Connect with Us
Insource IT
Insource IT — ISO 27001:2022 Certification for a Managed IT Services Provider + Penetration Testing
Client: Insource IT (Managed IT Services Provider)
Engagement: ISO 27001:2022 implementation end-to-end, plus penetration testing (VAPT) across service platforms and customer-facing portals
The challenge
As a fast-growing MSP running RMM/PSA tooling, remote access gateways, and backup/DR services, Insource IT needed a certifiable ISMS that fit day-to-day operations—without disrupting SLAs or change cadence across many client environments.
What we did
Working with leadership, service desk, and platform owners, we designed and embedded a certifiable ISMS and validated the controls end-to-end:
Blueprint & baseline: Ran a focused gap assessment and produced an ISMS blueprint tuned for MSP realities—multi-tenant tooling, remote access, and patch SLAs.
Governance that runs itself: Stood up an Information Security Steering Committee, clarified roles/RACI, and set KPIs/KRIs with a recurring management-review cadence.
Policies woven into work: Authored the policy suite and Statement of Applicability aligned to ISO 27001:2022, then embedded them in ITIL/ITSM flows (incident, change, problem).
Risk & supplier discipline: Built asset and supplier registers (RMM/PSA, backup, cloud), executed risk assessments, and drove treatment plans to owners.
Operational hardening where it counts:
Enforced PAM/MFA on admin tools, tightened patch/change controls, improved log retention, access recertification, and rigorous leaver/offboarding.
Pen testing with closure: Tested perimeter, remote access, client portals/APIs, and the internal management plane—tracking fixes through re-test to verified closure.
People & proof: Delivered engineer-targeted awareness, updated service-desk runbooks, and assembled audit-ready evidence packs.
Audit to certification:
Prepared for internal audit, then supported Stage 1 and Stage 2 external audits—resulting in ISO 27001:2022 certification with no major nonconformities.
Results
ISO 27001:2022 certification achieved (no major nonconformities)
ISMS embedded in operations: risks linked to change calendar; metrics reported monthly
Reduced attack surface: high-risk PT findings remediated on gateways/portals; stronger PAM & MFA coverage
Stronger assurance for customers: validated processes for onboarding/offboarding, backup/DR, and supplier due diligence





Why it matters
Certification turns MSP best practice into independently verified assurance. Insource IT now demonstrates disciplined, secure service delivery—accelerating procurement, renewing client confidence, and scaling safely.
Explore our recently completed work
Illuminance Solutions
Insource IT