Entrusting your IT equipment to a supplier also means entrusting them with data: the company’s data, that of its employees, and sometimes that of its own customers. For a CIO, an IT manager or a purchaser, the security of this data is therefore inextricably linked to the choice of a partner. The stakes have changed: it is no longer simply a matter of ensuring system continuity, but of preventing the company’s data from becoming a commodity in the hands of attackers.
It was within this context that we obtained ISO 27001 certification in early 2026. In practical terms, this means that the protection of the data we process on behalf of our clients is underpinned by a rigorous, audited and internationally recognised system. For our clients and partners, this is a mark of trust: at bconnex group, responsible IT and information security go hand in hand.
ISO/IEC 27001 is the leading international standard for information security. It sets out the requirements for an Information Security Management System (ISMS): a structured set of processes, regulations and controls designed to protect sensitive data from threats, whether internal or external.
In practical terms, obtaining ISO 27001 is not simply a matter of checking a box once and for all. The standard requires the organisation to identify its risks, put in place appropriate measures (technical, organisational and human), and then continuously assess and improve them. An independent organization audits the system before granting certification, and regular audits verify that it is being maintained. In other words, certification is less a medal than an ongoing commitment.

💡 This requirement explains its growing importance. According to the ISO Survey 2024, there were around 96,000 valid ISO/IEC 27001 certificates worldwide, spread across all economic sectors. This is a clear sign that information security has become a priority shared by organisations of all sizes and in all sectors.
*Source : ISO, The ISO Survey 2024
Managing a company’s IT fleet is not simply a matter of supplying or recycling equipment. It requires involvement at every stage of the equipment’s lifecycle, from initial deployment right through to end-of-life, and therefore involves constant handling of sensitive data: both those stored on end-user devices and those passing through fleet management and security tools.
This is precisely where information security becomes a key issue. Inventory and monitoring of devices, access control, protection of information stored in our systems, traceability of data flows, and certified data erasure at the end of a device’s life: these are all processes that must be beyond reproach when we are entrusted with an entire fleet of devices. A breach in any one of these areas could undermine the trust in the entire chain.
💡 This risk is far beyond theoretical: attackers frequently target the least secure service providers in order to gain indirect access to their end customers’ systems. Choosing a service provider with proven security processes is therefore not merely a technical detail, but a way of protecting your entire supply chain.
ISO 27001 certification provides a structured framework for these challenges. It ensures that our best practices are not relying on the vigilance of a single individual or the habits of a team, but on a formalised system that is audited and continuously improved over time. For a business like ours, which specifically involves managing our clients’ equipment and data, this ensures complete consistency between our services and our high standards of security.
Our certification audit was completed without any non-conformities, covering our three countries of operation: France, Italy and Belgium. Behind this result lie several months of work: mapping all our information assets, auditing our own suppliers to verify that they are committed to at least the same standards as we are, identifying our risks and demonstrating, in our teams’ day-to-day work, that our controls actually work. Because an auditor is not looking for flaws: they are looking for consistency between what a company says it does and what it actually does.
Ultimately, every one of our clients asks themselves a simple question: “How can I be sure that my service provider is protecting my data?” ISO 27001 answers exactly that question.

This brings about three changes:
1/ An objective mark of trust. The certification is granted by an independent third party, following an audit. It is not merely a declaration of intent; it is verifiable proof.
2/ One less thing to worry about. If you require your service providers to hold ISO 27001 certification, which is becoming the norm, the matter is settled straight away, without the need for any further checks on your part when selecting or purchasing services.
3/ Support for your own compliance. Regulatory requirements are becoming stricter, from the GDPR to the NIS 2 Directive, and require organisations to ensure their service providers are reliable. Working with a certified partner gives you tangible evidence to demonstrate this vigilance to both your clients and the authorities.
💡 Julien Fournier, CTO and co-founder of bconnex group, who led the project, points out that many companies now require this certification from their IT service providers, and they are right to do so. It has become the standard for meeting their needs effectively. Obtaining certification is only the first step; maintaining it requires a consistently high standard, upheld by the teams on a day-to-day basis.
And this rigour does not stop at data protection: it also underpins our commitment to more sustainable IT. After all, for equipment to be reused or recycled with complete confidence, the data it contained must have been reliably and traceably erased. This is precisely what ISO 27001 addresses: by securing the end-of-life process for devices, it enables a more circular economy without ever compromising on confidentiality. Far from being at odds with one another, security and sustainability go hand in hand.
ISO 27001 reflects a fundamental commitment: to protect our customers’ data with the same dedication we apply to optimising and extending the lifespan of their IT infrastructure. For CIOs, IT managers and procurement professionals seeking a partner that combines performance, sustainable IT and information security, it offers a concrete and verifiable solution.
Would you like to find out more about our approach to IT asset management and our information security strategy? Contact our teams to discuss your concerns, or explore our full range of services on our website.