How Inavate helped Blend achieve ISO 27001 certification.

Blend

Maintaining robust information security is paramount for the smooth operation of any modern business within the digital landscape. Mike Thomas, the Technical Director at Blend, understood the importance of implementing an ISO 27001 certified information security management system (ISMS) to meet and exceed obligations as a member of the Hubspot Partner program and provide assurance to Blend’s clients.

With an extensive background in engineering, hosting infrastructure and involved in companies that were already ISO 27001 certified, Mike knew he would require the support of an expert consultancy to collaborate with to implement certification at Blend. As a growing inbound demand generation and HubSpot partner agency, an external consultancy would provide the expertise to enhance policies already in place and help to develop a robust framework.

Mike turned to tech networking groups for recommendations of consultants to work with. Inavate, a trusted consultancy renowned in the industry, came highly recommended. Inavate’s proven track record working with agencies similar in size and experience, coupled with their expertise in achieving ISO 27001 certification, made them the perfect choice for Blend.

Bespoke ISO 27001 implementation

“We wanted to work with a consultancy to help with implementation and support running the ISMS while plugging any knowledge gaps,” explains Mike.

“Unlike other companies offering automated processes, Inavate took a personalised approach guiding us through the why’s and how’s of the implementation process. Inavate aimed to maximise the benefits of the certification rather than treating it as a checkbox exercise and provided a bespoke business focussed and cost-effective solution, avoiding the outlandish quotes received from other providers,” continues Mike.

“Inavate helped me convince fellow members of the leadership team that ISO 27001 and working with Inavate would be of benefit and offer a tangible outcome,” says Mike.

“As a small business, it made sense to outsource to a consultancy, and Inavate offered the continued partnership and expertise we were looking for,” adds Mike.

Conducting 5D lifecycle to align ISMS with business strategy

Inavate conducted a comprehensive ISMS implementation for Blend, covering all aspects of the 5D lifecycle covering:

  • Defining business goals and supporting security objectives
  • Designing the management system to achieve the security objectives
  • Deploying controls after conducting risk assessments
  • Demonstrating by conducting internal audits
  • Developing the system by measuring, reviewing and improving the ISMS

Inavate played a vital role in creating ISMS-related documents, including risk assessments, information asset lists, corrective action plans, ISMS manuals, and legal registers. The consultancy also assisted with policy creation, delivered training and internal audits, and provided guidance during the external ISO 27001 certification audit.

Mike says: “Collaboration with Inavate extended beyond the implementation phase. We had some existing policies, and we worked with Inavate on the finer details of the written policies. Inavate also ensured ongoing partnership post-certification, addressing the need for internal audits without Blend employees having to go through rigorous training to become qualified information auditors.”

Plugging the knowledge gap

“We received valuable advice on relevant software products and services. Specifically, we were guided on what to consider when selecting a learning management system and to provide extensive training and fill the knowledge management gap within our team. Inavate are vendor agnostic, however based on their recommendations, we opted for 360 learning,” comments Mike.

“Inavate shared their expertise on implementing technical control solutions, such as mobile device management for efficiently managing a fleet of devices. These insights proved to be valuable, adding significant value to tackling our challenges,” adds Mike.

Continual improvement through internal audits

Mike comments: “We received ISO 27001 certification a few months ago now, as yet, we have not had to conduct internal audits. I am confident in the responsiveness and reliability of Inavate. Knowing that they will be there to assist me when the time comes is extremely reassuring. We will be in contact when the internal audit rolls around!”

A trusted ISO 27001 consultant

Finding a trusted consultant with the right expertise is a priority to ensure information security compliance.

Mike concludes: “With their small size and flexibility, Inavate meticulously honed their deliverables to meet our specific requirements. They proved to be nimble and adaptable – exactly what we were looking for in a consultancy.”

“Inavate’s invaluable advice, when in the thick of implementation, got us certified successfully,” adds Mike.

About Blend

As a top HubSpot Partner website agency, Blend helps businesses grow their pipeline through exceptional HubSpot websites.

Blend has built an agency that specialises in true B2B inbound demand generation that leverages HubSpot websites to generate pipeline. Martech can no longer be considered separately from the other tech that powers a business, B2B websites and marketing must focus on generating pipeline and aims to help companies achieve a frictionless customer experience.