An instant connection
Heigo has been a specialist in advising on and supplying workwear, personal protective equipment, and footwear to companies and organizations for over 35 years. Jan Jurrius is the CISO and responsible for the quality systems at Heigo and its sister company Vitagro, a specialist in sustainable green space management. Part of that is ISO 27001 certification, he explains.
“We don’t have the certification because our customers ask for it. The owner of our companies simply wants everything to be in order, which is why we are ISO 27001 certified. We want to be secure. When the 2013 version transitioned to the 2022 version, I rewrote the system accordingly. The reason we chose Normec for the certification was that we wanted to consolidate everything with a single provider. Our audits for ISO 14001 and ISO 9001 also need to be conducted periodically. We were looking for a partnership for that. It was a distinguishing factor that Normec Certification Institute offers all three, because many certification bodies do not handle ISO 27001. We immediately clicked with Normec from the very first meeting. Ultimately, Normec Certification Institute, as part of Normec, conducted the audits for us. That went very smoothly.”
Entire chain secured
During the audit, various Heigo employees were interviewed. But Normec Certification Institute took it a step further, Jan explains: “Our IT partners were also interviewed for the audit. One partner manages our clothing management system, and the other manages our entire server infrastructure. Via a Teams connection, both partners had to demonstrate how they handle information security and answered all sorts of questions from the Normec Certification Institute. That’s reassuring for us, because it means we know both partners have everything in order. This ensures information security throughout the entire chain.”
An important point during the audit was providing evidence for the transition from the 2013 version to the 2022 version. Jan succeeded in this: “And that really goes down to the nitty-gritty. You have to be able to explain exactly how you achieved that transition. For example, with a much stricter risk analysis. The best part is that we passed the audit without any real comments or observations.”
“Normec Certification Institute also audited our IT partners, so the entire data chain.”
Greater awareness among employees
IT is just one part of the ISO 27001 certification, according to Jan: “You also have to have everything in order physically, organizationally, and on the human side. People will always be the weakest link; we know that. We try to keep each other on our toes here. I’ve noticed that it really works. We have an e-learning environment where we train our people in information security every month. By now, I get the impression that our employees, consciously or unconsciously, are already quite aware. Recently, I sent out a phishing email as a test, and only one person fell for it. You can really tell there’s more awareness among our employees. That’s an added positive effect of our ISO 27001 certification.”
“Greater awareness among our employees is an additional positive effect of our ISO 27001 certification”
Ensuring the security of the information used within the company is why Heigo obtained its ISO 27001 certification several years ago and has since successfully renewed it. Normec Certification Institute conducted the audit.
Looking for a partner who thinks along with you?
We don’t just assess whether your company is compliant; together, we ensure that your organization improves and is ready for the future