Information security

Secure work starts with clear choices.

You entrust systems, accounts and business data to Nivcom. That is why we consider not only technology, but also access, suppliers, continuity and clear agreements.

Transparent about ISO 27001

Certified partners without borrowing their certification claim.

Nivcom is not currently independently certified to ISO/IEC 27001:2022 and therefore does not present itself as an ISO-certified organisation. For important parts of its services, Nivcom works where appropriate with suppliers that are ISO/IEC 27001-certified within their own defined scope or subject to comparable independent assurance.

A supplier certificate applies to the management system and processes within that supplier’s scope. It does not automatically transfer to Nivcom. Selecting such suppliers does help make information security a demonstrable consideration throughout the supply chain.

How Nivcom makes security practical

Not a standalone tick box, but measures appropriate to the service and risk.

01

Limit access

Accounts and administrative privileges are configured as restrictively as practical. Strong authentication and MFA are preferred.

02

Select secure suppliers

Security, certification scope, privacy terms and continuity are considered for critical services.

03

Keep services current and recoverable

Updates, backups and recovery arrangements are configured and discussed in line with the selected service.

04

Act clearly during incidents

Signals are investigated, impact is limited and affected customers receive relevant information without undue delay.

Information security

What this means for you

A practical security approach that remains understandable and applicable to smaller organisations.

  • One point of contact who explains technical risks in plain language.
  • Considered choices for hosting, cloud, payments and other supply-chain partners.
  • Project agreements covering access, backups, administration and responsibilities.
  • No certification language without a demonstrable scope or substantiation.

Need a certificate or supporting information?

For tenders, processor agreements or security questionnaires, Nivcom can explain which supplier performs a component and what supporting information is available for that component. Certificates or audit information can only be provided subject to the relevant supplier’s terms.

ISO/IEC 27001:2022 is a standard for information security management systems. Only a certificate naming a specific organisation and scope demonstrates independent certification for that scope.
Discuss your security requirements