Build an ISMS that works in the real world.
Too many ISO 27001 projects produce documentation that satisfies an auditor without ever changing how the organisation actually operates. Our approach favours a working Information Security Management System (ISMS) — built with your teams, not imposed on them — where certification is the natural outcome of a system that works, not the goal in itself.
Who it's for
- Organisations pursuing a first ISO 27001 certification
- Companies whose customers or tenders require an ISO 27001 approach
- CIOs/CISOs looking to structure security governance for the long term
Deliverable
A working Information Security Management System
Policies, procedures, a risk register and operating evidence, ready for the certification audit and grounded in your actual practices.
Starting investment
From €8,000
Process
Diagnostic
Gap analysis against the standard's requirements and Annex A controls, based on your existing practices and documentation.
Governance
Defining the ISMS scope, security policy, and associated roles and responsibilities.
Risk assessment
Establishing the risk assessment and treatment process, aligned with your business context.
Implementation
Rolling out security controls, procedures and operating evidence, with hands-on support for your teams at every step.
Audit readiness
Readiness review, an internal mock audit if needed, and support through to the certification audit with your chosen body.
ISO 27001 Readiness
Is this the right fit for your needs?
Let's talk about your context to refine the right scope and timeline.