ISO 27001 Information Security

Structured protection of critical data — and the client trust it earns you. Risk-led, proportionate, and built on controls you will actually operate.

ISO 27001 Information Security
STANDARDISO 27001:2022
DISCIPLINEInformation Security
SUPPORTGap analysis to certification

What ISO 27001 is

ISO 27001 is the international standard for information security management systems (ISMS). It sets out how to identify information security risks and apply proportionate controls to manage them — covering people, process and technology, not just IT.

The 2022 revision restructured the Annex A controls into four themes: organisational, people, physical and technological, with several new controls covering areas such as threat intelligence, cloud services and data leakage prevention.

Why organisations certify

  • Frequently demanded by enterprise clients and in procurement due diligence
  • Supports UK GDPR and data protection obligations
  • Reduces the likelihood and impact of breaches and downtime
  • Replaces repeated ad-hoc security questionnaires with one recognised certificate

How we support you

Scope and context

We define a defensible ISMS scope. Getting scope right is the single biggest driver of cost and effort — too wide and the project balloons, too narrow and clients will not accept it.

Risk assessment and treatment

We run a structured information security risk assessment, agree risk criteria and appetite, and produce a risk treatment plan with owners and timescales.

Statement of Applicability and controls

We produce the Statement of Applicability against the Annex A controls, documenting which apply, which do not, and why — then help you implement policies and controls proportionate to your risk.

Internal audit and certification

We audit the ISMS, support management review, and prepare you for Stage 1 and Stage 2 certification assessment.

What you get

  • A structured, documented risk assessment process
  • Protection of critical data proportionate to actual risk
  • Customer and stakeholder trust, evidenced by certification
  • Faster, cleaner responses to client security due diligence

Let’s talk about your project.

Tell us where you are now — we’ll come back with a first assessment and next steps.

Request a Free Consultation