惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
宝玉的分享
宝玉的分享
量子位
Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
J
Java Code Geeks
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
Blog — PlanetScale
Blog — PlanetScale
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
S
SegmentFault 最新的问题
B
Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 【当耐特】
小众软件
小众软件
The Cloudflare Blog
Y
Y Combinator Blog
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
IT之家
IT之家

AAG IT Support

Welcoming Debar to AAG | AAG IT Support Important Changes to Cyber Essentials | AAG IT Support IT Support Pricing Guide | AAG IT Support Welcoming H Harrold & Sons to the AAG Family | AAG IT Support AAG Build Computing Lab in Historic School | AAG IT Services Careers – Strategic Technology Advisor | AAG IT Support Why Most Businesses Don’t Need AI (yet) | AAG IT Support Welcoming Edwards Chartered Accountants to the AAG Family | AAG IT Support How to Check Your Microsoft Secure Score | AAG IT Support How AAG Uses AI to Cut the Friction for Our Customers AI vs Automation: The Difference Most Businesses Get Wrong | AAG IT Support Welcoming Klingspor Abrasives to AAG | AAG IT Support Why AI Alone Doesn’t Improve Productivity | AAG IT Support AAG Welcomes SDE Group Onboard | AAG IT Support How automation stops employees doing low-value work | AAG IT Support 70% of employees are using AI tools at work | AAG IT Support The Microsoft 365 Built-In Security Feature: Microsoft Purview | AAG IT Support AAG growth continues as we welcome GWB Harthills | AAG IT Support Employee of the Quarter - Ben Bedford | AAG IT Support Welcoming Jake Taylor to the AAG service desk | AAG IT Support
How AAG IT retained ISO27001 certification in 2026 | AAG ...
Mark Swift · 2026-07-22 · via AAG IT Support

Why ISO27001 Matters to Us

For almost a decade, we have continually reviewed, tested and improved the processes we use to protect AAG, our customers and the information entrusted to us. For a business providing 24/7 Managed IT Support and Cyber Security Services, we believe we should hold ourselves to the same high standards we encourage our customers to adopt.

That’s why we invested in ISO/IEC 27001:2022, and have done for almost 10 years, and why I lead the charge every day to keep our guards up and our processes watertight.

What does retaining ISO 27001 actually involve?

Retaining ISO/IEC 27001:2022 certification is not simply a case of renewing a certificate each year.

You have to demonstrate that information security is actively managed across the business, with the right processes, controls and responsibilities in place.

Our external audit looks closely at how those controls work in practice, including areas such as:

  1. Policies and Procedures
  2. Asset Management
  3. Supplier Onboarding
  4. New User / Leaver Processes
  5. Backup & Disaster-Recovery Plans
  6. Training & Awareness
  7. Risk Assessment & Management

The most important part is that these processes cannot simply exist on paper. It’s a good start if they do, but that won’t be enough.

We need to demonstrate that they are being followed, reviewed and continually improved as the business, technology and risks around us change.

That is one of the (many) reasons we continue to invest in ISO 27001. Information security is never finished, and maintaining the standard helps make sure we continue to challenge ourselves rather than becoming complacent.

What does our ISO 27001 certification mean for our customers?

Our customers trust us with access to some of the most important parts of their businesses, from their IT infrastructure and Microsoft 365 environments to sensitive business information.

That trust comes with a responsibility to hold ourselves to a high standard.

Our ISO/IEC 27001:2022 certification provides independent assurance that information security is managed through established processes, regular risk assessment and continual improvement.

It means our approach to security does not rely on good intentions or individual actions. We have structured processes in place for identifying risks, managing access, protecting information, responding to incidents and reviewing how effectively our controls are working.

For our customers, it provides additional confidence that the business responsible for supporting and protecting their technology takes the security of its own operations seriously too.

One thing you can do today: stop treating cyber security as a one-off project

One of the biggest lessons from maintaining ISO 27001 for almost a decade is that cyber security is never finished (we all know that).

Businesses change. Employees join and leave. New technology is introduced. Suppliers change. New vulnerabilities are discovered and the ways cyber criminals operate continue to evolve.

The controls that protected your business two years ago may not be enough today.

You do not need to pursue ISO 27001 certification to adopt the same mindset. Start by asking some simple questions:

  1. When did you last review the cyber risks facing your business?
  2. Are the security processes you have documented actually being followed? (Don’t just say “yes” because you think they are either…)
  3. When did your employees last receive cyber security training?
  4. Are you regularly reviewing access, vulnerabilities and the technology being used across your organisation?

Cyber security should be an ongoing process of reviewing, testing and improving the way your business protects its people, systems and information.

How can AAG help strengthen your cyber security?

People are an important part of cyber security, but they are only one part of the picture.

A strong cyber security strategy combines people, processes and technology. That can include regular cyber security awareness training and phishing simulations alongside technical measures such as vulnerability management, penetration testing, Multi-Factor Authentication and incident response planning.

AAG’s Cyber Security Services help businesses understand where their risks are, strengthen their defences and continually improve their security posture.

Whether you are looking to improve your existing security controls, work towards a certification such as Cyber Essentials or ISO 27001, or simply understand where your biggest risks currently sit, the first step is understanding what you have in place today.