One data breach is all it takes to lose a client’s trust in how their information is handled.
Clients don’t just want to know systems are secure. They also want confidence that information security is properly managed across the organisation they’re relying on.
That’s where ISO 27001 comes in.
ISO/IEC 27001 is the international standard for information security management. It provides a framework for identifying risks, protecting information, and continuously improving how security is managed.
At Orangebox, we see ISO 27001 as an important benchmark for modern cybersecurity practices, and it’s guided the work we did in 2025 to sharpen how we manage risk and protect data.
Strengthening Our Security Framework
As part of that work, we strengthened and consolidated our information security framework to align with recognised best-practice standards.
This framework helps ensure information security is managed consistently across the organisation through clear governance, defined responsibilities, risk management processes and policies, and regular review.
By taking a structured approach to security, we can protect customer information more effectively and respond quickly as new threats emerge.
Security in Practice
Orangebox operates a mature cybersecurity environment designed to protect both our systems and our clients’ data.
Key controls include:
- Multi-factor authentication across all accounts
- Role-based access controls
- Segmented Microsoft Azure infrastructure (client data is kept in separate, walled-off environments, not one shared space)
- Encryption for data at rest and in transit
- 24/7 security monitoring and incident response
We also run regular vulnerability scanning (automated checks for known weaknesses), structured patch management (keeping software security updates current), independent penetration testing (an outside expert who tries to break in, to find gaps before anyone else does), and disaster recovery testing to ensure systems remain resilient.
This matters in practice for the data you share with us. Whether it’s a contact list for a direct mail campaign or donor records for a personalised communication programme, it’s handled within this controlled environment, not passed around in spreadsheets or stored outside our secure infrastructure.
Our ISO 27001 Journey
Many of the operational controls expected under ISO 27001 are already in place at Orangebox.
Our next focus is formalising the governance and documentation required for certification, including defining the scope of our Information Security Management System (the policies and processes that govern how security decisions get made) and preparing for internal and external audits.
Certification is an important milestone, but the real goal is building a security framework that continues to evolve as risks change.
Our Commitment
At Orangebox, information security is part of how we operate.
Our alignment with ISO 27001 comes down to a simple idea: we take the same care with your data that we’d want taken with our own.
If you have specific questions about how we handle your data, we’re happy to walk you through it.