Edit page or add comments

Information security statement

What is this Statement for? Who is it for?

This is a short statement setting out dxw’s stance on the topic of information security. It is for anyone to read to give a brief overview of how dxw manages information security within the company.


Information Security Statement


dxw exists to improve people’s lives by designing, building, running, and improving digital public services.

Our reputation is built on our ability to consistently deliver work of excellent quality that exceeds our clients’ expectations, including the expectation that we will protect our clients’ information as well as our own. 


Our information security management system

Information security means preserving the confidentiality, integrity and availability of the information that we process or have access to. 

We implement an information security management system (ISMS). This defines how we manage information security. It is based on:

We are always trying to improve how we manage information security. We do regular audits to measure the effectiveness of the ISMS. 


Work covered by the ISMS

The ISMS and the policies and procedures within it apply to all dxw business units and activities as defined in the scope of our ISO 27001 certification. This includes operations, marketing, sales, delivery, technology, finance, HR and project management. 


Staff responsibilities

Managing information security is part of everyone’s day-to-day work. 

All staff, directors and contractors must comply with the policies and procedures in the ISMS. 

When someone joins dxw they must complete information security training so they understand their responsibilities.


Last updated: 22 September 2026