How Entag built organisational governance to match their technical security maturity.


When fast-growing IT solutions provider, Entag engaged Acumenis to achieve ISO 27001 certification, they already had a mature security environment and an experienced technical team.
With these strong foundations already in place, why bring in an external partner?

For Entag's Chief Technology Officer Justin Maskey, the decision was driven by a desire to embed security in every aspect of their business while providing greater confidence and transparency for partners and clients, and also ensure an efficient audit process.
"Obtaining guidance and expertise from a partner like Acumenis enabled us to better understand the requirements from a policy and standards perspective, which ultimately helped us deliver the outcome sooner to the business," Justin said.
"Overall, the partnership helped us reach audit readiness sooner while building a foundation that will scale with our growth."
Challenge
Demonstrating maturity and capability
Entag needed a clear and credible way to demonstrate the maturity of its security program. The challenge was never about capability, it was about presenting that capability in a way that aligned with global standards and matched client expectations for preferred suppliers.
ISO 27001 provided the solution. However, it also brought with it new complexities and the added challenge of ensuring their staff understood requirements without distracting from day-to-day activities.
"By pursuing ISO27001, we aimed to create a more structured and standardised environment that would not only enhance our internal processes but also provide greater confidence and transparency for our partners and clients. This approach helped us ensure that security was embedded in every aspect of our operations, rather than being limited to just technical controls."
"Partnering externally allowed us to continue to focus on the technical and internal operational improvements needed…(Acumenis') support ensured we could balance day-to-day priorities while still progressing our compliance journey efficiently."
Solution
Evidence-based validation
For Entag, the solution came in three parts. First, by formally aligning with ISO 27001, Entag moved towards a structured and fully documented security framework. With Acumenis' support, Entag mapped its existing practices to the standard, making them easier to measure, communicate and maintain.
Next, Acumenis facilitated a tailored tabletop exercise that gave Entag a closer look at how it would respond to a serious incident under real-world conditions. This allowed Entag's team to test their response processes, uncover gaps, and refine communication in a safe environment.
Finally, Acumenis undertook targeted penetration testing to validate the strength of Entag's systems. The results gave leadership and technical teams clear insight into potential vulnerabilities and enabled them to take proactive, prioritised steps to reduce risk.
"Independent penetration testing has become an important part of how we validate our controls and stay honest about our risk posture. It reinforced that assurance isn't a one-off activity for certification, it's an ongoing discipline. The findings helped us focus our remediation efforts, improve documentation and operational practices, and build a repeatable cycle of testing, learning and uplift that complements our internal reviews."

Impact
Confidence, consistency and credibility
Entag experienced benefits both internally and externally.
Across the business, Entag achieved stronger governance and clearer accountability through easy-to-follow, evidence-based policies and processes. "We're more consistent in how we assess and manage risk, partner with suppliers, and respond to security events," Justin said.
"Externally, we've been able to have more confident conversations with clients about assurance and due diligence, supported by a recognised framework and independent testing."
Overall, the partnership with Acumenis brought deep ISO 27001 expertise and a pragmatic, business-first approach to building its ISMS. The standard was translated into clear and achievable actions that were tailored to Entag's size and growth strategy.
"Acumenis helped us reach audit readiness sooner while building a foundation that will scale with our growth…Their templates, coaching and structured cadence helped us uplift policies, evidence and internal audit readiness quickly, without creating unnecessary overhead, and kept us focused on what mattered most for certification and ongoing improvement."
Let's talk about where you are and where you need to be.
Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.
