Book a Security Assessment enquiry@cybersecuritylondon.com · London Bridge
Service 10 / 12

ISO 27001
consultancy.

ISO 27001 shows clients you manage information security properly. Our consultants help you build an information security management system that fits how you work, and get it certified.

  • Gap analysis
  • ISMS implementation
  • Internal audit
  • Certification support

Last reviewed

The Shard rising into low cloud above London Bridge
01 — Overview

What it is,
and why it matters.

ISO 27001 is the international standard for information security management. Certification is increasingly expected by larger clients, especially in finance, technology and professional services.

We keep it practical. Rather than a pile of generic templates, we build policies and processes around how your business already runs, so the system is useful as well as certifiable.

A good fit if…

  • Clients or tenders are asking for ISO 27001
  • You want a structured, recognised security framework
  • You already have Cyber Essentials and want to go further
  • A previous ISO project stalled
02 — What's included

Everything you need,
nothing you don't.

01

Gap analysis

Where you stand today against the standard.

02

Risk assessment

The information security risk assessment at the heart of ISO 27001.

03

ISMS documentation

Policies, procedures and the Statement of Applicability, written to fit your business.

04

Control implementation

Practical help putting the Annex A controls in place.

05

Internal audit

An independent internal audit before the certification audit.

06

Certification support

Preparation for and support during the external audit.

03 — How it works

Four clear
steps.

  1. Step 1

    Gap analysis

    Compare where you are with the standard.

  2. Step 2

    Build

    Create the ISMS and implement controls.

  3. Step 3

    Audit

    Run the internal audit and management review.

  4. Step 4

    Certify

    Support through the certification body's audit.

04 — Options

How we can help

A

Full implementation

From gap analysis to certification, with our consultants alongside you.

B

Gap analysis only

A clear report of what is needed and how long it will take.

C

Internal audit service

Independent internal audits to keep your certification on track.

D

Ongoing ISMS support

Help with surveillance audits, changes and the 2022 transition.

05 — Cost

What affects
the cost.

1

Size and scope

The number of people, locations and systems in your ISMS scope.

2

Starting point

Existing policies and controls reduce the work needed.

3

Support level

Full implementation or targeted help where you need it.

4

Certification body

The external audit fee is separate and set by the certification body.

After a gap analysis we give you a clear breakdown of ISO 27001 certification cost: our fees and the expected certification body fee.

Get a quote
06 — FAQs

Questions,
answered.

An international standard for managing information security. It requires a risk-based management system (an ISMS) covering people, processes and technology.

It depends on the size and complexity of your business and how much is already in place. There are consultancy costs and a separate certification body fee. A gap analysis gives you an accurate figure.

Typically several months for a small to medium business, depending on your starting point and the time your team can give.

The Annex A controls were reorganised into four themes and some new controls were added, such as threat intelligence and cloud security. We help existing certificate holders transition.

07 — Guides

Further
reading.

Next step

Let's talk about
ISO 27001.

A short call, no obligation. We'll listen, ask a few questions and suggest a sensible first step.

Contact

Start with
an assessment.

Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.

Studio

The Leather Market
London Bridge

Dealing with a live incident? Put “urgent” in your message or email enquiry@cybersecuritylondon.com. We use your details only to reply, see our privacy notice.