ISO/IEC 27001 is the international standard for information security management. Certification shows customers and partners that you manage information risk systematically, and it increasingly opens doors in procurement.
ISO/IEC 27001 is also the baseline we use when designing any new solution, so our recommendations are always aligned with its control set.
How we get you certified
- Gap analysis against the standard and Annex A controls.
- Scope and context definition, agreed with leadership.
- Risk assessment and treatment, including the Statement of Applicability.
- ISMS documentation: policies, processes and procedures that fit how you work.
- Control implementation across people, process and technology.
- Internal audit and management review to prepare for the certification body.
- Certification support through Stage 1 and Stage 2 audits, and continual improvement afterwards.
Remote CISO
Not every organisation needs a full-time Chief Information Security Officer, but every organisation needs that accountability. Our remote CISO service gives you a qualified, experienced security leader who owns your information security policies, reports to your board and keeps your programme on track, all at a fraction of the cost of a permanent hire.
Managed security operations (SOC)
We design and run security monitoring that fits your risk profile, either from our own operations centre or embedded with your team on site:
- A 24-hour SOC service, delivered under agreed SLAs and escalation routes by consultants holding CISSP and CEH certifications.
- Design and deployment of SIEM, intrusion detection (IDS and HIDS), file integrity monitoring and vulnerability scanning, connected to your data centres over secure links.
- Regular penetration testing to validate your controls.
- A tailored incident management plan covering investigation, containment, escalation and lessons learned.