How CDW Helped Durham Region Achieve ISO 27001 Certification
Article
7 min

How CDW Helped Durham Region Achieve ISO 27001 Certification

What started as a cybersecurity gap assessment evolved into a full-scale security transformation. Learn how CDW helped Durham Region implement ISO 27001 and build a stronger, more integrated security program.

CDW Expert CDW Expert
Chi-Cheng Chu, Chief Information Officer, Durham Region. (Right) and Cyrus Wang, Manager – Information Security, Durham Region.(Right)

Cyrus Wang, Manager – Information Security, Durham Region (Left) and Chi-Cheng Chu, Chief Information Officer, Durham Region (Right)

The Regional Municipality of Durham serves a large and growing population across eight smaller municipalities in Ontario, supporting more than 800,000 residents. The administrative body facilitates essential public services from water and wastewater management to public health, transportation infrastructure and community services.

As a public-sector organization responsible for sensitive citizen data and mission-critical systems, Durham Region operates under a high level of accountability. Its Corporate Services Information Technology (CS-IT) team plays a central role in ensuring these services remain secure, reliable and accessible.

/

To me, as the CIO for the Region, I feel like it is my mandate to ensure that we protect all our information, public resources and supporting systems that serve our residents, in a highly secure way.

- Chi-Cheng Chu, Chief Information Officer, Durham Region

Recognizing the increasing importance of cybersecurity in the public domain, the organization set out to adopt the ISO 27001 standard. To implement this framework, CDW Canada was engaged to provide advisory and implementation support for the certification process.

CDW acted as both an advisor and implementation resource, to navigate the complexity of ISO certification while keeping the project aligned with business priorities and resource realities.

/

CDW demonstrated an understanding of the Region’s resource constraints and organizational culture throughout the project.

- Cyrus Wang, Manager – Information Security, Durham Region

Why Durham Region wanted to evolve their cybersecurity program

In 2022, Durham Region underwent a cybersecurity assessment that highlighted key areas for maturing its cybersecurity practice.

CS-IT’s leadership recognized the need to anchor its security approach to an internationally recognized standard, one that could bring structure, transparency and long-term resilience.

“The organization was doing good on the technology side, thinking from a technology, people and process perspective. However, we needed to establish practices or processes to manage what we had,” Wang added. “We were also looking for a structured governance model to handle the whole cyber risk management portion of it.”

When Chu joined the organization in 2023, one of his priorities was to translate those findings into a practical roadmap. ISO 27001 emerged as the right framework to guide that transformation, offering a proven, end-to-end approach.

“The organization pursued ISO 27001 certification to build a comprehensive, 360-degree information security management system and advance our overall security maturity,” Chu remarked.

“This would ensure the organization is not running into risks that are potentially difficult to address while defending against any of the incidents or challenges that we will be facing in the coming years.”

Cyrus Wang, Manager – Information Security, Durham Region (Right) and Chi-Cheng Chu, Chief Information Officer, Durham Region (Left)

How CDW supported the ISO certification journey

CDW has previously helped a Canadian professional services organization as well as a law firm obtain the ISO 27001 certification. Our Risk Advisory Services (RAS) team, which manages cybersecurity assessment and validation programs, engaged with Durham Region’s CS-IT team throughout the certification process.   

Going beyond technical advisory, the RAS team provided hands-on guidance, supervision and momentum that the Region needed for audit readiness. Here’s how CDW’s role unfolded in successfully facilitating the ISO 27001 certification.

Bringing structure to a complex standard

ISO 27001 introduces a highly structured framework with dozens of controls and interdependencies, something the Region was navigating for the first time. CDW helped the organization understand the requirements and plan implementation activities.

“The ISO is a very complex and systematic way of managing almost 100 different security controls,” Wang noted. “CDW was able to give us quite a strict internal audit process, so that we could spot all the weaknesses and areas that needed our attention ahead of the external audit.”

Enabling informed decision-making

Beyond execution support, CDW brought an independent, industry-informed perspective that proved valuable in aligning internal stakeholders. As a security partner, CDW helped validate decisions, reinforce priorities and ensure the program stayed aligned with best practices. This external voice carried weight across both operational teams and leadership.

As Chu noted, CDW brought “that independent voice and industry expertise that helped guide us through the process to make sure that we are working towards the right direction.”

Supporting critical areas including business continuity

One of the key technical and operational challenges involved strengthening business continuity and disaster recovery practices. While backup technologies were already in place, there was limited clarity around required control levels and implementation standards.

CDW stepped in to provide detailed guidance aligned to ISO requirements, covering areas such as encryption, backup classification and recovery expectations. The CS-IT team also benefited from structured templates and hands-on workshops.

“The resources CDW provided were very helpful for us in establishing and performing our first disaster recovery and business continuity test,” Wang added.

“As part of the process, they also gave workshops working directly with, not just our information security team, but also the enterprise technology team, to make sure everyone understood the recommendations and was able to implement them correctly.”

Driving execution with limited resources

Like many public-sector organizations, Durham Region was faced with resource constraints and competing priorities. CDW supported the Region in prioritizing activities within available resources.

Acting as a program guide, CDW helped prioritize efforts and keep teams aligned to the most critical tasks, ensuring efficiency. This discipline was key to keeping the certification on track, despite these constraints.

5 key ISO 27001 certification outcomes for Durham Region

As the certification came to conclusion, Durham Region not only bridged previous security vulnerabilities, but also implemented stronger process governance.

CSS Ref

Integrated, end-to-end processes

Security practices are now embedded across IT workflows, replacing fragmented processes with a unified approach.

Improved visibility into risk

The organization now has a clearer understanding of cybersecurity risks across systems, projects and departments.

Stronger governance and consistency

Teams follow standardized processes, ensuring repeatable and reliable execution of security controls.

Enhanced collaboration across departments

The certification effort brought multiple teams together, improving coordination and shared accountability for security.

Modernized security controls

Investments in vulnerability management, patching and privileged access management elevated the municipality’s technical posture.

Future program expansion and continued partnership with CDW

Looking ahead, Durham Region is focused on building on the early success of its ISO 27001 certification by expanding its scope across the organization and embedding a culture of continuous improvement.

Having established a strong foundation within its CS-IT environment, the Region now plans to extend the same standards to individual departments that manage their own systems and technologies.

At the same time, the organization recognizes that ISO is not a one-time milestone but an ongoing commitment requiring regular reviews, audits and refinements to keep pace with evolving risks and technologies. As the program evolves, CDW continues to provide advisory support related to the Region’s information security program.

“Public sector organizations don’t always have enough resources to take on something as ambitious as the ISO certification, which is why not many organizations take this route,” Chu said.  

“CDW provided advisory and implementation support that assisted the Region in managing priorities and allocating resources throughout the certification process,” Chu added.