Skip to content

By    |    Tue 11 Aug, 2026   |    4 mins read

What our ISO 27001 certification actually proves about how we handle your data

What our ISO 27001 certification actually proves about how we handle your data featured image
             

Most digital agencies are not ISO 27001 certified. The process is expensive, time-consuming, and unlike most compliance exercises, it doesn't end. There are ongoing controls to maintain and a renewal audit every year. Oxygen pursued it anyway, because of who we work with. Our clients include organisations in healthcare, financial services, business services, government, and private equity across APAC and the GCC. Engaging with them means access to patient records, deal data, financial transactions, and internal systems. These organisations have dedicated procurement teams whose job is to verify that any supplier touching their data can be trusted with it. This article is written for those teams.

The short answer to what our certification proves: an independent, accredited auditor has verified that our information security controls meet the requirements of ISO/IEC 27001:2022, the internationally recognised standard for information security management systems. That is categorically different from self-reported compliance. It means a third party looked at how we actually operate and confirmed the controls hold up.

What the standard requires and what certification actually means

ISO/IEC 27001 certification requires an organisation to build and operate an Information Security Management System (ISMS) — a structured framework covering how information is identified, classified, protected, and reviewed. It isn't a checklist you complete once. The standard takes a risk-based approach, requiring ongoing identification of threats, documented controls to mitigate them, and regular reviews to ensure those controls are working. To achieve certification, an organisation must pass an independent third-party audit conducted by an accredited certification body. The auditor tests whether the ISMS meets the standard's requirements in practice, not just on paper.

The 2022 revision of the standard explicitly extended its scope beyond information security to include cybersecurity and privacy protection — directly relevant for clients operating under data protection regimes across multiple jurisdictions. For organisations in healthcare or finance evaluating suppliers, ISO 27001 certification is increasingly a procurement prerequisite, not a nice-to-have. According to Intertek, one of the primary commercial benefits of certification is that it enables organisations to win contracts where certification is a formal requirement. That pressure is real, and it flows downstream to agencies like us.

What changed inside Oxygen when we went through the process

Access controls and permission management

The certification process surfaced risks we hadn't been systematically examining. The clearest example came from access permissions. As Fouad Khalife, our Operations Director, explains: "No one was responsible for periodically reviewing who could access our most important platforms, and we had far too many users with admin rights, usually because granting full access was quicker than waiting for someone to do the specific task. We now run periodic access reviews, with a proper process for requesting each level of permission, so a client always knows who can touch their systems and why."

That kind of drift, where admin access accumulates through convenience rather than necessity, is common in fast-moving agencies. The ISMS framework forced us to treat access as something that requires active justification, not passive inheritance. Every engagement now has documented access policies: who has access, at what permission level, and when that access will be reviewed or revoked. For a client handing over credentials to their CRM, marketing automation platform, or internal data environment, that structure matters.

Security as a day-to-day discipline, not an annual exercise

Compliance programmes that only activate before an audit are a known problem in enterprise security. The standard is designed to prevent that: controls must be maintained continuously, with documented evidence, and the ISMS must be reviewed and updated as risks evolve. We use Drata to manage our control library, upload evidence, assess supplier risk, and run staff training. Device management is enforced through Mosyle, our mobile device management (MDM) platform, which applies password policies, software update requirements, and disk encryption (FileVault) across our hardware fleet. The controls hold between audits because the tooling enforces them automatically, not because someone remembers to check.

This matters to clients not because they need to understand our toolstack, but because it means information security isn't contingent on individual behaviour. The controls are structural. When a project wraps and access needs to be removed, there is a process. When a new tool enters our environment, it goes through a documented assessment. That consistency is what a certification audit is actually testing for.

How certification affects what we build in client environments

Oxygen increasingly builds and automates systems inside client environments — marketing operations infrastructure, CRM architectures, data integrations, AI-assisted workflows. Speed is a feature of that work, but speed without discipline creates risk. An ISMS keeps that honest. Every new tool or integration we build has to answer the same questions the certification process taught us to ask: who has access, where is data flowing, what are the risks, and how are they controlled?

That discipline applies equally when we're building inside a client's environment as when we're managing our own. A client in financial services or healthcare who commissions a CRM implementation or an AI-assisted reporting workflow is not just buying a technical deliverable. They are extending access to a supplier. ISO 27001 certification means that supplier has been audited on how they handle that access — by someone other than the supplier themselves.

The 2022 update to the standard is particularly relevant here. By formally incorporating cybersecurity and privacy protection into its scope, it acknowledges that information security today extends beyond traditional IT perimeters to include cloud tools, third-party integrations, and AI systems. For us, that means our ISMS governance applies as much to a new AI automation tool as it does to a legacy system. The question of how data flows through an AI-assisted process is an information security question, and we treat it as one.

What this means for your vendor security review

For enterprise procurement teams running supplier due diligence, ISO 27001 certification shortens the review cycle in a specific way. Rather than relying on a supplier's self-reported security questionnaire — where the answers reflect what the supplier wants you to believe — certification provides third-party verified evidence of controls. The auditor's job is to verify that what is documented actually matches what is practised. That verification is what certification represents.

In practical terms, when Oxygen is going through a vendor security review with a client in government, healthcare, or financial services, we can provide: our certificate of conformity, documentation of our ISMS scope, evidence of our access control policies, and records of our supplier risk assessment process. We are not asking procurement teams to trust our word on data handling. We are providing audited evidence.

It is also worth being clear about what the certification does not prove. It does not guarantee that a breach will never happen. No certification does. What it demonstrates is that a structured, risk-based approach to information security is in place, that controls are documented and operating, and that an independent auditor has verified this. The residual risk is managed, not eliminated — and that is what a mature ISMS is designed to achieve.

Why we think every agency working in regulated industries should pursue this

We are not suggesting ISO 27001 certification is right for every agency or every client engagement. For smaller projects with no access to sensitive data, the overhead is disproportionate. But for agencies that regularly work inside client systems in healthcare, finance, or government, the calculus changes. The clients in those sectors have enterprise-grade security expectations, and they apply those expectations to their suppliers.

The more honest argument is this: if you are advising clients to become more disciplined, more data-literate, and more systemically governed, your own operations should hold up to the same scrutiny. We work with clients across APAC and the GCC on digital transformation programmes, system implementations, marketing operations and CRM strategy. That work frequently involves us inside their environments. Our ISO 27001 certification means that when a procurement team looks closely at how we handle information, they find a documented, audited answer, not a polished deck.

An agency should be its own best case study. This is one of ours.

Oxygen Content Team's avator'

About the Author

Oxygen Content Team

The Oxygen content team is a collective group of marketers at Oxygen who collaborate on content specific to our services, industry verticals and expertise. Content is peer-reviewed amoungst our team of experts.

Find me on:

New to HubSpot? Oxygen Can Get You Up and Running

Speak with a Hubspot expert about your business requirements

You may also like