Insource IT

Insource IT — ISO 27001:2022 Certification for a Managed IT Services Provider + Penetration Testing

Client: Insource IT (Managed IT Services Provider)
Engagement: ISO 27001:2022 implementation end-to-end, plus penetration testing (VAPT) across service platforms and customer-facing portals

The challenge

As a fast-growing MSP running RMM/PSA tooling, remote access gateways, and backup/DR services, Insource IT needed a certifiable ISMS that fit day-to-day operations—without disrupting SLAs or change cadence across many client environments.

What we did

Working with leadership, service desk, and platform owners, we designed and embedded a certifiable ISMS and validated the controls end-to-end:

Blueprint & baseline: Ran a focused gap assessment and produced an ISMS blueprint tuned for MSP realities—multi-tenant tooling, remote access, and patch SLAs.

Governance that runs itself: Stood up an Information Security Steering Committee, clarified roles/RACI, and set KPIs/KRIs with a recurring management-review cadence.

Policies woven into work: Authored the policy suite and Statement of Applicability aligned to ISO 27001:2022, then embedded them in ITIL/ITSM flows (incident, change, problem).

Risk & supplier discipline: Built asset and supplier registers (RMM/PSA, backup, cloud), executed risk assessments, and drove treatment plans to owners.

Operational hardening where it counts:

Enforced PAM/MFA on admin tools, tightened patch/change controls, improved log retention, access recertification, and rigorous leaver/offboarding.

Pen testing with closure: Tested perimeter, remote access, client portals/APIs, and the internal management plane—tracking fixes through re-test to verified closure.

People & proof: Delivered engineer-targeted awareness, updated service-desk runbooks, and assembled audit-ready evidence packs.

Audit to certification:

Prepared for internal audit, then supported Stage 1 and Stage 2 external audits—resulting in ISO 27001:2022 certification with no major nonconformities.

Results

ISO 27001:2022 certification achieved (no major nonconformities)

ISMS embedded in operations: risks linked to change calendar; metrics reported monthly

Reduced attack surface: high-risk PT findings remediated on gateways/portals; stronger PAM & MFA coverage

Stronger assurance for customers: validated processes for onboarding/offboarding, backup/DR, and supplier due diligence

Why it matters

Certification turns MSP best practice into independently verified assurance. Insource IT now demonstrates disciplined, secure service delivery—accelerating procurement, renewing client confidence, and scaling safely.

Project Information

Client

Insource IT

Category

ISO 27001:2022 implementation
Recent Work

Explore our recently completed work

Illuminance Solutions

CyberProof partnered with Illuminance end-to-end to build a certifiable security

Insource IT

ISO 27001:2022 implementation end-to-end, plus penetration testing (VAPT) across service

Department of Planning, Lands and Heritage (DPLH)

ISO 27001:2022 implementation end-to-end, plus penetration testing (VAPT) across service