Be ready for the security questions customers and auditors ask.
We prepare practical security processes and policies, and organize evidence for ISO 27001 and customer reviews, building on what you already have.
Services
- 01
ISO-27001 Readiness Assessment
A customer has asked about ISO 27001, and you need to understand what's already in place and what's still missing.
What changesA clear starting point, with the main gaps, priorities and next steps explained.
What we deliverView service: ISO-27001 Readiness Assessment- An agreed preparation goal and scope, based on your business and customer requirements.
- A review of existing security practices and evidence against the agreed ISO 27001 requirements.
- Findings linked to the evidence reviewed, with a prioritized action plan and dependencies.
- 02
ISMS Starter Package
Security responsibilities and records need a structure your team can actually use.
What changesA practical starting point for managing information security, with clear responsibilities and next steps.
What we deliverView service: ISMS Starter Package- An agreed starting scope for your information security management system (ISMS), with roles and objectives.
- Core working documents and routines for tracking risks, actions and evidence.
- An implementation plan and team handover, showing what remains to be put in place.
- 03
Statement of Applicability Workshop
You need to explain which security controls apply and why.
What changesClear control decisions you can explain, linked to your business risks and requirements.
What we deliverAsk about this service: Statement of Applicability Workshop- Preparation using your security management scope, risk findings and relevant requirements.
- A working session to review the controls needed and their implementation status.
- A draft or updated Statement of Applicability, with reasons for control decisions and open actions.
- 04
Audit Preparation Sprint
An audit is approaching, and preparation is competing with everyday work.
What changesAn organized audit pack and agreed preparation work completed, with outstanding gaps made clear.
What we deliverView service: Audit Preparation Sprint- A preparation checklist for the agreed audit scope and requested evidence.
- Organization of records and completion of agreed policy, process and evidence-preparation tasks.
- A walkthrough of the evidence with your team, plus outstanding actions and next steps.
- 05
Compliance Evidence Review
You have security records, but aren't sure they support what customers or auditors are asking.
What changesA clearer view of what your evidence supports and what still needs attention.
What we deliverAsk about this service: Compliance Evidence Review- A review of selected records against the agreed customer or audit requirements.
- An evidence map linking records to requirements and identifying gaps or inconsistencies.
- A prioritized list of missing evidence and the work needed to address it.
- 06
Security Policy Pack
Your policies are missing, outdated or describe a way of working your team doesn't follow.
What changesClear security policies that fit your business and can be put into practice.
What we deliverAsk about this service: Security Policy Pack- Tailored policy and procedure drafts based on your business, requirements and agreed ways of working.
- Review with the people responsible, with any working practices that need to change identified.
- Final drafts for approval, with assigned owners and a process for keeping them current.
- 07
Management Review Preparation
A management review is due, but the evidence, progress updates and decisions are scattered.
What changesA clearer basis for leadership decisions about security priorities and improvements.
What we deliverAsk about this service: Management Review Preparation- An agenda and input pack for the agreed management review.
- A summary of security performance, risks, findings and progress on previous actions.
- A format for recording decisions, responsibilities and follow-up actions.
Know what to expect before we start.
We agree scope, pricing and timing before work begins, then take responsibility for the agreed work and keep you informed.
The agreed assessment, preparation or implementation work, with clear findings, usable documents and next steps.
Your priorities, access to relevant information and people, and approval of decisions and policies that affect the business.
What do you need
taken care of?
An informal 30-minute call to discuss your needs and see how we could work together.