News and updates from Maple

What is ISO 27001, and why does it matter for your IT provider? image

What is ISO 27001, and why does it matter for your IT provider?

Earlier this week we announced that Maple Technology has achieved ISO 27001 accreditation. It's one of the most widely recognised security standards in the world, but it's also one of the most misunderstood. Here's what it actually is, what it took to achieve, and why it should matter when you're choosing who manages your IT.

What ISO 27001 actually is

ISO 27001 is an international standard for an Information Security Management System, or ISMS. Rather than certifying a single product or a one-off security check, it certifies how an organisation manages information security as an ongoing discipline: how risks are identified, how controls are chosen and implemented, how incidents are handled, and how the whole system is reviewed and improved over time.

It covers areas including:

  • Risk assessment and treatment
  • Access control and identity management
  • Supplier and third-party risk
  • Incident response and business continuity
  • Physical and environmental security
  • Staff awareness and training
  • Continual improvement and internal audit

Achieving certification means an accredited external auditor has examined our policies, our processes, and the evidence that we actually follow them, not just that they exist on paper.

What the process actually involves

This is the part that surprises people. ISO 27001 isn't primarily about buying new security tools or overhauling how you work. For us, it was largely about documentation, evidence, and consistency: making sure that what we do day to day, and what we say we do, are demonstrably the same thing, every time, for every client.

That meant formalising risk assessments, tightening how access is granted and reviewed, and building an audit trail across processes that were often already sound in practice but hadn't been consistently recorded. It's rigorous, and it takes sustained commitment across a business, not just from one department.

Why it matters for your business

If you outsource your IT, you're extending your own risk surface to include your provider. ISO 27001 certification gives you independent assurance that the organisation managing your systems and data has:

  • A structured, tested approach to identifying and managing security risk, not an ad hoc one
  • Documented, auditable processes rather than informal practices that vary by staff member
  • A commitment to ongoing review, not a one-off assessment that goes stale
  • Accountability built into how incidents and access are managed

For businesses in regulated sectors particularly, this also simplifies your own due diligence. When a client, auditor, or regulator asks how your IT provider manages information security, "we're ISO 27001 certified" is a stronger answer than a description of internal practices they can't independently verify.

Considering it for your own organisation?

If you're thinking about pursuing ISO 27001 yourself, the biggest piece of advice we'd offer is to start by mapping what you already do against the standard before assuming you need to change how you work. Most organisations are closer than they think; the gap is usually in evidence and consistency, not practice. Treat it as a genuine improvement exercise rather than a certificate to acquire, and it pays off well beyond the audit itself.

We'll be covering Cyber Essentials Plus, our second accreditation, in the next post.