Inca Safety
Client Portal Coming soon Book a consultation
Home  /  Services  /  ISO 27001
Service

ISO 27001

Build an information security management system that fits your business — not one borrowed from an enterprise security team.

We help small and medium businesses understand what they actually need to protect, choose controls they can realistically operate and build the evidence needed to stand up at audit.

Security controls you can actually operate

Most ISO 27001 guidance assumes you have a dedicated information security team, specialist software and plenty of time to manage the system.

Most small and medium businesses don’t.

That doesn’t mean ISO 27001 is out of reach. It means the system needs to be proportionate.

We start with what information you hold, what your clients and contracts require you to protect, how your business actually operates and where the meaningful risks sit.

Then we select controls you can genuinely maintain, document the decisions properly and build an information security management system that works after certification — not just during the audit.

Because a control that looks impressive on paper but nobody can operate isn’t much of a control.

ISO 27001 is about managing risk, not collecting controls.

More controls do not automatically mean better security.

ISO 27001 asks you to understand your information security risks, decide how those risks should be treated and explain why particular controls are — or are not — appropriate to your organisation.

That is why the Statement of Applicability matters.

It should tell a clear story: what risks you are managing, what controls you have selected, why they apply and how those controls operate in practice.

The goal isn’t to implement every possible security control. It’s to implement the right controls, for the right risks, and be able to demonstrate that they work.

What's included

How the engagement runs

Scope definition
Be clear about what the ISMS covers, what sits outside it and why — before the project becomes larger than it needs to be.
Risk assessment
Identify the information, systems, threats and vulnerabilities that matter, then make consistent decisions about treatment.
Statement of Applicability
Document which Annex A controls apply, which do not and the reasoning behind those decisions in a way that stands up to questioning.
Policies & operational controls
Build the policies, processes and practical controls your organisation actually needs — including access, incidents, suppliers, continuity and change.
Awareness & capability
Help your people understand the security behaviours and responsibilities that apply to their role, rather than treating awareness as an annual checkbox.
Audit evidence
Make sure the system produces the records and evidence an auditor expects because the controls are operating — not because someone assembled a folder the week before.
1
Understand the business

We define the scope, understand what information matters and identify the contractual, client and regulatory requirements driving the project.

2
Assess the risk

We work through the risks with you, decide what needs treatment and build a Statement of Applicability that reflects those decisions.

3
Put controls to work

Policies, processes, technical controls, supplier arrangements, training and records are implemented across the business — without unnecessary complexity.

4
Test and get audit-ready

We run the internal audit, complete management review, close gaps and help your people understand what to expect at certification.

Quick facts

FrameworkISO/IEC 27001:2022
Typical timeline4–7 months
Suited toBusinesses with client data obligations

Talk to a specialist

A short conversation is the fastest way to know where you stand.

Book a consultation →
Already certified?

We can help with internal audits, surveillance audit preparation, management review, corrective actions and keeping your ISMS useful between certification audits.

The aim is not just to keep the certificate. It is to keep the system working.

Build security around the business. Certification follows.

Whether you’re starting from scratch, responding to a client requirement or trying to simplify an ISMS that has become too hard to maintain, we’ll start with how your organisation actually works.

No enterprise-sized security program. No control catalogue for the sake of it. Just a practical ISO 27001 system that protects what matters and stands up under scrutiny.