Email Level8

contact@level8.solutions

Nick Maiden
Director of Operations & Systems Education

We were pleased to have it confirmed recently that LEVEL8 successfully completed our latest external ISO 27001:2022 surveillance audit, with continuation of certification formally recommended. And in more good news, there were no non-conformities identified, reflecting the years of deliberate, sustained investment in how LEVEL8 manages information security.

ISO 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). It is assessed against a structured, risk-based framework that organisations should use to protect the confidentiality, integrity, and availability of the information they hold. This can include their own data or, crucially, data entrusted to them by clients.

Certification is not a one-time achievement. It requires independent external audits on an ongoing basis, meaning the standard must be actively maintained and continuously improved. Recertification therefore carries more weight than initial certification, as it demonstrates that strong security practices are genuinely embedded in how an organisation operates day to day.

How we achieved recertification

The audit was conducted by Centre for Assessment against the full requirements of ISO 27001:2022 (the most current version of the standard). The auditor’s conclusion was clear: our ISMS is mature, well-embedded, and demonstrates sustained and effective continual improvement.

Several specific strengths were highlighted in the auditor’s report:

  • Leadership commitment. Ownership and accountability for the ISMS sits at senior level, ensuring information security is a strategic priority, never relegated to an afterthought.
  • Robust risk management. We maintain a comprehensive risk register, with risks assessed using likelihood and impact criteria and reviewed regularly in response to operational changes and emerging threats.
  • Strong technical controls. The audit found strong performance across access management, authentication, vulnerability management, backup, and monitoring. This was verified through live system demonstrations and documented procedures.
  • Training and awareness. Security awareness is consistently embedded across the organisation, ensuring everyone understands their responsibilities.
  • Supplier management. We apply rigorous third-party due diligence and maintain ongoing oversight of our supply chain.
  • Continual improvement. Our ISMS and supporting documentation is actively maintained, with each audit cycle used as a driver for further enhancement.

Our resilience was tested and demonstrated

A really interesting aspect of this audit was how we responded to a real-world security incident. Rather than viewing this as a negative, the auditor highlighted it as evidence of a genuinely responsive security posture. The incident was managed with clear investigation, appropriate containment, careful consideration of regulatory obligations, and the implementation of corrective actions. Improvements to our monitoring, awareness, and incident response processes followed. This is exactly the kind of response a well-functioning ISMS is designed to produce.

What this means for our clients

We understand that when organisations decide to work with LEVEL8, they are trusting us with sensitive information, and deserve full confidence that it is being handled responsibly.

ISO 27001 recertification provides that assurance in a concrete, independently verified way. It means our security controls have been scrutinised by an external auditor, our risk management processes have been tested, and our commitment to improvement has been validated. It means that the policies and procedures governing how we handle your data are not just documented, they are actively followed and regularly reviewed.

Today, when data breaches and cyber threats are increasingly common, working with an ISO 27001-certified organisation is one of the clearest indicators that information security is being taken seriously.

This is demonstrated by the LEVEL8 management team who, while certainly viewing recertification as a significant achievement, do not see it as the final destination for our ISMS and related policies and procedures.

The observations raised during this audit, including in areas such as supplier management, joiner/mover/leaver processes, and information classification, will be worked through in the months ahead as part of our ongoing improvement programme. That process of continuous refinement is, in many ways, the point: audits don’t just validate what we do well, but also push us to do better.

We are proud of this result and grateful to everyone across our experienced team, whose diligence makes it possible. And most importantly, we trust that it gives our clients the confidence that their data is in the safest of hands when working with LEVEL8.

To find out more and cover off any specific questions you have about the security of your data when working with LEVEL8, get in touch with us today.