About ISO Security

Experienced, practical ISO 27001 support

ISO Security is a UK-based boutique information security consultancy working with organisations across the country. We do two things: help organisations implement ISO/IEC 27001:2022, and help them keep the management system working afterwards.

Clients deal directly with a senior consultant throughout. There is no account layer between you and the person doing the work.

Company story

From IT services to information security

ISO Security was established in 1995. The early years were spent in IT services and business technology, working closely with owner-managed and mid-sized organisations — the kind of work that teaches you how technology decisions are really made, under commercial pressure and with limited resources.

Since 2015 the practice has focused exclusively on information security: implementing Information Security Management Systems, preparing organisations for independent certification and providing the ongoing CISO-level oversight that keeps those systems credible between audits.

That focus is deliberate. We are not a general IT support provider, a penetration testing company, a managed security provider or a certification body. Being specialist in two connected services means the advice you receive is grounded in doing the same work repeatedly, across different sectors and sizes of organisation.

How we work

Engagements start with understanding the business rather than the technology: what you sell, who depends on you, what your customers and contracts require, and what would genuinely hurt if information were lost, exposed or unavailable. Only then does the conversation move to scope, risk and controls.

We work alongside your team rather than around it. The ISMS has to be operated by the organisation long after the project ends, so people need to understand why things are done, not just be handed a document to sign.

Approach

What guides the work

Practical before theoretical

A control that nobody follows is worse than no control at all. We design for the way your organisation actually works, then evidence it properly.

Proportionate documentation

Enough to satisfy the standard, demonstrate control and help people do the right thing — and no more. Volume is not a measure of quality.

Clear ownership

Every risk, policy and action has a named owner. Ambiguity is the reason most management systems stall between audits.

Plain language

Security decisions are explained in terms of customers, contracts, operations and reputation, so leadership can make informed choices.

Capability

Where we spend our time

Two services, delivered across the full ISO 27001 certification cycle.
  • ISO/IEC 27001:2022 gap analysis and readiness assessment
  • ISMS scoping, design and implementation
  • Information security risk assessment and treatment
  • Statement of Applicability and Annex A control selection
  • Internal audit and management review
  • Certification, surveillance and recertification audit support
  • Ongoing virtual CISO and ISMS management
  • Supplier and third-party information security oversight

Talk to the consultant who would do the work

An initial conversation costs nothing and is not a sales call. Explain your situation and you will get a straight assessment of what is involved.

Or email info@isosecurity.co.uk