In the field of hosting, trust is built not only on the speed of servers or the reliability of services. Every day, clients trust the hosting provider with much more: their websites, email accounts, backups, corporate data, and the continuity of their own business operations.
That is why for Cityhost, the issue of information security has long been part of the company's systematic work. This year, this approach received independent international confirmation: Cityhost successfully passed accreditation according to national and international standards DSTU ISO/IEC 27001, DSTU ISO/IEC 27701 and received the corresponding certificates.

DSTU ISO/IEC 27001 and DSTU ISO/IEC 27701 (hereinafter ISO) — are among the most authoritative national and international standards in the field of information security management. Their acquisition means that the company has undergone an external audit and confirmed compliance with national and international requirements in the field of information security, cybersecurity, and information protection.
What does this mean for clients?
Certification confirms that information security in the company is viewed not as a separate set of technical settings, but as an integrated system. It encompasses the assessment of potential risks, access control to information, incident response procedures, internal processes, and regular reviews of data protection approaches.
Let’s consider examples of how security work is carried out in a company that operates according to the standards DSTU ISO/IEC 27001 and DSTU ISO/IEC 27701.
Situation #1. A support employee wants to view client data
In a company without clear procedures, access to such information may be granted to significantly more employees than is actually necessary. No one checks who needs this access now and who still has it from previous positions or projects.
The ISO approach stipulates that accesses are granted according to defined rules, regularly reviewed, and unnecessary rights are removed. The company must always understand who has access to what information.
Situation #2. A corporate account of an employee has been hacked
In a crisis moment, the biggest problem often lies not in the attack itself, but in the chaos surrounding it. Who is responsible for the response? Who needs to be notified? What actions should be taken first?
Cityhost has defined incident response procedures, responsible persons, and a course of action to minimize consequences and restore normal operations.
Situation #3. An important service has stopped working due to a failure
For a client in such a situation, it is important not only that the problem will be fixed, but also how quickly the company understands the cause of the failure and begins to act. ISO provides for procedures for such cases: who makes decisions, how the incident is recorded, how its consequences are assessed, and what actions will help prevent similar problems in the future.
Situation #4. A new employee joins the company or someone resigns
Without clear rules, new employees may be granted excessive accesses "just in case," and after resignation, some accounts may remain active longer than necessary.
The standard requires monitoring the entire lifecycle of accesses — from granting them to timely revocation.
That is why DSTU ISO/IEC 27001 and DSTU ISO/IEC 27701 are valuable not so much for the certificates themselves, but for the approach to work. For users, this means confidence that issues of security, access, data backup, and incident response are not addressed situationally, but are part of a continuous controlled process.
Obtaining the certificates has become another step for Cityhost in the development of internal processes and a confirmation of responsibility to clients who have trusted us with their projects for over 20 years.



