Information security

ISO 27001 consultancy

In recent years, Britain has been called the most ‘phished’ country in the world. Sadly, it only takes one security breach to destroy a reputation which has taken years to acquire. We'll help you find what valuable data you hold, where you hold it, and how to mitigate the risks it carries.

Your project is led by a Lead Auditor with IT Governance.

ISO 27001

What is ISO 27001?

The standard your enterprise clients ask about before they will share data with you.

ISO 27001 is the international standard that outlines the frameworks and best practices for implementing and maintaining an Information Security Management System. At its core, it helps registrants manage their sensitive information, reduce the risk of data breaches, and keep their processes and systems compliant with current laws and regulations.

Implementing an Information Technology Security System by achieving the ISO 27001 standard will help you identify what valuable data you hold, where you hold it, what risks this data presents, and, crucially, how you can mitigate these risks. Our ISO 27001 consultants can also help you write and implement the necessary policies to ensure GDPR compliance.

2002 Building management systems for SMEs since
100% Of our clients registered first time
2022 The revision of the standard we implement against
0 Contracts to sign before we start

Why invest in ISO 27001?

ISO 27001 certification will help you:

Protect your data and stay compliant

ISO 27001 provides a comprehensive framework to ensure that you implement proper controls to safeguard personal and sensitive data – and by doing so, you'll comply with both the General Data Protection Regulation (GDPR) and the UK Data Protection Act.

Gain more trust

You'll be able to reassure your customers that you have robust systems in place to protect information from security breaches or cyberattacks. This fosters trust and confidence, which is increasingly important in the digital age where customers expect businesses like yours to take data protection seriously.

Protect your firm from cyberattacks

Data breaches, ransomware, phishing attacks, and other cybercrimes can cause significant financial and reputational harm to your business. ISO 27001 introduces strong security controls, including encryption, to reduce your vulnerabilities and keep you protected.

Boost business continuity

ISO 27001 requires businesses to have incident response plans and business continuity strategies in place. These protocols ensure that, in the event of a cyberattack, data breach, or other security incidents, you have what you need to respond quickly and effectively.

Improve your approach to risk management

The structured approach towards information security that ISO 27001 provides will help you build resilience against data breaches, loss of intellectual property, and other information security incidents, all of which can have severe financial and reputational consequences.

Improve your operational efficiency

Achieving ISO 27001 certification will transform the way you handle data, reducing the chances of human error, and ensuring that you and your employees follow tried-and-tested practices when dealing with sensitive information.

Nurture employee awareness and accountability

Everyone has their own role to play in protecting your business from cyberthreats. ISO 27001 encourages better, more regular cybersecurity training for everyone who works for and with you, reducing the frequency and impact of human errors on your security provision.

Gain a competitive advantage

Many suppliers or clients – particularly those in the finance, defence and healthcare industries – will require you to be ISO 27001 certified before they will consider you as a viable partner. Achieving the standard can open up new opportunities that weren't previously available to you.

Inside the standard

What an ISO 27001 system actually contains

The parts an auditor will ask to see. We build each of them with you rather than handing over a finished folder.

  • A defined ISMS scope — what is in it, what is out, and why
  • An information asset inventory: what data you hold and where it lives
  • A risk assessment, and a treatment plan that says who is doing what about it
  • A Statement of Applicability recording which Annex A controls apply to you
  • Controls mapped to the 2022 revision's reorganised themes, not the old layout
  • Incident response and business continuity plans that have been tested
  • An internal audit programme and management review that produce decisions
  • Readiness for a two-stage certification audit, with us in the room

Already certified to ISO 9001?

We can also help to implement ISO 27001 within the ISO 9001 framework, if you have already gained this standard — one management system and one audit cycle, rather than two running in parallel. See our ISO 9001 page.

What to expect

How ISO 27001 registration actually works

Six stages, in the order we work through them. How long each takes depends on how much of your data you can already account for.

  1. Stage 1

    Gap analysis against the 2022 revision

    We look at what you already have and measure it against the current version of the standard, then tell you plainly how far off you are. Nothing is committed at this point.

  2. Stage 2

    Scope and asset inventory

    Deciding what the ISMS covers, and finding the data. This stage regularly turns up systems and spreadsheets nobody had counted as holding client information.

  3. Stage 3

    Risk assessment and Statement of Applicability

    We work through the risks with you, write the treatment plan, and record which Annex A controls apply — and, just as importantly, which do not and why.

  4. Stage 4

    Training your team

    ISO 27001 is the only standard we offer risk awareness training for, alongside auditor, management awareness and staff awareness training. Human error is the usual way in.

  5. Stage 5

    Internal audits and management review

    We run the audit programme and the review meetings so the ISMS is genuinely operating, rather than documented, before anyone external looks at it.

  6. Stage 6

    The certification audit, and everything after it

    ISO 27001 is assessed in two stages. A consultant is with you for both, and stays on for the surveillance visits afterwards if you want us to.

A client has asked whether you are certified. Now what?

That is how most ISO 27001 projects start here. Tell us what they have asked for and what you already have, and we'll tell you what is realistic.

ISO 27001 consultants

What to expect from our ISO 27001 consultants

If you're concerned that your data isn't as closely guarded as you'd like, and you can see the value in investing in this certification for your firm, it's time to speak to our dedicated ISO 27001 consultants.

At ADL Consultancy, we take a tailored approach to every project, ensuring our clients get precisely what they need from our ISO experts, when they need it. David is a Lead Auditor with IT Governance and our Managing Director; he builds and maintains Information Security Management Systems for clients across the UK.

We're a family consultancy with family values, and we love nothing more than seeing our clients succeed. We typically work with companies in Essex, London, Hertfordshire, and the surrounding areas.

  • Risk assessment and gap analysis against the 2022 revision
  • Statement of Applicability and the control set that actually fits you
  • Internal audits and management review meetings
  • Staff and risk awareness training as part of the rollout
David, Managing Director and Lead Auditor with IT Governance

Sectors that ask for ISO 27001 first

  • Finance
  • Legal
  • Healthcare
  • Defence
  • IT & managed services
  • SaaS & software
  • Recruitment
  • Public sector suppliers

We typically work with companies in Essex, London, Hertfordshire and the surrounding areas — including a dedicated page for businesses in Kent.

Testimonials

Businesses we have taken through ISO 27001

Three companies whose information security management systems we built and still audit.

“When we decided to undertake our ISO27001 journey, finding a consultant that could make this as painless an experience as possible was key. David's expertise in his field is second to none but also his patience and understanding of our position as business owners, ensuring day to day productivity wasn't effected was invaluable.”
Operations DirectorPlatform365
“After a couple of attempts at navigating the process internally, we found the process overwhelming. We were introduced to David at ADL Consultancy, who instantly put us at ease, and assisted us with receiving both ISO 27001 and 9001 certification first time around. I cannot recommend them highly enough!”
Managing DirectorMethod IT
“Working alongside ADL Consultancy has been nothing short of an absolute pleasure. They have helped Support UK to secure certification in ISO9001 and ISO27001, and this will be a massive growth stepping stone for our organisation.”
Business Alliance ManagerSupport UK Ltd

Certification only counts if the certificate does. Every ISMS we have taken to audit has been registered with a UKAS approved body — the ones your clients will check

BSI NQA LRQA British Assessment Bureau BRE Auva

Get in touch about ISO 27001

Get in touch today for more information on our ISO 27001 consulting services and take the first step towards a safer, more secure future for your organisation.