cyber security services, and are endorsed by seven separate UK police forces. We can provide affordable cyber security training of the kind mentioned in this article to help prevent your staff from falling victim to phishing emails, whether they be targeted or automated.

If you would like to organise a conversation with us, please call us at 0114 223 8000 or email us at info@tecsec.co.uk