ISO 27001 consultancy

Make information
security manageable.

Support for an information security management system that connects risk, responsibility and evidence.

WHO IT’S FOR

A clear starting point.

Organisations implementing or improving an information security management system and preparing for independent assessment.

THE THINKING BEHIND THE WORK

Security work becomes harder to manage when policies, controls and risks sit apart. We help establish a clear scope, organise the evidence and connect treatment decisions to the way your business actually operates.

THE BUILDING BLOCKS

What the work can include.

We turn these into a defined scope for your project. No vague “everything included” promises.

01

ISMS scope & context

Support defining boundaries, relevant requirements and responsibilities.

02

Risk assessment support

A structured approach to identifying, assessing and documenting information-security risks.

03

Treatment & applicability

Help linking treatment decisions, selected controls and the Statement of Applicability.

04

Policies & evidence

Practical documentation and records aligned to agreed responsibilities.

05

Review & improvement

Support with objectives, internal review, management review and corrective actions.

06

Assessment preparation

A proportionate readiness plan and evidence organisation for the agreed assessment.

HOW WE GET THERE

A process you can follow.

01

Define

Agree the ISMS scope, access boundaries and preparation needs.

02

Assess

Review risks, requirements and existing controls.

03

Organise

Support implementation, ownership and evidence.

04

Review

Evaluate progress and remaining preparation work.

What affects the scope?

The applicable requirements, technical boundaries and extent of implementation support are agreed first. This is not a penetration test or a guarantee against security incidents. Independent certification remains separate; conflict and confidentiality checks apply.

A FEW USEFUL DETAILS

Before you decide.

There’s room to ask more when we discuss your project.

Is this only for technology companies?

No. Information-security management can be relevant to many types of organisation. The scope should reflect your information, activities and requirements.

Will you configure every technical control?

Only technical implementation specifically included in the scope. We distinguish management-system consultancy from managed IT and specialist security testing.

Can you support an integrated system?

Yes, where the scope and existing arrangements make this appropriate. We look for useful shared processes rather than duplicate paperwork.

GOOD THINGS START WITH A CONVERSATION

Let’s make your
next move count.

Tell us where you are and what you want to change. We’ll review your enquiry and discuss a sensible scope and next steps.