Structured protection of critical data — and the client trust it earns you. Risk-led, proportionate, and built on controls you will actually operate.

ISO 27001 is the international standard for information security management systems (ISMS). It sets out how to identify information security risks and apply proportionate controls to manage them — covering people, process and technology, not just IT.
The 2022 revision restructured the Annex A controls into four themes: organisational, people, physical and technological, with several new controls covering areas such as threat intelligence, cloud services and data leakage prevention.
We define a defensible ISMS scope. Getting scope right is the single biggest driver of cost and effort — too wide and the project balloons, too narrow and clients will not accept it.
We run a structured information security risk assessment, agree risk criteria and appetite, and produce a risk treatment plan with owners and timescales.
We produce the Statement of Applicability against the Annex A controls, documenting which apply, which do not, and why — then help you implement policies and controls proportionate to your risk.
We audit the ISMS, support management review, and prepare you for Stage 1 and Stage 2 certification assessment.
Tell us where you are now — we’ll come back with a first assessment and next steps.
Request a Free Consultation