Corporify works with sensitive corporate data and has therefore paid close attention to cybersecurity from the outset. However, as the company began attracting larger clients and expanding internationally, this was no longer always enough. More and more clients explicitly asked for ISO 27001 certification. Corporify decided to pursue it and chose Vinçotte as its certification body. The process took around a year from initial idea to certification. Internally, it also helped make many processes clearer and more structured.
Corporify develops software for companies with complex corporate structures. This may be a group consisting of dozens or even hundreds of legal entities, with different shareholders and frequent changes. This information is often spread across documents, spreadsheets and different systems. Corporify brings it all together on a single platform, with a digital shareholder register as the starting point. From there, clients can manage their corporate data, generate documents and automate processes.
“Cybersecurity has therefore always been part of our DNA,” says Andy Kellens, CTO of Corporify. “Our architecture is secure by design, data is encrypted, and we were already doing a great deal in terms of privacy and secure coding. What we did not have was independent certification.”
“In the early years, clients gave us the benefit of the doubt, even without certification,” says Olivier Van Borsel, CEO of Corporify. At the time, the company mainly served local law firms, accounting firms and private equity. That changed as larger companies became clients and Corporify began expanding internationally. Security questionnaires became more extensive, and the same question appeared increasingly often in tenders: Are you ISO certified? Sometimes, the answer was even decisive. “One potential client told us explicitly that they could not commit until we were ISO certified,” Van Borsel recalls. “With another client, we were able to say that we had obtained the certificate that very day. That immediately resolved the issue.”
For a company with international ambitions, ISO 27001 offers another major advantage: the standard is recognised worldwide. “In Belgium, you can still explain who you are and how you work. Abroad, people may not necessarily know Corporify,” says Van Borsel. “The certificate allows us to demonstrate that our approach has been independently assessed. We also find that certain steps with clients’ IT or compliance departments move faster as a result.”
From a technical perspective, Corporify had already implemented many security measures. During the preparation for ISO 27001, it became clear that the rest of the organisation also needed to be involved. What are the risks, who is responsible for what, and which agreements and procedures are needed to manage information securely? “That is an important point,” adds Patrick Coomans, Global Product Owner Cybersecurity at Vinçotte. “You can implement many technical measures, but information security needs to be supported throughout the organisation. Everyone needs to understand the risks, know which agreements apply and follow them consistently.” For Corporify, this was one of the biggest eye-openers. During the preparation phase, the company was supported by Spinae, a Ghent-based consultancy that helps organisations with cybersecurity and compliance. Together, they mapped what Corporify was already doing, what needed to be documented more clearly and which additional steps were required.
The full preparation process took around a year and led to concrete changes. Laptops and access rights are now managed differently. New devices are configured according to fixed standards, and employees can no longer install software themselves. Clear procedures are also in place for people joining or leaving the company. New employees receive access to the appropriate systems, and that access is withdrawn when they leave. “Previously, you would simply ask someone to create an account, so to speak,” Kellens explains. “Today, we have a complete paper trail. We can see who has access to which tools and monitor far more effectively whether someone still has access they no longer need. There is much more structure behind it now.”
After the preparation phase, it was up to Vinçotte to assess whether Corporify met the requirements of ISO 27001. “During an audit, an organisation must be able to demonstrate that what is written down is also put into practice,” says Tom Meylaers, Division Director Business Assurance at Vinçotte. “The purpose of certification is precisely for an independent party to verify that the system works and that information security is structurally embedded in the organisation.”
The choice of that independent party was also important to Corporify. With clients in fifteen countries, the company deliberately wanted to work with an established name. “When you go through a process like this, you want the certificate to have real value for your clients,” says Van Borsel. “There are online programmes where everything is done remotely and you can become certified very quickly. We wanted an organisation that large corporations would also recognise. The party conducting your audit helps determine how much value the certificate carries.”
During the audit, Corporify experienced how thoroughly Vinçotte worked. “You start the morning thinking you are well prepared, but by the second coffee break you are already a little less certain,” Van Borsel says with a laugh. “They really examined the details and asked probing questions. That made it quite tense, but it is also satisfying afterwards. You know you did not receive the certificate without earning it.”
Obtaining ISO 27001 does not mean the work is finished. Periodic audits monitor whether Corporify continues to comply with the standard. The company must keep applying its processes, monitoring risks and demonstrating the improvements it makes. “Certification is not a snapshot that you can simply forget afterwards,” says Meylaers. “An organisation evolves, technology changes and new risks emerge. You must therefore keep assessing where improvements are needed.” For Corporify, this has now become part of everyday operations. Incidents are documented, access rights are reviewed regularly and the approach is adjusted where necessary. “Much of what ISO requires is actually simply good governance,” says Van Borsel. “But in a growing company, there are always things that seem more urgent. If no one requires you to look at them, they easily slip down the priority list. Certification means it is no longer optional.”
According to Vinçotte, this is also where the broader value of certification lies. “An ISO 27001 certificate makes the way your organisation approaches information security visible,” says Coomans. “You can say that you handle it carefully, but a certificate also shows that your approach has been independently assessed against the standard.” Van Borsel therefore advises other entrepreneurs not to wait too long. “If you know that at some point you will need such a certificate, and you have the time and resources, begin early. You can then build your processes accordingly from the outset. We had to review our entire organisation afterwards and identify what still needed to change. Once your company is fully operational, it is much harder to make time for that.”
Corporify is currently active in fifteen countries and aims to continue expanding internationally. The ISO 27001 certificate is also valuable in that context. “If we expand further outside Belgium in the future, we do not want to explain each time how we approach security,” Kellens concludes. “An internationally recognised standard gives us a solid foundation.”
Vinçotte supports you in every step!
Visit our Cybersecurity page