lead-forensics Skip to main content

Net Platforms

Every IT provider says they take security seriously. That claim is rarely false, but it’s also not something an outsider can check. Net Platforms became certified to ISO/IEC 27001:2022 this year, and it’s worth explaining why that distinction between saying something and being able to prove it matters to a business about to hand over financial records, client details or full access to its network. 

What ISO 27001 assesses 

ISO/IEC 27001 isn’t a product, and it isn’t a list of software a business has installed. According to ISO, which publishes the standard jointly with the International Electrotechnical Commission, conformity means an organisation has put a system in place to manage the risks connected to the data it holds, built on defined practices the business commits to in advance. That system, known as an information security management system, gets assessed against three principles ISO calls ‘confidentiality’, ‘integrity’ and ‘availability’. Confidentiality means only the right people can reach the data. Integrity means the data hasn’t been altered or deleted, by accident or otherwise. Availability means it’s there when it’s needed, which sounds obvious until a server goes down and the backups turn out to be months out of date. 

Certification bodies carry out surveillance audits on an ongoing basis, checking the system is still being followed months and years after sign-off. That ongoing scrutiny is what turns certification into proof, not just a claim. A policy that exists on paper looks identical on a website to one that’s lived day to day. The audit is what tells them apart. For business owners weighing up IT provider certifications, that distinction is the entire point. 

The distance between certified and reassuring 

Plenty of IT providers will tell you they prioritise security. Fewer can show an independently audited management system behind that claim. Getting certified means opening internal processes to a third party with no commercial incentive to sign it off, unlike a website claim, which costs nothing to make and answers to nobody. That difference matters more than it might first appear, because organisations are increasingly demanding proof, not just reassurance. The pattern shows up in procurement. According to the government’s Cyber Security Breaches Survey, 11% of UK businesses now require their suppliers to hold a security certification, a figure that climbs to two in five among large businesses but stays low across smaller ones. Put simply, most small and medium businesses aren’t asking their IT provider the one thing that would tell them most about how that provider treats their data. 

Cyber Essentials itself sets a genuinely useful baseline: five technical controls, covering firewalls, secure configuration, access control, malware protection and patching. Every business should have these in place regardless of who supports their IT. It’s renewed annually, which confirms those five controls are still there. ISO 27001 goes further. Where Cyber Essentials confirms that a fixed set of controls is in place, ISO 27001 requires an organisation to keep reassessing whether those are even the right controls at all, as the business and the risks around it change. A checklist can be satisfied once and then quietly go stale. A system that has to keep re-justifying itself is harder to let slip without anyone noticing. 

It’s tempting to assume all this only applies to large, heavily regulated organisations. It doesn’t. The most recent ISO Survey puts the number of valid ISO/IEC 27001 certificates at over 96,000 worldwide, covering nearly 180,000 sites and spanning small firms and large ones across manufacturing, professional services and technology alike. 

Yet the government’s own Cyber Security Breaches Survey found that only 11% of UK businesses formally require their suppliers to hold any security certification at all, a figure that climbs to two in five among large businesses but stays low across smaller ones. Put simply, most small and medium businesses aren’t asking their IT provider the one thing that would tell them most about how that provider treats their data. 

What it means for how your systems get treated 

None of what follows is exotic. It’s the discipline any competent IT provider should have anyway. The difference is that ISO 27001 requires proof it’s still happening, rather than proof it was set up once and left alone. Every change to a system gets logged and justified, because unlogged changes are how small mistakes turn into incidents nobody can trace. Access to client data gets reviewed periodically, because a former employee’s login left active for months is one of the more ordinary ways a breach starts. Incident response gets tested regularly, because the worst time to discover a plan has a flaw is during the incident it was meant to cover. Backups are checked for whether they would restore, not just whether they ran overnight, because a backup that ran but doesn’t restore is no better than no backup at all. 

Getting there meant applying that same discipline to our own systems here at Net Platforms, documenting how client data is accessed, backed up and reviewed internally, and having all of it evidenced to an external auditor, not just written down once and left in a drawer. You can read more about how the business has grown since 2004 on our about us page. It’s a slower, more deliberate way of running IT than reacting to problems as they surface. That’s rather the point of it. 

What’s worth asking any provider 

Everything above is only useful if it changes what you ask a provider, replacing assumption with evidence. 

  • Is the certification issued by an accredited, independent body, and can they show you the actual certificate rather than just the logo? 
  • What’s covered by it? Some certifications apply to one part of a business, not necessarily the systems that touch your data. 
  • How often does it get reviewed, and what would happen if a surveillance audit found a problem? 
  • Is your organisation’s information specifically inside the scope of their management system, or is the certificate about their own internal operations only? 

A provider who can answer all four without hesitation is telling you something real about how they work. One who can’t is telling you something too. 

If you’d like to see how that plays out day to day, our cyber security page sets out the practical measures behind the certification. 

Secret Link