You are on page 1of 2

BSI Case Study Fredrickson International 27001 Information Security Management

How Fredrickson has reduced third party scrutiny and


protected its reputation with ISO 27001 certification.

“We feel that as an Customer Objectives Background


organization we simply • Independent verification of the Fredrickson International is a
effectiveness of information industry leading Debt Collection
cannot afford to take security policies and procedures Agency (DCA), operating in the
an ad-hoc approach • Reduced client and regulatory UK with three sites across Surrey.
to managing information scrutiny of information security Fredrickson employ more than
security risk. With BSI’s practices 300 staff and recover debt in
• Win more business and meet excess of £100m per annum.
help we have implemented The organization’s key corporate
pre-qualification requirements
a system that has provided values are compliance,
• Gain client credibility and trust performance and innovation.
both an appropriate and
affordable level of protection Customer Benefits Fredrickson has enjoyed a
to our customers.” • Greater security awareness sustained period of growth both
across all levels of the organic and through new client
Simon Jones organization acquisition. Fredrickson is
Fredrickson Managing Director
• Shorter second-party security pleased to count among its
audits of its system clients, a Central Government
• Enhanced customer confidence Department, many well respected
and perception of the UK financial institutions and
organization several FTSE 100 companies.
BSI Case Study Fredrickson International 27001 Information Security Management

Why Certification? Benefits Fredrickson is committed to setting the

BSI/UK/66/SC/1012/en/DD
The debt collection industry is subject to Clients and the general public can now have standard and becoming the most compliant
increasingly intense regulatory scrutiny total confidence in Fredrickson’s information agency in the UK. According to Jan-Michael
worldwide, and Fredrickson’s clients also security practices and the way their personal Lacey, Fredrickson “believe that in the near
come from a number of highly regulated information is managed. future ISO 27001 certification will be
industry sectors including Banking, a pre-requisite imposed by many of our
Fredrickson has also found that the duration clients when selecting outsourced partners.”
Finance, Utility, Telecommunications,
of second-party audits of its information

© BSI Group
Home Shopping and Central Government.
security practices has reduced substantially. BSI’s Role
Like most organizations, Fredrickson
According to Jan-Michael Lacey, Sales &
is facing increased security challenges Fredrickson chose to work with BSI due to
Marketing Director at Fredrickson “being
and IT management demands. BSI’s reputation in the industry. “BSI stands
able to show we are fully ISO 27001 certified
alone in terms of quality and its reputation
Information security is fundamental to has significantly reduced the man hours
and helped us to drive business excellence
the success of Fredrickson’s business needed to complete IT security questionnaires
throughout the organization”, explained
with much of its work involving receiving, required by clients in bidding for work and
Darren Wright, IT Director, Fredrickson.
analysing and storing sensitive consumer on an ongoing basis after a contract has
and business credit information. been awarded.” Fredrickson’s BSI Client Manager has provided
information and recommendations to help
It is vital that the organization has appropriate
Implementation Fredrickson gain certification, and prepare
controls in place to protect its systems
For Fredrickson, seeking certification to for the stringent, continuing assessment
from hackers, and prevent personal
ISO 27001 was relatively straight forward, audits. Through these regular visits, BSI has
information on its systems falling into the
having already been operating in compliance been able to draw Fredrickson’s attention to
wrong hands as there is a real risk it could
with the standard. The organization carried areas where improvements could be made
be used by criminals to commit identity
out a gap analysis, and set to work fine and new ways of thinking introduced. For
fraud. It is therefore imperative that
tuning its system. Fredrickson, third party certification with
Fredrickson can assure its customers and
BSI is a way of proving to interested parties
the general public that it takes the security While many of the policies and procedures that they are compliant in this area. Darren
of their personal information seriously. required were already in existence, documents Wright from Fredrickson explained that
The organization is regularly audited by were not accessible and knowledge was “there have been several high profile instances
both its clients and other interested parties only shared on a need to know basis. To of data loss within our industry and as such
and Fredrickson anticipate that moving remedy this, Fredrickson created an information reducing the risk of this happening and
forward, this third party scrutiny will only security committee, with the objective of proving we have the highest levels of security
increase. As such, it is Fredrickson’s raising awareness throughout the company in place is important in demonstrating to
aspiration to get on the front foot by becoming and driving the process forward. The committee clients that we are fit for purpose. We are
the most compliant agency in its industry. used a combination of training and poster proud to say we achieved the certificate
According to Simon Jones, Managing campaigns to ensure staff understood the without de-scoping – this confirms that
Director at Fredrickson, “rather than simply importance of information security as well every single member of staff was involved
say we are compliant, we felt it would as the role they had to play. A shared drive in this achievement across all three of our sites.”
provide the market with the confidence it for documents, easily accessible by staff
across the organization, was also created. Fredrickson is committed to not becoming
needed, if we were to undergo independent
This process helped ensure the involvement complacent, and taking a continual
assessment of our ISO 27001 Information
of all employees from the beginning, which improvement approach. Having realised
Security Management System with BSI”.
was essential in enabling Fredrickson to its short term objectives, Fredrickson is
embed the requirements of the standard now working to develop greater security
and move forward with certification. awareness amongst staff, and ensure
ongoing vigilance and awareness.

Contact us to find
out how BSI can
help your business
make excellence
a habit.

The trademarks in this material (for example the BSI logo or the
word “KITEMARK”) are registered and unregistered trademarks
owned by The British Standards Institution in United Kingdom
+44 845 080 9000 bsigroup.com and certain other countries throughout the world.

You might also like