Infinite Lambda has achieved ISO 27001 certification, the leading international standard for information security management. The certification was awarded by LRQA following an independent audit of our policies, processes, and controls.
ISO/IEC 27001/2022 sets out the requirements for an information security management system, covering how organisations identify, manage, and reduce risk to the security of their information. It is published by the International Organization for Standardization and recognised worldwide.
LRQA, an accredited external body, examined our policies, processes, and controls directly and confirmed they meet the standard. To keep the certification active, we will be going through regular audits that will attest to us maintaining the same high standards.
Infinite Lambda’s ISO 27001 certification
Our ISO 27001 certification applies to consultancy and managed services across data platform modernisation, enterprise AI deployment, cloud data engineering, analytics, training, and proof of concept delivery.
In practice, being ISO 27001 certified means:
- Knowing what data and systems we hold and making sure only the right people can reach them;
- Having a clear process for spotting and responding to incidents, and holding our suppliers to the same standards we hold ourselves;
- Being prepared to keep operating or recover quickly if something goes wrong, and making sure everyone at Infinite Lambda understands their part in keeping information secure.
The standard itself spans risk management, access control, asset management, incident response, supplier and third-party security, business continuity, and people and training. Given that our work spans data platforms and AI environments, access control and supplier security carry particular weight, since much of what we deliver depends on who can reach a system and how well the platforms and tools underneath it are managed.
Incident response, asset management, and business continuity matter for the same reason. Any project built on cloud infrastructure needs a clear way to detect and respond to problems, alongside a clear picture of the data and systems involved and a plan to keep operating if something goes wrong. People and training close the loop, since all of this depends on the people running these projects understanding their part in keeping them secure.
An important milestone
For Infinite Lambda’s clients and partners, the certification gives independent, third-party assurance that information security is a top priority for us. It shows that the way we handle data and manage risk has been checked by experts outside the business, using a standard that is recognised well beyond our own industry.
As ISO 27001 is increasingly a requirement in enterprise deals and procurement processes, this also matters to us commercially.
Internally, the process pushed us to formalise practices that benefit the business regardless of the certificate itself. Access reviews are now more consistent, incident response has a clearer process behind it, and vendor assessments are more thorough than before. None of this was done for the sake of an audit. These are changes that make us more reliable to work with day to day.
At the enterprise level, security is a matter of collaboration and a shared responsibility.
This certification reflects contributions from people across Infinite Lambda, and keeping it depends on everyone continuing to follow the practices now in place.
As our COO Adriana Stoyanova put it:
The ISO 27001 certification is key to building trust with customers and partners.
An independent auditor examined our practices directly, from how we manage risk to how we control access to our systems, and confirmed they meet a standard recognised internationally.
This is a huge milestone for us as a collective. Getting here took input from people right across the business, and that is what I am really proud of.
– Adriana Stoyanova, COO, Infinite Lambda
Beyond the ISO 27001 certification
We will adhere to the same rigorous standards when it comes to information security. Regular surveillance audits will help keep the certification active and our practices current.
If you have questions about our approach to information security, or want to talk through what this means for a project you have in mind, get in touch.