What is ISO/IEC 27001?
ISO/IEC 27001 is an internationally recognised standard for information security management systems. It provides a framework for identifying and managing information security risks through appropriate processes and controls.
2nd September 2026
Roughly a 4 minute read by
We’re thrilled to share that Engage has achieved ISO/IEC 27001 certification.
Achieving ISO/IEC 27001 gives our clients independent assurance that we have the right processes and controls in place to protect information, manage risk and build a resilient business.
ISO/IEC 27001 is the internationally recognised standard for information security management systems (ISMS). And while protecting client data is a big part of it, the standard goes much further.
It looks comprehensively at how information and risk are managed across our agency, from the tech and systems we rely on to physical security, business continuity and even how information is handled within our office.
To achieve certification, we had to demonstrate to an independent external auditor that Engage meets the requirements of the standard. That meant gathering evidence of our processes and controls before progressing through two stages of external audit with A-LIGN.
Ultimately, it comes down to assurance. For many organisations, ISO/IEC 27001 is already an important part of supplier due diligence. Achieving certification gives our clients an internationally recognised, independently audited benchmark for how we manage information security.
It means greater confidence in the processes and controls behind the work we do together. Greater assurance that we’re thinking seriously about risk and resilience. And for prospective clients, one less unknown when assessing Engage as a digital partner.
According to Matt Wilkinson, Head of Engineering, one of the most valuable parts of the process has been looking beyond information security alone and thinking more broadly about risk and resilience.
What happens if a critical system becomes unavailable? How quickly can we recover from a major incident? How do we make sure Engage can continue delivering for clients when something unexpected happens? Disaster recovery and business continuity form an important part of that thinking.
"It’s made us think more widely about risk. If we lost everything tomorrow, how would we get back on our feet as quickly as possible? Our clients need to know we’re dependable, and the framework helps us make sure we’re building that resilience into the business."
This is a key distinction. No organisation can credibly promise that nothing will ever go wrong. What we can do is make sure we understand our risks, take appropriate steps to manage them and have robust plans for responding when the unexpected happens.
There was another principle we were determined not to lose sight of while working towards certification: security processes have to work for the people using them.
It would be easy to introduce more approvals, more layers and more rigid processes in the name of security. But if a process makes it unnecessarily difficult for someone to do their job, the answer isn’t always to police it more heavily; sometimes the process itself needs to change.
ISO/IEC 27001 sets out what organisations need to achieve, without prescribing exactly how every business must get there.
That has allowed us to build security into the way Engage works, finding approaches that manage risk without introducing unnecessary barriers for our teams or slowing down the work we do for our clients.
For us, that balance is crucial. Strong information security shouldn't come at the expense of a culture that empowers a team to do their best work.
If you’d like to understand more about our ISO/IEC 27001 certification, our approach to information security, or what this means for your organisation, get in touch.
ISO/IEC 27001 is an internationally recognised standard for information security management systems. It provides a framework for identifying and managing information security risks through appropriate processes and controls.
It provides independent assurance that Engage has established processes and controls for managing information security and protecting information. Our approach has been independently audited against the requirements of the standard.
No. As Matt highlighted, the standard takes a much broader view of information security and risk, including areas such as physical security, business continuity and disaster recovery.
Certification isn't a one-off exercise. Maintaining the standard requires an ongoing approach to reviewing risks, maintaining controls and continually improving our information security management system.
25th August 2026
13th August 2026
12th August 2026
11th August 2026