Certified secure: Our upgrade to ISO 27001:2022

Swiss-style security, independently certified. Required for the banks and health teams we serve.

Certified secure: Our upgrade to ISO 27001:2022

We’re Now ISO 27001:2022 Certified – Here’s What That Means for our Partners & Clients

We’re proud to announce that we’ve successfully transitioned our ISO/IEC 27001 certification to the latest 2022 standard. This marks a significant step in strengthening our information security management systems (ISMS) and reflects our ongoing commitment to protecting the data of our customers, partners, and internal stakeholders.

What’s New in ISO 27001:2022?

The previous version of ISO 27001 was released in 2013. The 2022 update brings a modernized and more adaptive approach to information security. Some of the key changes include:

  • Updated Control Set: The number of controls has been reduced from 114 to 93, now grouped into 4 domains (Organizational, People, Physical, and Technological). This streamlining allows for better alignment with today’s cybersecurity threats.
  • Emphasis on Threat Intelligence and Cloud Security: New controls such as threat intelligence, data masking, and secure coding reflect the realities of modern IT environments.
  • Integration with Other Management Systems: The revised structure aligns more closely with other ISO management standards, making integration smoother across business functions.

Why We Upgraded

While our 2013 certification served us well for many years, the digital landscape has changed dramatically in the last decade. The 2022 revision of ISO 27001 reflects current and emerging risks—especially around cloud computing, remote work, AI, and supply chain security.

We made the decision to upgrade not just to stay compliant, but to ensure our ISMS continues to be relevant, resilient, and forward-looking. Here’s what drove us:

  • Future-Proofing Our Security Posture: Threats today are not what they were in 2013. The updated standard helps us better detect, respond to, and recover from modern cybersecurity challenges.
  • Supporting Responsible Use of AI: As our organization explores AI-driven solutions, data governance and secure processing become even more critical. The new ISO 27001:2022 controls help us put the right guardrails in place—ensuring our use of AI technologies is transparent, ethical, and secure.
  • Meeting Client Expectations: Many of our enterprise customers now explicitly require vendors to be compliant with the latest ISO standards. Transitioning early reinforces our credibility and proactive approach.
  • Strengthening Operational Discipline: The updated framework encourages tighter integration across departments and functions, helping us drive greater consistency and accountability in how we manage information security risks.
  • Enabling Scalable Innovation: With better security practices aligned to the 2022 standard, we’re better positioned to innovate—particularly in AI, automation, and digital services—without compromising data integrity or compliance.

The Transition Process

Moving to ISO 27001:2022 involved a thorough gap assessment, updates to our documentation and policies, and extensive internal training. Here’s a quick overview:

  1. Gap Analysis – We began with an in-depth comparison of our existing 2013-compliant ISMS with the requirements of the 2022 version.
  2. Control Re-mapping – Our information security team carefully restructured our controls to fit the updated Annex A structure.
  3. Policy & Risk Assessment Updates – We revised our risk management methodology, added controls around threat intelligence, and enhanced our incident response mechanisms.
  4. Training & Awareness – All relevant team members were upskilled on the new requirements to ensure operational compliance.
  5. External Audit – Finally, our upgraded system was rigorously audited by an accredited certification body.

Challenges and How We Overcame Them

Every transition comes with its own set of hurdles. For us, aligning our legacy documentation with the new control format was a time-intensive process. Additionally, ensuring cross-functional adoption—particularly for new controls around secure development, AI model integrity, and data masking—required tailored training sessions and workshops.

Thanks to the strong collaboration between our security, IT, and compliance teams, we were able to address these challenges efficiently and stay on track.

What This Means for our Partners & Clients

For our clients and partners, this upgraded certification reaffirms that:

  • We are aligned with global best practices for information security.
  • Your data is managed with enhanced protection against modern cyber threats.
  • Our use of AI and emerging technologies is backed by rigorous controls and ethical standards.
  • Our processes and controls are regularly audited and continuously improved.

We believe that strong information security is not a one-time achievement, but an evolving journey—and we’re proud to keep moving forward with every update and every audit.

Next Steps

Ready to test this architecture on your data?

We validate use cases in 4 weeks via our productized Agentic AI Design Sprint.