ISO/IEC 27001 Consulting and Certification Support
Senior-led ISO/IEC 27001:2022 consulting for UK organisations pursuing certification, re-certification or a defensible information security posture for clients and auditors.
Our approach
Scope and gap assessment
Define the scope of the ISMS, benchmark current controls against ISO/IEC 27001:2022 and Annex A, and identify the shortest credible path to certification.
Risk assessment and treatment
Establish a repeatable information risk methodology, run the initial assessment, and produce a defensible Statement of Applicability and treatment plan.
ISMS design and implementation
Policies, standards, procedures, evidence and metrics that fit how your organisation actually works, integrated with existing governance rather than bolted on.
Internal audit and management review
Independent internal audit, management review preparation and remediation of findings before Stage 1 and Stage 2 certification audits.
Certification audit support
Auditor liaison, evidence packs, non-conformity response and ongoing surveillance-audit readiness for years two and three.
Related
Operational resilience
FCA operational resilience, DORA and third-party risk.
Read about Operational resilience →Virtual CISO and vCISO
Senior cyber security leadership without a permanent hire.
Read about Virtual CISO and vCISO →AI governance
ISO/IEC 42001, EU AI Act and responsible AI adoption.
Read about AI governance →