ISO 27001
Build an information security management system that fits your business — not one borrowed from an enterprise security team.
We help small and medium businesses understand what they actually need to protect, choose controls they can realistically operate and build the evidence needed to stand up at audit.
Security controls you can actually operate
Most ISO 27001 guidance assumes you have a dedicated information security team, specialist software and plenty of time to manage the system.
Most small and medium businesses don’t.
That doesn’t mean ISO 27001 is out of reach. It means the system needs to be proportionate.
We start with what information you hold, what your clients and contracts require you to protect, how your business actually operates and where the meaningful risks sit.
Then we select controls you can genuinely maintain, document the decisions properly and build an information security management system that works after certification — not just during the audit.
Because a control that looks impressive on paper but nobody can operate isn’t much of a control.
ISO 27001 is about managing risk, not collecting controls.
More controls do not automatically mean better security.
ISO 27001 asks you to understand your information security risks, decide how those risks should be treated and explain why particular controls are — or are not — appropriate to your organisation.
That is why the Statement of Applicability matters.
It should tell a clear story: what risks you are managing, what controls you have selected, why they apply and how those controls operate in practice.
The goal isn’t to implement every possible security control. It’s to implement the right controls, for the right risks, and be able to demonstrate that they work.
What's included
How the engagement runs
We define the scope, understand what information matters and identify the contractual, client and regulatory requirements driving the project.
We work through the risks with you, decide what needs treatment and build a Statement of Applicability that reflects those decisions.
Policies, processes, technical controls, supplier arrangements, training and records are implemented across the business — without unnecessary complexity.
We run the internal audit, complete management review, close gaps and help your people understand what to expect at certification.
Quick facts

Talk to a specialist
A short conversation is the fastest way to know where you stand.
Book a consultation →We can help with internal audits, surveillance audit preparation, management review, corrective actions and keeping your ISMS useful between certification audits.
The aim is not just to keep the certificate. It is to keep the system working.
Build security around the business. Certification follows.
Whether you’re starting from scratch, responding to a client requirement or trying to simplify an ISMS that has become too hard to maintain, we’ll start with how your organisation actually works.
No enterprise-sized security program. No control catalogue for the sake of it. Just a practical ISO 27001 system that protects what matters and stands up under scrutiny.