Cyber security intelligence, AI governance, practitioner analysis
Flagship certification
ISO/IEC 27001 Implementation and Remediation
Full-cycle ISO/IEC 27001 consultancy: gap analysis, ISMS implementation, remediation of failed audits, and internal audit cycles, led by a Lead Auditor with six programmes taken through certification.
ISO/IEC 27001 fails in predictable places: scope drawn too wide, controls documented but not operated, and internal audits that do not test what the certification auditor will. This engagement covers the full cycle: implementation from zero, remediation of a struggling programme, or rescue after a failed audit.
Frameworks covered
ISO/IEC 27001:2022
The management system clauses and all 93 Annex A controls
ISO/IEC 27002
Implementation guidance applied control by control
SOC 2 crosswalk
Evidence mapped once, reused for both frameworks
How the engagement runs
1
Gap analysis
Every clause and control assessed against three honest states: absent, documented but not operating, and operating with evidence.
2
Scope and risk assessment
A defensible ISMS scope, an asset-based risk assessment, and a risk register your teams can maintain without a consultant on retainer.
3
Implementation and remediation
Controls built or repaired in priority order, with policies people actually follow and evidence pipelines that run themselves.
4
Internal audit
Audit cycles run the way the external auditor will run them, so findings surface while they are cheap to fix.
5
Certification and surveillance
Pre-audit review, audit-day support, and a surveillance calendar so year two does not become a scramble.
What you walk away with
Clause-by-clause gap report with nonconformity severity
Complete ISMS documentation set: policies, risk register, Statement of Applicability
Remediation plan with owners, dates, and effort estimates
Internal audit reports to certification standard
Audit-day support and surveillance calendar
How this plays out
Example scenario
A fintech needed certification inside nine months to unblock two enterprise deals that required it contractually.
The work: Tight scope, risk assessment in the first month, controls implemented in dependency order, and internal audit at month six against the certification standard.
Stage 1 and stage 2 passed first time; both enterprise contracts closed with the certificate attached.
Example scenario
An established firm failed stage 2 with major nonconformities in supplier management and access control, with the auditor returning in four months.
The work: Remediation triage: the majors closed with operating evidence, not paperwork, and a mock re-audit two weeks before the real one.
Certification achieved at the return visit; the remediation register became the firm's standing improvement process.
Start the conversation
A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.
Not whether your security is good. Whether you can demonstrate that you decide
about it deliberately, act on those decisions, and check that the actions
worked.
That distinction decides how a readiness engagement is run. An organisation
with modest controls and honest records passes. One with excellent controls
and no evidence that anybody chose them does not, and is usually more
surprised.
Record every requirement in one of three states
Most readiness assessments use two, present and absent, and that is why they overstate. A written procedure nobody has run is not a control. An assessor does not ask whether a document exists; they ask when it last ran and to see what it produced.
The middle column is where most organisations sit and where most nonconformities
come from. A readiness assessment that cannot distinguish it from the right-hand
column is telling you what you want to hear.
The 2022 revision, and why the transition matters
Annex A was restructured in the 2022 revision, from 114 controls in fourteen
clauses to 93 in four themes, with eleven controls that did not exist before.
Certificates issued against the 2013 version ceased to be valid on 31 October
2025. An organisation still working from 2013-era documentation is preparing
for an audit that no longer exists, and the newer controls are the ones most
likely to be genuinely absent rather than merely undocumented: threat
intelligence, information security for cloud services, ICT readiness for
business continuity, secure coding.
Where the time actually goes
Six to twelve months from a standing start, and the constraint is operating
history rather than documentation.
A risk assessment is evidenced by having been made, with owners and dates. An
internal audit has to have found something. A management review has to have
decided something. None of it can be produced retrospectively, and no budget
compresses it, which is why the honest advice is often to start the parts that
accrue time before deciding whether to certify at all.
The Statement of Applicability is the document that takes longest and is
judged hardest, because it is where an assessor reads whether somebody made a
decision about each control or wrote one sentence ninety-three times.
Whether you need this at all
Worth asking, because the answer is frequently no.
Organisations routinely begin an ISO 27001 programme when the customer asking
for assurance would have accepted Cyber Essentials Plus and a documented
supplier process, at a fraction of the cost and in a quarter of the time. The
question to answer first is what the person asking actually needs, and that is
usually a shorter conversation than the programme it replaces.
Where certification genuinely is required, starting with an honest picture of
the gap is cheaper than starting with a consultant's template, because the
template describes an organisation you do not have.
How the engagement runs
An assessment produces a gap picture scored against what an auditor would
raise rather than as a percentage, because a number like 68% ready is not
actionable and flatters by averaging a missing risk assessment against a
well-written policy.
The output is sequenced by dependency and effort, not by clause number, and it
is dated. A readiness assessment loses accuracy within months, and one used to
commit to a certification timeline after it has gone stale is worse than none.
Performed personally, by a practitioner who audits to this standard.