News and updates from Maple

We're ISO 27001 accredited. Here's what that actually means for you. image

We're ISO 27001 accredited. Here's what that actually means for you.

We’ve talked about our ISO 27001 accreditation before, but there’s a difference between saying you’re ISO 27001 accredited and explaining what that actually means for the businesses you support.

For a technology partner, it matters because information security isn’t just about your own systems. If we have access to your users, devices, data or Microsoft 365 environment, the way we manage security becomes part of your wider risk picture.

So, what does ISO 27001 actually mean in practice?

It’s much more than having good cybersecurity

ISO 27001 is the international standard for information security management.

It isn’t a certificate you get for having a firewall, antivirus and a strong password policy.

It’s an independently audited framework for identifying information security risks, putting appropriate controls in place and continually checking that those controls are working.

That covers things such as:

  • Who has access to systems and information, and why
  • How access is granted, changed and removed
  • How security risks are identified and managed
  • How suppliers and technology providers are assessed
  • How security incidents are reported and handled
  • How staff are trained and kept aware of security responsibilities
  • How policies and processes are reviewed
  • How the business responds when something doesn’t go to plan

The important part is the evidence.

It’s not enough for us to have a policy saying how something should be done. We need to be able to demonstrate that the process exists, that people follow it and that it is reviewed.

And it doesn’t stop once certification is achieved. ISO 27001 involves ongoing external audits, alongside our own internal reviews, so the controls have to keep working in practice.

Why does that matter if Maple manages your IT?

This is where ISO 27001 becomes more relevant to our clients.

If we manage part of your technology environment, we’re part of your supply chain.

We may have access to your Microsoft 365 environment, user accounts, devices, systems and information. That means our own approach to information security matters too.

You shouldn’t have to simply take our word for it that we manage that access appropriately.

ISO 27001 gives you independent assurance that our information security management has been assessed against an internationally recognised standard.

For the financial services businesses we work with, that can be particularly useful.

It can make due diligence easier

If you’ve ever completed a supplier questionnaire, you’ll know how often information security comes up.

How do you manage access?

How do you assess suppliers?

How do you handle security incidents?

How do you train staff?

What security policies do you have?

Being able to provide details of our ISO 27001 certification and scope gives you independently audited evidence to support those answers.

It doesn’t replace your own due diligence, but it can make the process considerably easier.

It supports your own security requirements

Our clients are responsible for managing their own information security and regulatory obligations.

But the businesses they work with also form part of that wider picture.

Whether you’re a hedge fund, family office, insurer or professional services firm, you need to understand the risks associated with the suppliers who have access to your systems and information.

Working with a technology partner that has its own independently audited information security framework gives you another layer of assurance when assessing that risk.

It gives you evidence rather than just a promise

There’s a big difference between saying:

“We take information security seriously.”

and being able to demonstrate the processes, controls and evidence behind that statement.

That’s one of the reasons we wanted ISO 27001 to be part of how Maple operates, rather than simply something we could put on the website.

If you need our certification details, scope or supporting information for your own supplier due diligence, audit or compliance processes, we can provide it.

What ISO 27001 doesn't mean

It’s also important not to overstate what certification means.

ISO 27001 doesn’t guarantee that a security incident will never happen. No security framework can do that.

What it demonstrates is that there is a structured approach to managing information security risk, with defined controls, processes and responsibilities, and that these have been independently assessed.

If something does go wrong, the aim is not to rely on improvisation. There should already be a process for identifying the issue, responding to it, recording what happened and learning from it.

That ongoing cycle of review and improvement is a big part of what the standard is designed to achieve.

So, what should you take from it?

If Maple manages your IT, our security practices matter to you.

ISO 27001 is one way of independently demonstrating how we manage that responsibility.

It gives our clients something more useful than a badge: evidence that information security is built into the way we operate, with controls that are documented, reviewed and independently audited.

And if you're currently reviewing your technology suppliers, we're happy to provide the information you need for your own due diligence.

Want to see our ISO 27001 certification details or understand what our certification covers? Get in touch and we'll be happy to talk you through it.