Is your organization digitally trustworthy?

Woman working at a desk with a desktop computer and laptop in an office cubicle.

Why resilience, governance, and independent assurance are shaping the future of business.

"Organizations need confidence that their systems, products and data will remain safe, reliable and resilient, even when things go wrong," says Jonas Van Hove, Global Lead Digital & Cyber Solutions at Kiwa. "This broader concept is what Kiwa calls Trust in Digital." Today, trust in digital is not just an IT task, but a strategic business issue, and even a societal challenge. It involves governance, operational resilience, and stakeholder confidence across organizations, value chains and entire market systems.

In this article, we discuss how trust in digital has evolved, what's driving it, and what organizations can do to prove to their customers, investors and all other stakeholders they are digitally trustworthy in the broadest sense.

From hardware to everywhere: How trust in digital has evolved

“Everything is connected” may sound like a cliché, but it is also a fact. Because of digitalization, businesses and organizations today, even ones that are not especially modern, rely on data and connected products, often with Internet of Things (IoT) capabilities embedded in their infrastructure, and increasingly autonomous AI-led systems taking on heavier roles. The clear divide between operational technology (OT) and IT has disappeared. A production line that once relied on manual machinery now gathers its own data through connected sensors. Your building’s heating system is no longer just a separate hardware package; it’s part of your digital ecosystem. Common household products, from the thermostat to the fridge, are becoming digital communication channels.

As connectivity has grown, so have expectations and concerns. Trust in digital has evolved from an internal IT responsibility into a business capability that influences procurement decisions, regulatory compliance and customer confidence. Increasingly, organizations are expected not only to protect their own systems, but also to contribute to resilience across the wider digital ecosystems in which they operate, helping to build trust throughout increasingly connected value chains and market systems. 

This shift has fundamentally changed the meaning of the term digital trust. It is no longer just about protecting customer data and ensuring that your website is compliant under the European Union’s General Data Protection Regulation (GDPR). It is about making sure a connected car can be safely driven even if its software is compromised, that the power grid stays balanced and operational even when wind and solar farms are hit by a cyberattack, and that hospitals can perform surgery even when patient data becomes unavailable. Trust in digital directly affects business continuity and reputations, safety, customer confidence and, potentially social and economic stability.

When digitalization touches everything, the safety of your business and everything it stands for is deeply tied up with trust in your digital systems. Cybersecurity and overall safety are now inseparable. And cybersecurity is just one piece of the puzzle. Building the kind of trust we need today means designing resilient systems that continue operating safely, reliably, and as intended, even during disruption.

Jonas Van Hove
Global Lead Digital & Cyber Solutions at Kiwa

What is driving trust in digital?

Several global trends are accelerating the need for stronger trust in digital.

    European legislation

    In Europe, regulations such as the Cyber Resilience Act (CRA), NIS2, the EU AI Act , and the Machinery Regulation (EU) 2023/1230 are raising expectations around cybersecurity, secure-by-design products, supply chain resilience and the protection of critical infrastructure.

    Global regulation

    Although Europe is often seen as the epicenter of cybersecurity regulation, this is a global trend, not a European one. Governments and regulators around the world are introducing new requirements to strengthen cybersecurity, digital resilience and responsible data governance. This trend extends across major markets, including Europe, the United States and Asia-Pacific, reinforcing digital trust as a growing business priority and driving companies to place growing importance on international standards such as ISO 27001 and ISO 42001.

    Supply chain expectations

    As organizations depend on a growing range of technologies, including AI, and external providers, supply chain vulnerabilities can quickly become business-critical. Insurers now require digital suppliers to be cyber-safe, and legislation in the EU and USA requires organizations to prove they are in control of the digital risks they run through their suppliers. As a result, customers and procurement teams increasingly expect suppliers and partners to demonstrate strong, internationally recognized cybersecurity and resilience measures.

    Executive accountability

    Boards and senior leadership teams are expected to understand cyber risks, demonstrate effective governance and make resilience part of strategic decision-making. Together, these developments show that digital regulations are no longer simply compliance exercises. They have become essential tools for the success of any organization: market access, building resilience, maintaining confidence across supply chains, strengthening trust throughout an organization and increasingly demonstrating the credibility needed to compete for new business.

What this means for your organization

Regardless of your industry, products or services, the growing call for digital trustworthiness directly affects your organization. If you rely on connected products, every device you use introduces potential digital risks: even relatively simple products can become entry points for cyber-attacks if resilience is not considered during design and development. The same applies to operational technology. Cyber incidents affecting industrial control systems can impact safety, disrupt production, and harm the environment. As your organization becomes more interconnected, you can no longer focus only on your own systems: the need for trustworthiness and reliability extends far beyond your own operations. Your technology partners, suppliers, customers and other stakeholders, along with the data, automation and AI they rely on, introduce new risks and expand the number of potential exposure points. Vulnerabilities elsewhere can have direct consequences for your business. Every single stakeholder you’re connected with, even indirectly, is part of your risk profile. As Jonas notes, "When everything is connected, the attack surface is bigger than ever."

Building resilience through independent assurance

Digital risk will continue to evolve. Leaks and attacks will be unavoidable, even if only because cyber attackers permit themselves to ignore all the rules by which businesses are bound. Beyond basic compliance, your company needs to strategize for long-term resilience. That means combining governance, testing, certification, red team assessments, where an authorized party attempts to penetrate your systems to identify vulnerabilities, and expert advisory services to understand risks before they become incidents. As Jonas notes, “A certificate alone does not make you resilient, but it is a starting point: it forces you to ask the right questions and begin to build resilient systems.”

Rather than relying solely on internal processes, businesses increasingly need credible third-party evidence that their systems, products and operations are reliable. Independent assurance provides that confidence, while helping organizations demonstrate compliance, strengthen governance and build trust with customers, regulators and partners. According to Jonas, "Kiwa's strength lies in its combination of functional safety expertise, cybersecurity capability and independent assurance. Few organizations can bridge physical safety, digital resilience and regulatory understanding in such a practical way." This multidisciplinary approach allows Kiwa to combine deep sector knowledge with on-the-minute cybersecurity expertise. By combining global technical expertise with local sector knowledge, Kiwa supports organizations across regions through a coordinated, customer-focused approach that aligns technical, regulatory and commercial requirements. As Jonas explains, Kiwa’s water specialists, for example, can work alongside cyber experts to understand both how systems operate in practice and how these systems and their users can be protected digitally.

Kiwa supports organizations through a broad portfolio of assurance, verification, testing and certification services tailored to different stages of digital maturity, including: 

  • IT systems
  • IoT and connected products
  • Operational technology 
  • Data and AI governance
  • Training and awareness

Whether organizations operate locally or across multiple countries, they benefit from globally consistent services delivered by experts who understand local regulations, sector requirements and operational realities.

The future of trust in digital

Trust in digital and trustworthiness are becoming more important as products, systems and supply chains become increasingly autonomous and interconnected. The rapid progress and adoption of AI alone is introducing huge, new challenges. “AI doesn’t behave predictably like traditional software does,” says Jonas. “If there’s model drift or data poisoning that leads to flawed outputs, root-cause analysis becomes harder. With AI in the mix, maintaining up-to-date logs and strong data governance is vital to keeping decision-making as transparent and efficient as possible.”

Jonas advises companies to treat trust in digital as a broad resilience issue, not a technical challenge. “Design for resilience before incidents occur, rather than simply responding after they've happened.”

Future-ready companies understand their risks, design for continuity, test their assumptions and use independent assurance to build lasting confidence among customers, partners and regulators. They recognize that trust in digital is not simply about compliance, but about building resilient organizations that can adapt as technologies, threats and regulations continue to evolve.

Independent assurance and certification are vital tools for turning trust in digital ambitions into measurable outcomes. From information security and privacy to AI management and business continuity, internationally recognized standards provide organizations with practical frameworks to strengthen governance, demonstrate trustworthiness and prepare for evolving regulatory requirements. Our next article explores how Kiwa and NQA (a Kiwa company) translate Trust in Digital into practical assurance programmes, helping organizations select the right standards, coordinate certification activities and build resilience over the long term.

Get in touch today!