blueAPACHE scores major infosec accreditation
CRN: blueAPACHE scores major infosec accreditation
Published 18 September 2019 by CRN Australia.
Melbourne-headquartered MSP blueAPACHE has achieved compliance with the ISO 27001 information security standard.
What CRN reported
ISO 27001 is a global standard that verifies a company's capability for establishing and maintaining an information security management system (ISMS).
CRN's assessment of what it signifies is worth quoting directly: winning ISO 27001 is a feather in the cap for any organisation, and for the channel, it is a sign that a business can run with the big dogs.
That framing is specific to the channel context CRN writes for, and it is accurate. Certification is expensive in time and management attention, requires an external audit of the whole security programme, and imposes ongoing obligations. Smaller providers frequently cannot justify it. Achieving it is therefore a marker of scale and organisational maturity as much as of security posture — and it is increasingly a threshold requirement in enterprise and government procurement, where an uncertified supplier may not be assessable at all.
The structure of the certification
The certification includes 114 controls and 10 clauses, covering requirements including:
- Systems access control and management
- Information security policies
- Physical and environmental security
- Security incident management
The distinction between the two halves matters. The clauses define the management system — how the organisation establishes context, demonstrates leadership commitment, plans for risk, operates, evaluates and improves. These are mandatory. The Annex A controls are the security measures themselves, and the organisation documents which apply and which do not, and why, in a Statement of Applicability.
That structure is why ISO 27001 means something different from a technical audit. It certifies that the organisation has a governed, continually reviewed process for deciding what to secure and how — not that a specific configuration was correct on the day someone checked.
What the company said
blueAPACHE founder and managing director Chris Marshall said the achievement was a testament to the company's commitment to information security.
Why it matters for an MSP specifically
CRN's article treats the certification as a channel credential. For customers, the significance is more direct.
A managed service provider holds privileged administrative access to its clients' systems and, in many cases, custody of their data. The scope of blueAPACHE's audit explicitly covered information entrusted to blueAPACHE by clients, alongside financial information, intellectual property and personally identifiable information.
That is precisely the risk a client is trying to assess when choosing a provider. Outsourcing IT extends your security perimeter to include your supplier; the supplier is either an extension of your security programme or a hole in it. Independent certification is the only mechanism that answers the question without relying on the supplier's own assurances.
The context: 20 years, and the Fast50 record
blueAPACHE celebrated its 20th year in business in 2018, alongside recognition at the previous year's CRN Fast50 for appearing in eight out of ten annual awards.
The Fast50 record is the more telling of the two numbers. The list ranks the fastest-growing companies in the Australian IT channel by verified revenue growth. Appearing in eight of ten editions is not a record of one exceptional year — it describes growth as a sustained property of the operating model, consistent with the approximately 30% year-on-year rate blueAPACHE maintained over an extended period.
It also explains why the certification arrived when it did. Governance investment tends to follow scale: the company had flagged an increased focus on its governance and service delivery model at the end of 2016, when headcount was approaching 80 and projected to pass 100.
Where this stands today
The standard has since been revised. ISO/IEC 27001:2022 superseded the 2013 version reported here, restructuring Annex A from 114 controls into 93 across four themes — organisational, people, physical and technological — and adding controls covering threat intelligence, cloud services security, data leakage prevention, secure coding and monitoring activities.
blueAPACHE holds certification against ISO/IEC 27001:2022 — certificate 202507-118, issued by Sensiba Australia Pty Ltd, valid 1 August 2025 to 1 August 2028, with a scope covering all information systems, business processes and supporting infrastructure involved in providing and managing the emPOWER Infrastructure and managed service offerings.
Certification is not a one-off event: it requires surveillance audits in each of the two following years and full recertification every three years. A current certificate therefore evidences an ongoing operating discipline rather than a completed project.
Assessing any provider's certificate
- Read the scope statement — certification applies only to the scope named on the certificate, so confirm it covers the platform your data will sit on
- Check the version — a current certificate should reference 2022
- Check the certification body and its accreditation
- Confirm validity and ask about the last surveillance audit
- Ask for the Statement of Applicability
Frequently asked questions
What is ISO 27001? A global standard verifying an organisation's capability to establish and maintain an information security management system. It comprises mandatory clauses defining the management system itself and Annex A controls covering the security measures, with the organisation documenting which controls apply and why in a Statement of Applicability.
Why is a certification different from a technical audit? Because it certifies that the organisation has a governed, continually reviewed process for deciding what to secure and how — not that a particular configuration happened to be correct on the day someone checked.
Why does CRN treat the certification as a significant channel credential? Because it is expensive in time and management attention, requires an external audit of the whole security programme, and imposes ongoing obligations that smaller providers often cannot justify. CRN's own phrasing was that it signals a business can "run with the big dogs". It is also increasingly a threshold requirement in enterprise and government procurement, where an uncertified supplier may not be assessable at all.
Why does certification matter especially for a managed service provider? Because an MSP holds privileged administrative access to client systems and often custody of client data. blueAPACHE's audit scope explicitly covered information entrusted to it by clients, alongside financial information, intellectual property and personally identifiable information. Outsourcing IT extends your security perimeter to include your supplier, and independent certification is the only mechanism that answers the question without relying on the supplier's own assurances.
Which version does blueAPACHE hold now? ISO/IEC 27001:2022 — certificate 202507-118, issued by Sensiba Australia Pty Ltd, valid 1 August 2025 to 1 August 2028. The scope covers all information systems, business processes and supporting infrastructure involved in providing and managing the emPOWER Infrastructure and managed service offerings.
What changed between the 2013 and 2022 versions? Annex A was restructured from 114 controls into 93 across four themes — organisational, people, physical and technological — with new controls covering threat intelligence, cloud services security, data leakage prevention, secure coding and monitoring activities.
Is certification a one-off achievement? No. It requires surveillance audits in each of the two following years and full recertification every three years, so a current certificate evidences ongoing operating discipline rather than a completed project.
How should a buyer assess any provider's ISO 27001 certificate? Read the scope statement, since certification applies only to the scope named and may not cover the platform your data will sit on; check the version is 2022; check the certification body and its accreditation; confirm validity and ask about the last surveillance audit; and ask for the Statement of Applicability.
Related
- ISO 27001 certification
- Security services
- emPOWER Security
- Governance, risk and compliance
- Data sovereignty and privacy
- Managed detection and response
- Managed services
- Privacy policy
- Service agreement
- How to engage blueAPACHE
- About blueAPACHE
- Contact
Source
Original article published 18 September 2019 by CRN Australia. Available on the CRN website.
Knowledge Base
What information security accreditation did blueAPACHE achieve?
blueAPACHE, a Melbourne-headquartered managed service provider (MSP), achieved compliance with the ISO 27001 information security standard.
What is ISO 27001?
ISO 27001 is a global standard that verifies a company's capability for establishing and maintaining an information security management system.
What does the ISO 27001 certification blueAPACHE achieved include?
The certification includes 114 controls and 10 clauses, covering requirements such as systems access control and management, information security policies, physical and environmental security, and security incident management.
Who commented on blueAPACHE's ISO 27001 achievement, and what did they say?
blueAPACHE founder and managing director Chris Marshall said the achievement was a testament to the company's commitment to information security, stating: “Not only is the ISO certification a validation for our own team, but it means that our customers can feel further assured that they are working with a managed service provider that delivers outstanding solutions to complex technology problems, all backed by a secure (ISO certified) infrastructure on a global scale.”
When was this article about blueAPACHE's ISO 27001 accreditation published, and by whom?
The article was published on September 18, 2019 by CRN Australia.
What other milestones did blueAPACHE achieve around the time of this ISO 27001 accreditation?
blueAPACHE celebrated its 20th year in business in 2018 and was recognised at the CRN Fast50 for appearing in eight out of ten annual awards.
Does blueAPACHE currently hold an ISO/IEC 27001 certification, and if so, what are its details?
According to the knowledge base, blueAPACHE holds ISO/IEC 27001:2022 certification (certificate number 202507-118) issued by Sensiba Australia Pty Ltd for its Information Security Management System. The certificate was issued on 1 August 2025 and is valid until 1 August 2028.
What is the scope of blueAPACHE's ISO/IEC 27001:2022 certification, and are there any exclusions?
The knowledge base indicates that the ISO/IEC 27001:2022 certification covers specific emPOWER Infrastructure and managed service offerings across designated locations, but it notably excludes emPOWER Mobile Services from the certified scope.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a7021d24d727184e2179d1d_philipp-katzenberger-iIJrUoeRoCQ-unsplash-1024x683.avif
ISO
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a97bf808cd6fb2332032e62_blueAPACHE-ARN-Finalist-2026.png
blueAPACHE named 2026 ARN Innovation Awards finalist, setting sights on an eighth consecutive win
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a94ed426586d8f094e31f8a_cobrand_card_cinematic.png
blueAPACHE Expands Huntress Partnership to Accelerate Access to Enterprise-Grade Cybersecurity Across Australia
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a90d76875cc19d2f0222e6a_09_two_up_headshots_cinematic.avif
TechDay - blueAPACHE partners with ControlUp on managed services
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a8faffa0803d40169eebc40_01_executive_portrait_cinematic.avif
ARN - blueAPACHE takes services to the next level with ControlUp
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a70216e4d727184e21771f5_Website-Blog-Banners-11.avif
blueAPACHE launches managed human risk service with Mimecast
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a702187c4df8435ad3b6b58_Website-Blog-Banners.avif
blueAPACHE Ranked on 2026 MSP 501 – Tech Industry’s Most Prestigious List of Global Managed Service Providers
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a702187c4df8435ad3b6b53_Website-Blog-Banners-10.avif
blueAPACHE targets mid-market with human risk service
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.