How AAG IT retained ISO27001 certification in 2026
AAG IT Services has successfully retained its ISO/IEC 27001:2022 certification, following another rigorous external audit of our Information Security Management System. Huge well done (and thanks) to everyone at AAG, for pulling out all the stops under pressure.
Why ISO27001 Matters to Us
For almost a decade, we have continually reviewed, tested and improved the processes we use to protect AAG, our customers and the information entrusted to us. For a business providing 24/7 Managed IT Support and Cyber Security Services, we believe we should hold ourselves to the same high standards we encourage our customers to adopt.
That’s why we invested in ISO/IEC 27001:2022, and have done for almost 10 years, and why I lead the charge every day to keep our guards up and our processes watertight.
What does retaining ISO 27001 actually involve?
Retaining ISO/IEC 27001:2022 certification is not simply a case of renewing a certificate each year.
You have to demonstrate that information security is actively managed across the business, with the right processes, controls and responsibilities in place.
Our external audit looks closely at how those controls work in practice, including areas such as:
- Policies and Procedures
- Asset Management
- Supplier Onboarding
- New User / Leaver Processes
- Backup & Disaster-Recovery Plans
- Training & Awareness
- Risk Assessment & Management
The most important part is that these processes cannot simply exist on paper. It’s a good start if they do, but that won’t be enough.
We need to demonstrate that they are being followed, reviewed and continually improved as the business, technology and risks around us change.
That is one of the (many) reasons we continue to invest in ISO 27001. Information security is never finished, and maintaining the standard helps make sure we continue to challenge ourselves rather than becoming complacent.
What does our ISO 27001 certification mean for our customers?
Our customers trust us with access to some of the most important parts of their businesses, from their IT infrastructure and Microsoft 365 environments to sensitive business information.
That trust comes with a responsibility to hold ourselves to a high standard.
Our ISO/IEC 27001:2022 certification provides independent assurance that information security is managed through established processes, regular risk assessment and continual improvement.
It means our approach to security does not rely on good intentions or individual actions. We have structured processes in place for identifying risks, managing access, protecting information, responding to incidents and reviewing how effectively our controls are working.
For our customers, it provides additional confidence that the business responsible for supporting and protecting their technology takes the security of its own operations seriously too.
One thing you can do today: stop treating cyber security as a one-off project
One of the biggest lessons from maintaining ISO 27001 for almost a decade is that cyber security is never finished (we all know that).
Businesses change. Employees join and leave. New technology is introduced. Suppliers change. New vulnerabilities are discovered and the ways cyber criminals operate continue to evolve.
The controls that protected your business two years ago may not be enough today.
You do not need to pursue ISO 27001 certification to adopt the same mindset. Start by asking some simple questions:
- When did you last review the cyber risks facing your business?
- Are the security processes you have documented actually being followed? (Don’t just say “yes” because you think they are either…)
- When did your employees last receive cyber security training?
- Are you regularly reviewing access, vulnerabilities and the technology being used across your organisation?
Cyber security should be an ongoing process of reviewing, testing and improving the way your business protects its people, systems and information.
How can AAG help strengthen your cyber security?
People are an important part of cyber security, but they are only one part of the picture.
A strong cyber security strategy combines people, processes and technology. That can include regular cyber security awareness training and phishing simulations alongside technical measures such as vulnerability management, penetration testing, Multi-Factor Authentication and incident response planning.
AAG’s Cyber Security Services help businesses understand where their risks are, strengthen their defences and continually improve their security posture.
Whether you are looking to improve your existing security controls, work towards a certification such as Cyber Essentials or ISO 27001, or simply understand where your biggest risks currently sit, the first step is understanding what you have in place today.
ISO27001 Frequently Asked Questions
What is ISO 27001 and why should I care?
ISO 27001 is the gold-standard framework for information-security management. Nail it, and you prove to customers, partners and regulators that you guard data with the upmost care – boosting trust and cutting your risk of costly breaches.
How long does certification take?
It entirely depends on your starting line. For a small-to-midsize business with basic processes, I’d outline 3 months, which will cover gap analysis, docs, training and mock audits, then a further few weeks for the external audit itself.
What costs are involved for ISO accreditation?
You’ll factor in: consultant fees (if you bring in help), tooling (e.g. risk-register software), staff time for training and process updates, plus certification-body charges. Think of it as an investment in peace of mind and competitive edge.
Do I need an external consultant for ISO27001?
You can go at it solo if you’ve got the in-house savvy. But we always recommend a guide who’s walked the path before – cuts your learning curve in half and stops you reinventing the wheel.
What’s a Statement of Applicability (SoA)?
It’s your master checklist of controls (like access management, encryption, logging) you’ve chosen to apply, and why. The auditor will review this to make sure every control is justified, implemented and tested.
How often must we review and update our ISMS?
At a minimum, you review your ISMS (Information-Security Management System) annually, along with quarterly management reviews, risk assessments and improvement tracking. In addition, whenever you roll out big changes, new services, M&A, or regulatory shifts. And you run a full internal audit at least once a year
What's an OFI?
An Opportunity For Improvement isn’t a red card, it’s a friendly nudge to tighten up a process or doc. Fix it pronto, log it in your improvements tracker to resolve the issue, and you’ll sail through your next audit.
What’s the biggest pitfall of ISO27001 certification?
Letting your ISMS gather dust after certification. Treat it like a living organism: nurture it with reviews, updates and ongoing training, or it’ll wilt, and so will your security posture.
Related stories
Browse more articles from our experts and discover how to make better use of IT in your business.
Welcoming Debar to AAG
We're delighted to welcome Debar as a new partner of AAG, delivering IT support in Bradford for their growing manufacturing business. Read more
Important Changes to Cyber Essentials
Cyber Essentials renewals in 2026 may require more preparation than in previous years. Read more
Welcoming H Harrold & Sons to the AAG Family
AAG IT Services welcomes Sheffield security specialist H Harrold & Sons as a new managed IT support client, strengthening IT reliability, Microsoft 365 and cyber security. Read more






