
We are proud to announce that Mycelium 365 has achieved ISO 27001 certification, an important milestone in how we manage information security across our business and the services we deliver to customers.
For us, this is more than a certificate.
ISO 27001 provides an internationally recognised framework for managing information security risks through a structured Information Security Management System, or ISMS. It requires organisations to identify risks, implement appropriate controls, define responsibilities, maintain policies and processes, and continually review whether those controls remain effective.
That approach closely reflects how we believe technology services should already be delivered. Security should be designed into an environment from the beginning, not added after something goes wrong. You can see the certification details on our certifications page.
What is ISO 27001?
ISO/IEC 27001 is the international standard for information security management systems. Rather than assessing a single product or a single technical control, it looks at information security as a management system: the governance, people, processes and technology that together determine how information is protected.
An ISMS assessed under ISO 27001 covers areas including:
- information security governance and leadership accountability
- risk identification, assessment and treatment
- access control and privileged access management
- identity and authentication
- supplier and third-party management
- incident management and reporting
- business continuity and resilience
- asset management
- operational security and change control
- employee responsibilities, screening and awareness
- data handling and classification
- policy management and documentation
- monitoring, internal audit and continual improvement
Certification is not a self-declaration. An organisation has to demonstrate to an auditor that the management system exists, is documented, is understood by the people who operate it, and is genuinely operating effectively - not just written down.
Why we pursued ISO 27001
A managed service provider sits close to the systems that matter most. Delivering managed IT services can mean holding access to:
- identities and directory services
- endpoints and mobile devices
- Microsoft 365 tenants
- Azure subscriptions and infrastructure
- security tooling and alerting
- business information and records
- privileged administrative accounts
That creates a responsibility well beyond keeping systems available. Customers need confidence that their technology provider maintains strong governance over its own systems, people, access and information - because the provider security posture becomes part of the customer security posture.
ISO 27001 gives that a structure, an evidence base and an independent audit, rather than a promise.
Security by Design
Modern IT environments are interconnected. Managed Microsoft 365, Managed Azure and Cloud, identity, endpoints, applications, data and cyber security are not separate projects - a weakness in one becomes an exposure in the others.
Practical examples we see regularly:
- Deploying Microsoft Defender does not compensate for poor identity controls.
- MFA is important, but it should sit alongside Conditional Access, managed endpoints with Microsoft Intune and access governance.
- Backups are essential, but organisations also need to know whether they can actually be restored within the required timeframe.
Security is not one product. It is a system of people, technology, governance and processes working together.
What this means for our customers
Certification matters most when it changes day-to-day practice. Here is what it means in practical terms.
Risk management
Security decisions should be based on understood and documented risks, not on implementing controls as a checklist exercise. A documented risk register forces the harder questions: what are we actually protecting, what would the impact be, and is the control proportionate to the risk it addresses?
Access to customer environments
MSPs can hold significant levels of privileged access. Under ISO 27001, that access has to be justified, recorded, reviewed and revoked when it is no longer required. It ties directly to how we manage identity, strong authentication, role scoping and administrative governance through Managed Microsoft Entra ID - for our own staff as much as for customer environments.
Incident management
No framework guarantees that incidents will never occur. The capability that matters is being able to detect, assess, respond to and learn from security events, with defined roles, timeframes and communication paths. That is the same discipline behind our 24/7 Security Operations Centre.
Supplier and third-party risk
Organisations increasingly depend on cloud vendors, SaaS platforms, software providers and external service partners. Those dependencies form part of the security environment, and they need to be assessed, documented and reviewed rather than assumed to be safe.
Continual improvement
Technology and threats keep changing. Controls that were appropriate two years ago may no longer be. ISO 27001 requires regular review, internal audit and measurable improvement - which is how security maturity is built over time rather than in a single project.
It also changes how we approach managed services
Traditional managed IT often focuses on a simple loop:
- A user has a problem.
- A ticket is raised.
- The problem is fixed.
- The ticket is closed.
That loop is necessary, but it measures activity rather than outcomes. A modern managed services model asks a different set of questions:
- Are recurring incidents decreasing?
- Are security risks being identified before they become incidents?
- Are unsupported systems being removed?
- Are devices properly managed?
- Are identities protected?
- Are backups working and recoverable?
- Are Microsoft 365 permissions appropriate?
- Is the organisation becoming more secure over time?
These are governance questions as much as technical questions. Our ISO 27001 framework strengthens how we identify risks, manage controls and drive improvement internally - and that discipline flows into how we plan and report on customer environments, including through a structured Technology Roadmap.
Supporting customers with their own security requirements
Australian organisations are increasingly facing security expectations from customers, insurers, government agencies, boards, regulators, procurement teams and larger organisations in their supply chain.
In practice that shows up as:
- security questionnaires during procurement
- cyber insurance application and renewal requirements
- contractual security obligations
- access control and privileged access evidence
- breach and incident notification commitments
- data handling and residency requirements
- supplier security assurance
- alignment to the Essential Eight
- requests for ISO 27001 or equivalent assurance
To be clear: ISO 27001 certification of Mycelium 365 does not automatically make a customer compliant with any regulatory framework, and we would never present it that way. What it does give us is practical, audited experience of operating a real ISMS - risk registers, access reviews, incident processes, supplier assessments and internal audits - and that experience directly informs how we help customers improve their own security posture.
ISO 27001 and the Microsoft cloud
Many of our customers operate predominantly within the Microsoft ecosystem. The technical controls that support an ISMS in that environment typically include Microsoft Entra ID, MFA and Conditional Access, Microsoft Intune for device compliance, Microsoft Defender across identity, endpoint and email, Microsoft Purview for information protection and data lifecycle, privileged access management, Microsoft Sentinel where centralised monitoring is warranted, Azure security controls, and Microsoft 365 auditing and monitoring.
But the distinction matters: technology alone does not create an Information Security Management System. Strong technical controls still need governance, policies, defined responsibilities, documented risks, repeatable processes, monitoring and continual improvement.
A business can have excellent security products and still have poor security governance.
Strong governance without appropriate technical controls can also leave significant gaps. The two need to work together.
What comes next
Certification is a milestone, not an endpoint. We will continue to review risks, improve controls, strengthen internal processes, develop our managed services, lift our own security maturity, and apply lessons learned across customer environments where appropriate.
As cloud, cyber security and artificial intelligence become increasingly connected, strong technology governance becomes even more important.
Businesses need technology environments that are productive and scalable. They also need environments that are controlled, resilient and secure.
That is the foundation behind our approach at Mycelium 365.
People first. Security by Design.
