A major customer requires certification
A key account or framework supplier has made ISO/IEC 27001:2022 a condition of continuing to work with you, and an informal answer is no longer accepted.
ISO/IEC 27001:2022 specialists
ISO Security helps UK organisations implement a practical Information Security Management System, prepare for independent ISO/IEC 27001:2022 certification and remain audit-ready through ongoing CISO support.

Why organisations call us
Most organisations do not begin an ISO 27001 project because they want a certificate on the wall. They begin because a customer, tender, investor, regulator or board has asked for stronger evidence that information is being managed properly — and the existing answer no longer stands up to scrutiny.
That makes it a business decision with commercial consequences, involving leadership, operations, HR, suppliers and technology together.
A key account or framework supplier has made ISO/IEC 27001:2022 a condition of continuing to work with you, and an informal answer is no longer accepted.
A bid or procurement exercise asks for certification, or credible evidence that you are working towards it, within a defined timeframe.
Policies are out of date, the risk register has not been reviewed, actions are open and evidence is being assembled in the weeks before each audit.
Responsibility is spread across IT, operations and management, so decisions stall and nothing is consistently maintained between audits.
Whatever the trigger, the requirement is the same: structure, clear ownership and practical implementation. That is what ISO Security brings.
Two connected services
Build an Information Security Management System that reflects how your organisation actually operates. We assess your current position, define the scope, manage risk, develop the necessary policies and processes, implement the required controls and prepare your team for independent certification.
Certification is not the end of the work. We provide ongoing CISO-level oversight to maintain your ISMS, manage risks, keep policies and evidence current, support management reviews and prepare for surveillance and recertification audits.
The implementation route
We understand how the business operates, who depends on it and what information matters most, then define an ISMS scope that is honest, defensible and credible to your customers.
We assess your current position against ISO/IEC 27001:2022 and produce a prioritised action plan, so you know what genuinely needs to change before an auditor sees it.
We agree a risk methodology that your team can repeat, identify information risks with the people who own them and record decisions in a risk treatment plan and Statement of Applicability.
We build a proportionate policy and process framework, assign roles and responsibilities, and support the implementation of the controls you have selected.
We prepare and support internal audit and management review, close corrective actions and confirm that evidence exists, is current and can be found quickly.
We help you engage an accredited certification body, prepare your team for Stage 1 and Stage 2, attend the audit where useful and manage any findings through to closure.
After certification
ISO/IEC 27001:2022 is built on continual operation and improvement. Risks change, suppliers change, people join and leave, and systems are replaced. An auditor looks for evidence that the management system responded to those changes over time.
Ongoing CISO support is the logical continuation after implementation: the same senior adviser keeps the system running rather than rebuilding it before each audit.
Why ISO Security
Clients work directly with an experienced Lead Implementer, Lead Auditor and CISSP. There is no handover to a junior team once the work begins.
The ISMS should fit the organisation rather than forcing the organisation into a generic template. Scope, risk and controls reflect how you actually work.
Support does not disappear after the certification audit. ISO Security can remain responsible for maintaining momentum through the certification cycle.
Information security decisions are explained in terms of risk, customers, contracts, operations and reputation, not technology for its own sake.
About the consultant
Alan Hutson is ISO Security’s Company Director and Principal Consultant. His background spans IT services, project management and business management as well as information security, which shapes how he approaches an ISMS: as something that has to work inside a live organisation with deadlines, budgets and competing priorities.
He is a certified ISO 27001 Lead Implementer and Lead Auditor, and a Certified Information Systems Security Professional (CISSP). The combination matters — building a management system and auditing one require different instincts, and knowing what an auditor will look for makes implementation more efficient.
You deal with him directly, from the first conversation through to the certification audit and beyond.
Credentials
FAQs
Tell us where you are today, what is driving the requirement and when you need to be ready. We will give you a clear, practical view of the next steps.
Or email info@isosecurity.co.uk