Practical before theoretical
A control that nobody follows is worse than no control at all. We design for the way your organisation actually works, then evidence it properly.
About ISO Security
ISO Security is a UK-based boutique information security consultancy working with organisations across the country. We do two things: help organisations implement ISO/IEC 27001:2022, and help them keep the management system working afterwards.
Clients deal directly with a senior consultant throughout. There is no account layer between you and the person doing the work.
Company story
ISO Security was established in 1995. The early years were spent in IT services and business technology, working closely with owner-managed and mid-sized organisations — the kind of work that teaches you how technology decisions are really made, under commercial pressure and with limited resources.
Since 2015 the practice has focused exclusively on information security: implementing Information Security Management Systems, preparing organisations for independent certification and providing the ongoing CISO-level oversight that keeps those systems credible between audits.
That focus is deliberate. We are not a general IT support provider, a penetration testing company, a managed security provider or a certification body. Being specialist in two connected services means the advice you receive is grounded in doing the same work repeatedly, across different sectors and sizes of organisation.
Engagements start with understanding the business rather than the technology: what you sell, who depends on you, what your customers and contracts require, and what would genuinely hurt if information were lost, exposed or unavailable. Only then does the conversation move to scope, risk and controls.
We work alongside your team rather than around it. The ISMS has to be operated by the organisation long after the project ends, so people need to understand why things are done, not just be handed a document to sign.
Approach
A control that nobody follows is worse than no control at all. We design for the way your organisation actually works, then evidence it properly.
Enough to satisfy the standard, demonstrate control and help people do the right thing — and no more. Volume is not a measure of quality.
Every risk, policy and action has a named owner. Ambiguity is the reason most management systems stall between audits.
Security decisions are explained in terms of customers, contracts, operations and reputation, so leadership can make informed choices.
Capability
An initial conversation costs nothing and is not a sales call. Explain your situation and you will get a straight assessment of what is involved.
Or email info@isosecurity.co.uk