Over the last several months, our team has been having some (occasionally vigorous) conversations about AI. Not whether to use it, but how to use it well. Through our early experiments with AI, we had proven to ourselves that its use brings significant benefits when combined with cybersecurity expertise. However, AI also introduces new risks that need to be carefully managed. I wanted to share where we’ve landed so far.
Category: ISO 27001
Stay ahead: Strengthen your business with third-party risk management
With the fast-paced business style, organisations nowadays heavily rely on third parties such as vendors, suppliers, logistics partners, cloud services providers, etc. These partnerships can offer great benefits but also could expose your organisation to risks. That’s where third-party risk management (TPRM) comes into play. TPRM provides a structured approach to evaluating and mitigating these potential risks.
Ready to take control and protect your business? Let’s dive into the world of TPRM!
ISO 27001 Audits Made Easy…Sort Of
Our clients pay us to give them good security advice. And there is nothing like taking your own advice and seeing how well that goes. So, a couple of years ago we decided to eat our own dog-food and go for ISO 27001 certification. This is an internationally recognised way to demonstrate that you have good security. We’ve recommended it to a number of our customers, and we’ve helped several gain it.
We had several things we wanted to achieve with this:
Extreme makeover – ISO/IEC 27002:2022 Edition
ISO/IEC 27002 has been updated in 2022. So, what’s changed?
This international standard of generic information security controls is widely used across the information security community as a benchmark for implementing good security practices, and has been largely unchanged since 2013. However, earlier this year the updated standard has had more than a facelift – it’s had a full makeover. Fundamentally there are three main changes, which I’ll go into.
ISO Blog Series Part 4: Road to ISO27001 – Document, Document and More Documenting
If you have been reading our blog series you will be following our journey to becoming ISO 27001 certified, which we achieved in February this year! In Part 3 we discussed how we utilised lockdown to get our advantage with some extra time on our hands. At that stage in our ISO journey, our ISMS was running with a high level of governance, however, it was not yet ready to get us ISO certified. There were still some pieces we needed to complete to get us over the line to achieve ISO 27001 certification. Let’s take a close look at the next stage we took on our journey to become ISO certified – one which involved a fair bit of documenting!
ISO Blog Series Part 3: Road to ISO 27001 – Lockdown, a lucky break!
If you have been following our ISO 27001 blog series you will know that Axenic is now officially ISO 27001 certified! The team is extremely excited about this accomplishment, however, the journey to becoming certified has not been easy. We are going to continue talking you through our journey to certification and Part 3 discusses our lockdown experiences and how we used this to our advantage.

