top of page
ChatGPT Image Sep 15, 2026, 04_44_31 PM.png

ISO 27001 Case Study - Supporting Omnicom agencies around the world with information security

From 2018 to 2025, AKRUP worked with agencies across Omnicom Group, helping teams in Europe, Asia and the Americas implement, maintain and continually improve information security programmes aligned with ISO 27001 and TISAX.

What started as information security implementation support developed into a long-term relationship spanning multiple Omnicom businesses and countries.

Project Overview

AKRUP began working with companies within Omnicom Group in 2018, supporting individual agencies with their information security and compliance requirements.

Over the following seven years, our work expanded across a number of Omnicom businesses around the world.

While every agency was different, the objective was generally the same: help each organisation put a practical information security management system in place, achieve the required ISO 27001 certification or TISAX assessment, and then make sure those systems continued to work effectively afterwards.

Our involvement therefore went beyond getting organisations ready for their initial audits.

We continued working with teams to maintain their management systems, manage risks, review controls, update documentation, prepare for future audits and adapt their information security arrangements as their businesses changed.

For DDB UK, our relationship went further, with AKRUP also acting as the organisation's Data Protection Officer (DPO).

image.png

Engagement: 2018–2025
Industry: Advertising, Media & Marketing
Geographic Coverage: Europe, Asia and South America

Framework: ISO 27001 & TISAX
Additional Service: DPO Officer for DDB UK

The Challenge

Advertising and media agencies regularly handle sensitive information belonging to some of the world's largest brands.

Client data, campaign information, unreleased products, creative assets and commercially sensitive material can all form part of everyday operations.

For agencies working with automotive clients, these requirements can become even more demanding, with TISAX introducing specific expectations around areas such as information security, prototype protection and data protection.

The challenge across the Omnicom businesses wasn't simply achieving certification or passing an assessment.

With multiple agencies operating across different countries, the management systems needed to remain practical for individual businesses while still providing a consistent and structured approach to information security.

And once certification or TISAX labels had been achieved, the work didn't stop. Risks, systems, suppliers, employees and client requirements continued to change, meaning the management systems needed to change with them.

Our Approach

We worked directly with the teams responsible for information security within each organisation.

Rather than trying to force every Omnicom business into exactly the same model, we looked at how each organisation actually operated and built the management system around that.

For new implementations, this meant understanding the existing environment, identifying gaps against ISO 27001 or TISAX requirements and working through the changes needed to get the organisation ready.

We supported teams with risk assessments, policies, procedures, security controls, supplier management, employee awareness, internal audits, management reviews and the evidence required for external assessments.

Once the initial implementation was complete, our focus moved towards maintaining and improving the management systems.

Because the relationship lasted from 2018 to 2025, we were also able to build a much deeper understanding of the businesses we supported. Instead of starting again every year, we already understood the organisation, its risks and its previous audit history, allowing us to focus on what had actually changed and where improvements were needed.

Who We Supported

Over the course of the engagement, AKRUP worked with a wide range of companies and agencies within Omnicom Group:

AlmapBBDO – Brazil

ISO 27001 and TISAX implementation and ongoing support.

image.png

EG+ - Poland

ISO 27001 and TISAX implementation and ongoing support.

image.png

TBWA – Sweden & Finland

ISO 27001 implementation and ongoing support.

image.png

DDB UK – United Kingdom

ISO 27001 and TISAX implementation and ongoing support, alongside AKRUP acting as the organisation's Data Protection Officer.

image.png

Omnicom Media Group – Norway, Finland, Sweden & Denmark

ISO 27001 implementation and ongoing support across the Nordic operations.

image.png

DDB Colombia – Colombia

ISO 27001 implementation and ongoing support.

image.png

TBWA China – China

ISO 27001 implementation and ongoing support.

image.png

DDB Germany – Germany

ISO 27001 implementation and ongoing support.

image.png

Interbrand - U.S.A

ISO 27001 implementation and ongoing support.

image.png

BeGrizzlee - U.S.A

ISO 27001 implementation and ongoing support.

image.png

Working across different businesses and countries meant there couldn't be a one-size-fits-all approach. Each organisation had its own teams, clients, technology and ways of working, so the management systems needed to meet the requirements of ISO 27001 and TISAX while still making sense for the individual business.

A Seven-Year Relationship

What made this project particularly rewarding was the relationships we built along the way.

Between 2018 and 2025, we worked with people across Omnicom businesses in different countries, cultures and time zones. Over those seven years, that meant getting to know a lot of different teams – from senior management and information security teams to IT, HR, Legal, Finance, Facilities and people working directly with clients.

Every business was slightly different, and so were the people we worked with. Some teams already had a strong understanding of information security, while for others ISO 27001 or TISAX was completely new. A big part of our job was being able to work with all of them, explain what was needed in a straightforward way and find solutions that worked for their particular business.

As the relationship grew, we became familiar faces rather than consultants who appeared once a year before an audit. People knew who to contact when they had a question, a new client requirement, a security concern or simply weren't sure how something should be handled.

We also saw people move into new roles, teams change and new colleagues join the businesses. Being involved for so long meant we could provide continuity through those changes and share the knowledge and experience we had built up across the different Omnicom companies.

For us, that long-term relationship was one of the most valuable parts of the engagement. We weren't just working with organisations or helping them pass audits – we were working with people, building trust and becoming a reliable part of the teams we supported across Omnicom.

Project Outcome

Over seven years, our work with Omnicom grew into much more than a series of individual ISO 27001 and TISAX projects.

We had the opportunity to work with teams across Europe, Asia and South America, getting to know the different businesses and the people behind them. While each company had its own way of working, we were able to bring our experience from one project to the next while still making sure the approach worked for each individual team.

During our time working together, we helped Omnicom businesses:

  • Achieve and maintain ISO 27001 certification

  • Prepare for and successfully complete TISAX assessments

  • Build practical approaches to managing information security risks

  • Develop policies and processes that reflected how their businesses actually worked

  • Prepare for internal and external audits

  • Respond to new client and information security requirements

  • Keep their information security programmes up to date as teams, technology and businesses changed

  • Provide ongoing data protection and DPO support to DDB UK

But one of the biggest outcomes for us was the trust that developed over the course of the relationship.

As we started working with more Omnicom businesses, we were often introduced to new teams and new projects, allowing a relationship that began with individual pieces of work to grow across multiple agencies and countries.

By the end of the engagement, we had worked with people from many different parts of the Omnicom network and supported teams through audits, assessments, organisational changes and new client requirements.

For us, that's what a successful consultancy relationship should look like. Of course, achieving ISO 27001 certification or a TISAX label matters, but so does having people who know they can pick up the phone, ask a question and get practical help from someone who already understands their business.

Why AKRUP?

AKRUP has built a proven track record of helping organisations achieve successful compliance outcomes across recognised security and assurance standards. With experience supporting clients worldwide, we understand what it takes to move from uncertainty to audit-ready confidence.

Our 100% project success rate reflects the quality of our delivery, the strength of our expertise and our commitment to getting results right the first time. Businesses choose AKRUP because we provide clear direction, practical guidance and reliable support that helps turn compliance into a competitive advantage.

What our clients say

Trusted by organisations across automotive, manufacturing and technology sectors.

ChatGPT Image Jun 10, 2026, 01_15_31 PM.png
"Very happy with the service recieved and the ongoing support"

Denzil Allen, Head of HSEQT

Rudolph and Hellmann

ChatGPT Image Jun 10, 2026, 01_39_52 PM_edited.png

Speak With Our Experts

Discuss your ISO 27001 requirements with one of our specialists. Complete the form below and we'll help you plan your route to successful ISO 27001 implementation.

Looking to achieve ISO 27001? Complete the form and one of our consultants will contact you to discuss your requirements and next steps.

bottom of page