Why ISO 27001 was a non-negotiable decision for DB Results

When you handle sensitive data for governments, enterprises and critical industries, trust isn’t a talking point. It’s a requirement.

Let me be straight: achieving ISO 27001 certification wasn’t about a badge on our website. It was about earning the right to be trusted with what matters most to our customers: their data, their systems, and their reputation.

At DB Results, we work across some of Australia’s most complex and sensitive digital transformation engagements, from medium-scale to large-scale enterprise programmes. The customers in these spaces don’t just want good consultants. They want consultants they can trust implicitly. ISO 27001 is how we prove that trust is backed by process, not just intention.

What ISO 27001 actually is

ISO 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). At its core, it’s built on three principles that any serious consulting organisation should be living by:

  1. Confidentiality 
    • Only the right people access the right information. full stop.
  2. Integrity
    • Your data stays accurate, complete, and untampered with.
  3. Availability
    • Information is accessible when your business needs it, reliably.

Getting certified isn’t a tick-box exercise. It requires a formal risk assessment, a living ISMS with documented controls, internal audits, and a rigorous external audit by an independent assessor. We went through all of it, and it made us better for it.

What actual drove the decision

Plenty of organisations say they take security seriously. Fewer can prove it. Here’s what drove our decision:

  • Our customers demanded it. Increasingly, government and enterprise procurement processes explicitly require ISO 27001 or equivalent before a vendor is even considered. We weren’t going to lose critical work because of a gap we could close.
  • We handle sensitive data every day. Strategy engagements, technology implementations, operational transformation: these projects touch customer systems, internal financials, and sometimes personal data at scale. Our duty of care is real.
  • It forced internal discipline. The certification process exposes gaps you didn’t know you had. It made us sharper: better processes, clearer responsibilities, tighter controls. That benefits our customers directly.
  • Regulatory alignment. Australia’s Privacy Act, APRA CPS 234 and CPS 232obligations for our financial services customers, and sector-specific requirements across government. ISO 27001 provides a credible framework to map compliance against all of them.
  • It aligns with who we are as a B Corp. Being a certified B Corp means we’re held to a higher standard across social, environmental, and governance accountability. Protecting the data and systems of the people and organisations we work with isn’t just a security obligation. It’s a values one. ISO 27001 fits naturally within that commitment.
  • The risk of not doing it was simply too high. A single breach doesn’t just cost money. It costs relationships built over years and a reputation that takes a decade to build.

Our customers place immense trust in us when they hand over their most critical and sensitive programmes. ISO 27001 is the framework that proves we treat that trust with the rigour, discipline, and accountability it demands.

Gavin Bunshaw

CEO DB Results

What it means for you as a customer

If you’re evaluating consulting partners, here’s what our ISO 27001 certification actually means for your engagement with us:

Your data is treated as seriously as you treat it. Our ISMS means that access controls, incident response procedures, and employee security training aren’t ad hoc. They’re documented, audited, and continuously improved.

  • Reduced vendor risk for your own compliance obligations. When your security team asks about our controls, we don’t send back a vague two-pager. We have documented evidence from independent auditors.
  • Faster procurement timelines. Many enterprise and government procurement panels specifically require ISO 27001. Working with us means less friction at the gates, for both of us.
  • A partner who treats security as operational, not optional. We’ve embedded this into how we work, not just how we present ourselves.
  • Peace of mind on large-scale programmes. Complex transformation engagements create exposure. Our certification means the people inside your systems have been through a rigorous, independently verified security framework.

The bigger picture

Being a B Corp shapes how we think about every decision we make as a business. It pushes us to ask not just “did we deliver?” but “did we do it the right way?” ISO 27001 is part of that answer. It’s how we demonstrate that our commitment to responsible business practice extends beyond our social and environmental footprint and into the way we handle the data, systems, and trust our customers place in us every single day.

The market doesn’t need more organisations talking about security. It needs partners who have done the hard work of embedding it into everything they do. At DB Results, we have. Our ISO 27001 certification isn’t a milestone we achieved and moved on from. It’s a living commitment we maintain, audit, and evolve as threats change, regulations tighten, and customer expectations rise.


If you’re shortlisting consulting partners for your next major programme and want to understand what our security posture looks like in practice, we’re happy to walk you through it. No marketing fluff, just straight answers.

Ready to work with a partner you can trust?

DB Results brings ISO 27001-certified security practices to every engagement, from day one.

Get in touch today

Related Articles

© 2026 DB Results. All rights reserved.