Success / ISO/IEC 27001

ISO/IEC 27001

ISO/IEC 27001 Certification at Moxie

Independently audited information security — so enterprise IT brands can brief, activate, and hand off data with confidence.

LRQA ISO/IEC 27001 Certified — UKAS Management Systems
Certification

ISO/IEC 27001.

Enterprise IT marketing handles sensitive briefs, guest lists, partner data, and campaign systems. ISO/IEC 27001 is the international standard for information security management — independently audited so clients can see how we protect what they entrust to us.

The standard

What ISO/IEC 27001 Is

ISO/IEC 27001 is the international standard for an Information Security Management System — the operating model an organisation uses to protect the information it holds.

An Information Security Management System (ISMS) is not a single software product. It is the documented way a company identifies information risk, selects and operates controls, assigns ownership, and reviews those controls as the business changes. ISO/IEC 27001 is the globally recognised specification for building and running that system.

Certification is independently audited. External auditors assess whether the ISMS is designed, operated, and continually improved as the standard requires — access control, incident handling, supplier management, asset inventory, and how confidential information is classified and shared.

Moxie Company Limited is ISO/IEC 27001 certified through LRQA under UKAS accreditation. That is the same LRQA / UKAS mark on this page: a management-system certification, independently assessed, for how we protect information across Hong Kong and Asia Pacific delivery.

  • International ISMS standard ISO/IEC 27001 defines how organisations manage information security as a system — people, process, and technology together.
  • Independently audited Certification is awarded after external assessment of the ISMS, not after a self-declared checklist.
  • LRQA under UKAS accreditation Moxie's certificate is issued through LRQA, with UKAS accreditation of the management-system certification.
  • Continual improvement The standard requires the ISMS to be reviewed and strengthened over time as programmes, platforms, and suppliers change.
The company

What Certification Means for Moxie Company Limited

ISO/IEC 27001 at Moxie is an independently audited ISMS — not a decorative badge on a pitch deck.

When Moxie Company Limited obtained ISO/IEC 27001 certification, auditors assessed the controls that govern how we handle client briefs, guest lists, partner data, and campaign systems. That is the substance of the certificate: accountable ownership, documented process, and independent review of how information is protected in day-to-day agency work.

Enterprise IT marketing in Hong Kong and APAC moves sensitive material by design — launch narratives, attendee records, channel plans, partner commercials, and the platforms that run registration and always-on programmes. Certification records that those assets sit inside an ISMS that is operated and independently checked, rather than left to informal “be careful” habits.

That is why ISO/IEC 27001 sits with our client roster and industry awards as proof of how Moxie operates — audited process alongside the brands and programmes we deliver.

  • Audited controls Access, suppliers, incidents, and information classification are part of the ISMS auditors review — not a logo applied after the fact.
  • Briefs and campaign systems Confidential creative, media, and GTM systems are handled inside the same information-security operating model.
  • Guest lists and partner data Registration files, executive invite lists, and partner co-marketing data are treated as information assets under the ISMS.
  • Accountable ownership Roles and reviews sit with named owners so security stays with every activation, not only with the kickoff slide.
Client delivery

How Certification Strengthens Client Services

Independently audited information security is part of how Moxie briefs, activates, and hands off data for events, digital programmes, and go-to-market work.

Procurement and security reviewers can evaluate Moxie with a recognised ISMS certification — ISO/IEC 27001 through LRQA under UKAS accreditation — when they onboard an events and marketing partner in Hong Kong. Programme teams can move faster through vendor questionnaires because the operating model is already independently assessed.

On live work that means NDA-covered materials, executive guest data, partner lists, registration platforms, and campaign systems sit inside one delivery path: briefing, activation, on-site control, and structured handoff into the systems your sales and marketing teams already use.

Ready to brief a summit, partner day, or always-on digital programme? Get In Touch and we will map events, digital, and creative around the information you need protected from first file share to post-event follow-up.

  • Briefing under NDA Confidential decks, product embargoes, and commercial terms enter a controlled briefing path — not an unmanaged inbox trail.
  • Events and guest data Invitation criteria, registration, badge data, and on-site lists are run as information assets through activation and close-out.
  • Digital programmes Campaign platforms, lead capture, and always-on systems sit inside the same ISMS as live events — one agency, one security model.
  • Data handoff Post-event and campaign files are packaged for CRM and partner follow-up with agreed ownership, not left in a shared dump.
  • Enterprise procurement Vendor due diligence gets an independently audited ISMS to cite — so security review supports the programme instead of stalling it.
  • Hong Kong and APAC delivery Regional activations inherit the same certified operating model from the Hong Kong team that runs the brief.
FAQ

ISO/IEC 27001 questions answered.

Short answers on the standard, LRQA / UKAS certification, and how Moxie handles briefs, guest data, and enterprise procurement.

What is ISO/IEC 27001?

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It specifies how an organisation identifies information risk, operates controls, assigns ownership, and continually improves how it protects the information it holds. Certification is independently audited.

Who certified Moxie Company Limited?

Moxie is ISO/IEC 27001 certified through LRQA under UKAS accreditation. LRQA is the certification body; UKAS accreditation applies to the management-system certification shown on this page.

What client information does this cover in agency work?

In Moxie's work that includes confidential briefs, guest lists, partner data, registration records, NDA materials, and the campaign systems used to run events and digital programmes. Those information assets sit inside the audited ISMS rather than outside it.

How does ISO/IEC 27001 help enterprise procurement?

Vendor onboarding and security questionnaires can cite an independently audited ISMS. That gives procurement and information-security reviewers a recognised standard to evaluate — so briefing a Hong Kong events and marketing partner does not stall on unproven process claims.

Does Moxie work under non-disclosure agreements?

Yes. Enterprise IT programmes routinely start under NDA. Certification means NDA materials, embargoed product stories, and partner commercials are handled inside the same information-security operating model as guest data and campaign platforms.

How do we start a programme with Moxie?

Use Get In Touch to brief the Hong Kong team on your market, moment, and data-handling requirements. We map events, digital, and creative from first file share through activation and structured handoff.