ISO/IEC 27001:2022

International standard for information security management systems. Any organisation that needs to show customers a certified security management system.

15 controls supported. References are Annex A control numbers.

Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

  • Control
    • 5.29Security during disruption
    • 5.30ICT readiness for business continuity
    • 8.14Redundancy of processing facilities
    How we help
    Your Hyper-V workloads run in one of our five data centres and replicate to a second site you choose, giving you a documented alternate processing facility with agreed recovery objectives.
    Evidence you get
    Architecture and RPO/RTO statement, replication health reports, signed records of failover tests.
  • Mapping under review

    Control
    • 8.13Information backup
    • 8.24Use of cryptography
    • 5.33Protection of records
    How we help
    Efficient Cloud Backup writes backups outside your cloud provider to Wasabi object storage, encrypted with a key only you hold and protected with Object Lock (WORM), so nobody can alter or delete them during the retention period, not even an attacker holding administrator credentials.
    Evidence you get
    Backup policy settings, Object Lock retention configuration, restore test records.
  • Mapping under review

    Control
    • 5.29Security during disruption
    • 5.30ICT readiness for business continuity
    • 8.14Redundancy of processing facilities
    How we help
    Health checks switch records to a secondary service when the primary one fails, and on the Enterprise plan your zones are also authoritative on a redundant multi-cloud network, so name resolution has no single provider as a point of failure.
    Evidence you get
    NS delegation showing both networks (Enterprise), zone and failover configuration (console or Terraform), health-check and failover event history.
  • Mapping under review

    Control
    • 8.15Logging
    • 8.16Monitoring activities
    How we help
    Logpush streams every HTTP request, firewall event and Zero Trust access decision to the storage or SIEM you choose, such as R2, with the retention you define.
    Evidence you get
    Logpush job inventory, retention settings, example investigation queries.
  • Mapping under review

    Control
    • 8.20Network security
    • 8.26Application security requirements
    How we help
    WAF, bot management, API protection and DDoS mitigation in front of every internet-facing application.
    Evidence you get
    Security configuration export, monthly threat reports, change history.
  • Control
    • 5.15Access control rules
    • 8.5Secure authentication
    • 8.12Data leakage prevention
    • 8.22Segregation of networks
    • 8.23Web filtering
    How we help
    Access verifies every user and device before they reach an application, Gateway filters web and SaaS traffic, and DLP profiles stop sensitive data such as ID numbers or source code leaving through uploads, SaaS or AI tools.
    Evidence you get
    Access policy export, DLP profiles and incidents, Gateway policy export, access logs.

Tell us what you are preparing for

We reply with the controls we can cover, what stays on your side, and a realistic timeline.

Where are you now?