ISO 27001 consultancy
In recent years, Britain has been called the most ‘phished’ country in the world. Sadly, it only takes one security breach to destroy a reputation which has taken years to acquire. We'll help you find what valuable data you hold, where you hold it, and how to mitigate the risks it carries.
Your project is led by a Lead Auditor with IT Governance.
What is ISO 27001?
The standard your enterprise clients ask about before they will share data with you.
ISO 27001 is the international standard that outlines the frameworks and best practices for implementing and maintaining an Information Security Management System. At its core, it helps registrants manage their sensitive information, reduce the risk of data breaches, and keep their processes and systems compliant with current laws and regulations.
Implementing an Information Technology Security System by achieving the ISO 27001 standard will help you identify what valuable data you hold, where you hold it, what risks this data presents, and, crucially, how you can mitigate these risks. Our ISO 27001 consultants can also help you write and implement the necessary policies to ensure GDPR compliance.
Why invest in ISO 27001?
ISO 27001 certification will help you:
Protect your data and stay compliant
ISO 27001 provides a comprehensive framework to ensure that you implement proper controls to safeguard personal and sensitive data – and by doing so, you'll comply with both the General Data Protection Regulation (GDPR) and the UK Data Protection Act.
Gain more trust
You'll be able to reassure your customers that you have robust systems in place to protect information from security breaches or cyberattacks. This fosters trust and confidence, which is increasingly important in the digital age where customers expect businesses like yours to take data protection seriously.
Protect your firm from cyberattacks
Data breaches, ransomware, phishing attacks, and other cybercrimes can cause significant financial and reputational harm to your business. ISO 27001 introduces strong security controls, including encryption, to reduce your vulnerabilities and keep you protected.
Boost business continuity
ISO 27001 requires businesses to have incident response plans and business continuity strategies in place. These protocols ensure that, in the event of a cyberattack, data breach, or other security incidents, you have what you need to respond quickly and effectively.
Improve your approach to risk management
The structured approach towards information security that ISO 27001 provides will help you build resilience against data breaches, loss of intellectual property, and other information security incidents, all of which can have severe financial and reputational consequences.
Improve your operational efficiency
Achieving ISO 27001 certification will transform the way you handle data, reducing the chances of human error, and ensuring that you and your employees follow tried-and-tested practices when dealing with sensitive information.
Nurture employee awareness and accountability
Everyone has their own role to play in protecting your business from cyberthreats. ISO 27001 encourages better, more regular cybersecurity training for everyone who works for and with you, reducing the frequency and impact of human errors on your security provision.
Gain a competitive advantage
Many suppliers or clients – particularly those in the finance, defence and healthcare industries – will require you to be ISO 27001 certified before they will consider you as a viable partner. Achieving the standard can open up new opportunities that weren't previously available to you.
What an ISO 27001 system actually contains
The parts an auditor will ask to see. We build each of them with you rather than handing over a finished folder.
- A defined ISMS scope — what is in it, what is out, and why
- An information asset inventory: what data you hold and where it lives
- A risk assessment, and a treatment plan that says who is doing what about it
- A Statement of Applicability recording which Annex A controls apply to you
- Controls mapped to the 2022 revision's reorganised themes, not the old layout
- Incident response and business continuity plans that have been tested
- An internal audit programme and management review that produce decisions
- Readiness for a two-stage certification audit, with us in the room
Already certified to ISO 9001?
We can also help to implement ISO 27001 within the ISO 9001 framework, if you have already gained this standard — one management system and one audit cycle, rather than two running in parallel. See our ISO 9001 page.
How ISO 27001 registration actually works
Six stages, in the order we work through them. How long each takes depends on how much of your data you can already account for.
-
Stage 1
Gap analysis against the 2022 revision
We look at what you already have and measure it against the current version of the standard, then tell you plainly how far off you are. Nothing is committed at this point.
-
Stage 2
Scope and asset inventory
Deciding what the ISMS covers, and finding the data. This stage regularly turns up systems and spreadsheets nobody had counted as holding client information.
-
Stage 3
Risk assessment and Statement of Applicability
We work through the risks with you, write the treatment plan, and record which Annex A controls apply — and, just as importantly, which do not and why.
-
Stage 4
Training your team
ISO 27001 is the only standard we offer risk awareness training for, alongside auditor, management awareness and staff awareness training. Human error is the usual way in.
-
Stage 5
Internal audits and management review
We run the audit programme and the review meetings so the ISMS is genuinely operating, rather than documented, before anyone external looks at it.
-
Stage 6
The certification audit, and everything after it
ISO 27001 is assessed in two stages. A consultant is with you for both, and stays on for the surveillance visits afterwards if you want us to.
A client has asked whether you are certified. Now what?
That is how most ISO 27001 projects start here. Tell us what they have asked for and what you already have, and we'll tell you what is realistic.
What to expect from our ISO 27001 consultants
If you're concerned that your data isn't as closely guarded as you'd like, and you can see the value in investing in this certification for your firm, it's time to speak to our dedicated ISO 27001 consultants.
At ADL Consultancy, we take a tailored approach to every project, ensuring our clients get precisely what they need from our ISO experts, when they need it. David is a Lead Auditor with IT Governance and our Managing Director; he builds and maintains Information Security Management Systems for clients across the UK.
We're a family consultancy with family values, and we love nothing more than seeing our clients succeed. We typically work with companies in Essex, London, Hertfordshire, and the surrounding areas.
- Risk assessment and gap analysis against the 2022 revision
- Statement of Applicability and the control set that actually fits you
- Internal audits and management review meetings
- Staff and risk awareness training as part of the rollout
Sectors that ask for ISO 27001 first
- Finance
- Legal
- Healthcare
- Defence
- IT & managed services
- SaaS & software
- Recruitment
- Public sector suppliers
We typically work with companies in Essex, London, Hertfordshire and the surrounding areas — including a dedicated page for businesses in Kent.
Businesses we have taken through ISO 27001
Three companies whose information security management systems we built and still audit.
“When we decided to undertake our ISO27001 journey, finding a consultant that could make this as painless an experience as possible was key. David's expertise in his field is second to none but also his patience and understanding of our position as business owners, ensuring day to day productivity wasn't effected was invaluable.”
“After a couple of attempts at navigating the process internally, we found the process overwhelming. We were introduced to David at ADL Consultancy, who instantly put us at ease, and assisted us with receiving both ISO 27001 and 9001 certification first time around. I cannot recommend them highly enough!”
“Working alongside ADL Consultancy has been nothing short of an absolute pleasure. They have helped Support UK to secure certification in ISO9001 and ISO27001, and this will be a massive growth stepping stone for our organisation.”
Certification only counts if the certificate does. Every ISMS we have taken to audit has been registered with a UKAS approved body — the ones your clients will check
Where ISO 27001 takes you next
An ISMS is a good foundation. These are the standards our information security clients most often add to it.
ISO 9001 & AS9100
The framework ISO 27001 can be implemented inside. Several of our clients certified to both at once and run a single set of audits.
ISO 9001 consultantsISO 42001 Artificial Intelligence
If you are building AI into your product, ISO 42001 extends an existing information security system rather than replacing it.
ISO 42001 certificationISO 27001 training
Auditor, management awareness, staff awareness and risk awareness training — the last of which we run only for ISO 27001.
See the coursesGet in touch about ISO 27001
Get in touch today for more information on our ISO 27001 consulting services and take the first step towards a safer, more secure future for your organisation.