Information Security Management Consultancy
We assist clients in effectively implementing, maintaining, and continuously enhancing their information security management systems and achieving ISO 27001 certification.
Our expert consultants and tutors offer on-premise services across the UK and virtual services globally. They can support specific projects to help organisations address the challenges of meeting ISO 27001 expectations.
In our 40 years of consulting experience, we have helped clients with projects such as:
- assessing how close a current ISMS is to standards requirements through gap analysis
- auditing the ISMS to ensure that it is and continues to be compliant
- identifying and reporting on information security risks
- applying information security risk treatment processes
- developing ISO 27001 training programmes
- creating and reviewing required documentation
How we can help
ISO 27001 gap analysis
A gap analysis objectively assesses how closely your current system meets ISO 27001 requirements.
Our ISMS consultant will review your management system and provide a written report detailing where your system does and does not conform to ISO 27001. The report findings can be used to develop an ISMS implementation plan.
Auditing against ISO 27001
Pre-assessment audits, supplier audits and internal audits assist in ensuring the information security management system is effectively implemented and maintained.
From undertaking a full audit of your ISMS to coaching your team through the audit process, our experienced consultants can provide as much support as required.
Developing ISMS documentation
ISO 27001 outlines the requirements for documented information including the ISMS scope, policy and the information security objectives.
Our ISO 27001 consultants can create documentation on your behalf, review your current documentation or advise on specified documentation you require support with.
ISO 27001 training programme
By creating and implementing a tailored ISMS training programme, organisations can become fully independent in managing their IMS for ISO 27001 certification and continuous improvement.
Our consultants can guide you through our ISO 27001 training courses, including CQI and IRCA certified ISO 27001 Lead Auditor and ISO 27001 Internal Auditor training, available across the UK, online, and on a dedicated basis at your organisation.
Information security risk assessment
ISO 27001 requires organisations to define and apply an information security assessment process.
Our information security consultants can provide support establishing your information security risk criteria and identifying, analysing and evaluating the information security risks to ensure compliance with ISO 27001. A report with findings and recommendations will be provided on completion.
Information security risk treatment
Clause 6.1.3 outlines the requirements for organisations to define and apply an information security risk treatment process. Annex A contains a list of control objectives and controls to ensure no necessary controls are overlooked.
Our experienced consultants, including Lead Auditors and Lead Implementers, can provide support selecting appropriate information security risk treatment options, determining controls and formulating an information security risk treatment plan.
Nonconformities and corrective action
Clause 10 of ISO 27001 outlines the requirements in relation to nonconformities and corrective actions. Organisations are required to react to the nonconformity and eliminate the cause to prevent reoccurrence.
If nonconformities were identified during your audit our consultants can provide advice and support in implementing corrective actions to address these, ensuring the results of these actions comply with the requirements of ISO 27001.
Speak to us
If you would like to speak to someone about how we can support your organisation call our team on 0333 123 9001 or contact us.
Customer reviews
Speedy Freight|19th Feb, 2025
Scottish Power|18th Feb, 2025
GSK|12th Feb, 2025
McCabe McGinn Construction Ltd|10th Feb, 2025
Accrofab Ltd|7th Feb, 2025
Arcus Fm|6th Feb, 2025
GSK|31st Jan, 2025
East Riding of Yorkshire Council|30th Jan, 2025
Micronclean Ltd|27th Jan, 2025
Turner & Townsend|24th Jan, 2025
Micronclean Ltd|23rd Jan, 2025
Altro Limited|20th Jan, 2025
Our Clients
We have worked with organisations across a range of industries from small UK based companies to internationally renowned organisations.
Our Reviews
We pride ourselves on our excellent customer feedback, view our most recent course reviews from our delegates.
Virtual Classroom
Our interactive, tutor-led Virtual Classroom training allows delegates to up-skill from the convenience of their home or office.
Lead Auditor Courses
View our range of CQI and IRCA certified Lead Auditor Training Courses including ISO 9001, ISO 14001 and ISO 45001.
Internal Auditor Courses
Acquire the skills to plan, conduct, report and follow up an Internal Audit with training across a variety of standards.