ISO/IEC 27001:2022 specialists

Achieve ISO 27001 certification — and keep it working

ISO Security helps UK organisations implement a practical Information Security Management System, prepare for independent ISO/IEC 27001:2022 certification and remain audit-ready through ongoing CISO support.

  • Established 1995
  • Certified Lead Implementer
  • Certified Lead Auditor
  • CISSP
  • UK-wide support
Abstract illustration of an Information Security Management System lifecycle: governance, risk, controls and continual improvement

Why organisations call us

ISO 27001 is rarely just an IT project

Most organisations do not begin an ISO 27001 project because they want a certificate on the wall. They begin because a customer, tender, investor, regulator or board has asked for stronger evidence that information is being managed properly — and the existing answer no longer stands up to scrutiny.

That makes it a business decision with commercial consequences, involving leadership, operations, HR, suppliers and technology together.

A major customer requires certification

A key account or framework supplier has made ISO/IEC 27001:2022 a condition of continuing to work with you, and an informal answer is no longer accepted.

A tender deadline is approaching

A bid or procurement exercise asks for certification, or credible evidence that you are working towards it, within a defined timeframe.

Your existing ISMS is falling behind

Policies are out of date, the risk register has not been reviewed, actions are open and evidence is being assembled in the weeks before each audit.

Nobody internally owns information security

Responsibility is spread across IT, operations and management, so decisions stall and nothing is consistently maintained between audits.

Whatever the trigger, the requirement is the same: structure, clear ownership and practical implementation. That is what ISO Security brings.

Two connected services

Support throughout the ISO 27001 lifecycle

ISO 27001 Implementation

Build an Information Security Management System that reflects how your organisation actually operates. We assess your current position, define the scope, manage risk, develop the necessary policies and processes, implement the required controls and prepare your team for independent certification.

Ongoing CISO Services

Certification is not the end of the work. We provide ongoing CISO-level oversight to maintain your ISMS, manage risks, keep policies and evidence current, support management reviews and prepare for surveillance and recertification audits.

The implementation route

A clear route to ISO 27001 certification

Six stages, each with a defined outcome. The exact approach and timeframe depend on your organisation's size, scope, complexity and current level of readiness.
  1. 01

    Discovery and scope

    We understand how the business operates, who depends on it and what information matters most, then define an ISMS scope that is honest, defensible and credible to your customers.

  2. 02

    Gap analysis

    We assess your current position against ISO/IEC 27001:2022 and produce a prioritised action plan, so you know what genuinely needs to change before an auditor sees it.

  3. 03

    Risk assessment and treatment

    We agree a risk methodology that your team can repeat, identify information risks with the people who own them and record decisions in a risk treatment plan and Statement of Applicability.

  4. 04

    ISMS design and implementation

    We build a proportionate policy and process framework, assign roles and responsibilities, and support the implementation of the controls you have selected.

  5. 05

    Internal review and audit preparation

    We prepare and support internal audit and management review, close corrective actions and confirm that evidence exists, is current and can be found quickly.

  6. 06

    Independent certification support

    We help you engage an accredited certification body, prepare your team for Stage 1 and Stage 2, attend the audit where useful and manage any findings through to closure.

After certification

Your ISMS must operate all year — not just before an audit

ISO/IEC 27001:2022 is built on continual operation and improvement. Risks change, suppliers change, people join and leave, and systems are replaced. An auditor looks for evidence that the management system responded to those changes over time.

Ongoing CISO support is the logical continuation after implementation: the same senior adviser keeps the system running rather than rebuilding it before each audit.

  • Maintaining the ISMS programme
  • Reviewing the risk register
  • Updating policies and procedures
  • Tracking actions and control effectiveness
  • Supporting management reviews
  • Coordinating internal audit activity
  • Maintaining audit evidence
  • Preparing for surveillance audits
  • Supporting recertification
  • Providing senior management reporting
  • Helping answer customer security questionnaires
  • Advising on material business or technology changes

Why ISO Security

Senior expertise without unnecessary complexity

Direct senior involvement

Clients work directly with an experienced Lead Implementer, Lead Auditor and CISSP. There is no handover to a junior team once the work begins.

Built around your business

The ISMS should fit the organisation rather than forcing the organisation into a generic template. Scope, risk and controls reflect how you actually work.

Implementation and continuity

Support does not disappear after the certification audit. ISO Security can remain responsible for maintaining momentum through the certification cycle.

Business-focused advice

Information security decisions are explained in terms of risk, customers, contracts, operations and reputation, not technology for its own sake.

About the consultant

Practical guidance from someone who has implemented and audited information security systems

Alan Hutson is ISO Security’s Company Director and Principal Consultant. His background spans IT services, project management and business management as well as information security, which shapes how he approaches an ISMS: as something that has to work inside a live organisation with deadlines, budgets and competing priorities.

He is a certified ISO 27001 Lead Implementer and Lead Auditor, and a Certified Information Systems Security Professional (CISSP). The combination matters — building a management system and auditing one require different instincts, and knowing what an auditor will look for makes implementation more efficient.

You deal with him directly, from the first conversation through to the certification audit and beyond.

Credentials

  • Certified ISO 27001 Lead Implementer
  • Certified ISO 27001 Lead Auditor
  • Certified Information Systems Security Professional (CISSP)

Established
1995
Specialist information security focus
Since 2015
Coverage
Organisations across the UK

FAQs

ISO 27001 questions we are asked most

Straight answers on scope, timescales, ownership and what happens after certification.

Need to achieve or maintain ISO 27001?

Tell us where you are today, what is driving the requirement and when you need to be ready. We will give you a clear, practical view of the next steps.

Or email info@isosecurity.co.uk