Langleys Solicitors LLP
"We saw achieving ISO 27001 as a vital part of our risk management strategy and continuous improvement programme. For us it was important from a regulatory, professional and commercial perspective to ensure our information security systems within the business were robust.
"Once we made the decision to implement the standard, our view was to apply it right across the firm from top to bottom. For us, it wasn't about getting the tick in the box. It provided the impetus for a culture change.
"We put the contract out to tender and chose Equas. Julian Russell, a Director of Equas, worked with us and we had some really positive debates about how the standard would actually work for our business. He came up with very practical solutions that, now they are in practice, are proving to work very well."
Tamsin Cooper, Partner, Risk and Compliance
The company
Langleys is a long established practice that has grown into a leading UK law firm offering a full range of legal services. It has around 350 employees including 34 partners, and recently completed a major refurbishment of its offices in Micklegate, York.
The firm is organised into four divisions: commercial, private law, insurance and residential conveyancing. It has invested heavily in its IT platform, viewing technology as essential to driving performance and maintaining competitive edge.
The challenge
The firm adopted a holistic approach, so the scope of the project was very broad: all people, all services, all processes, all technology and all assets across its offices.
With the threat from cyber crime increasing, the firm wanted to monitor and track everything it did to ensure its systems were as robust as possible.
The approach
The business already had a strong IT infrastructure with good systems and data protection. What it needed to build on were policies and procedures for handling information falling outside that network of coverage.
A thorough gap analysis was the starting point, and considerable time was spent ensuring the controls specified in the standard would be practical to implement.
Midway through the project, ISO 27001:2005 was superseded by ISO 27001:2013, with the older version becoming obsolete in October 2015. The new version placed a strong focus on measuring and evaluating how well an information security management system performs. Langleys' existing systems therefore had to be audited against the new requirements. New policies and procedures were written and tested.
The benefits
The firm now has complete visibility and tracking of security threats, and certification satisfied the requirements of its FCA regulated clients. Employees have far greater awareness of the importance of protecting information and of adhering to policies and procedures.
There are softer benefits too. The project effected a culture change that people bought into: they use the new system and it has become part of the way they work. The breadth of scope covered by the certification has enhanced the firm's competitive edge.
How we helped
Implementation Support
Build your management system the right way, at the level of help you need
Internal Auditing
Independent assurance that your system is working
Outsourced System Maintenance
Keep your certification valid without it landing on someone's desk
