Turn scattered security work into a practical routine.
We set up the foundations of your information security management system (ISMS), building on existing practices with clear records, responsibilities and review routines. You get a usable starting structure and a plan for the remaining work.
When it helps
When useful security work is happening, but the records, decisions and follow-up are difficult to keep together.
Security work is spread across people and tools
Access checks, risk decisions and improvements happen in different places. It takes time to work out what is covered and what still needs attention.
- Agree the part of your business the starting system will cover.
- Connect existing practices to shared records and clear responsibilities.
- Set up a practical way to track actions and review progress.
The documents don't match how your team works
You have policies or templates, but they describe processes the team does not follow. Keeping them useful is harder than simply keeping them on file.
- Review the agreed documents against current working practices.
- Adapt the core materials to your business and team.
- Separate current arrangements from changes still awaiting approval or implementation.
Security actions keep getting lost in everyday work
Problems get discussed and improvements get agreed, but checking progress depends on someone remembering to ask.
- Bring the agreed risks and actions into working records.
- Identify who can make decisions and move each action forward.
- Define review dates and the records needed to track progress.
You know the direction. The setup keeps slipping.
You have a clear view of how security should be managed, but building the documents and routines keeps losing out to product and business priorities.
- Build on your priorities and the arrangements already in place.
- Prepare the agreed documents, records and review routines.
- Walk the relevant people through using and maintaining them.
Working foundations, with the next steps clear.
We agree which documents, records and routines to establish, based on your priorities and what is already in place. The handover makes clear what is ready to use and what still needs approval or implementation.
Setup around how your business works.
- An agreed starting scope, security objectives and responsibilities for the information security management system.
- Preparation or adaptation of the agreed core documents using existing practices and available information.
- Starter records for risks, control decisions, actions and evidence, populated from the material reviewed.
- Defined review routines, record maintenance and approval steps for the agreed scope.
- A team walkthrough and implementation plan covering remaining work and dependencies.
A starting system your team can work with.
- A documented starting scope, objectives and responsibilities, alongside the agreed core working documents.
- Starter registers and an evidence index, showing what is recorded, what is unconfirmed and what is still missing.
- Review and upkeep instructions, with proposed dates and named responsibilities agreed with your team.
- An implementation plan showing outstanding decisions, approvals and improvements in a practical order.
Completing and operating the wider security programme.
Any further work is optional and agreed separately.
- Implementing every identified security control or technical improvement.
- Ongoing management of the ISMS, recurring reviews or wider staff training.
- Independent internal audits or certification audits.
How it works
We handle the setup, bring focused questions to the relevant people and build on the practices that already work.
Agree the starting scope
We review your priorities and available materials, then agree the documents, records and routines to establish. We confirm the people involved, required inputs, price and timing before the setup begins.
Build the working foundations
We adapt useful existing material and prepare what is missing within the agreed scope. We populate the starter records from the information reviewed and make unanswered questions visible.
Review the arrangements together
We check the drafts with the relevant people, resolve practical questions and prepare them for the agreed approvals. We separate what reflects current practice from changes the team still needs to introduce.
Hand over a usable starting system
We walk the team through the materials and upkeep steps, then hand over the implementation plan. It shows remaining decisions and work, who is involved and what should happen next.
Need a practical structure for managing security?
An informal 30-minute call to discuss where you are with security management and whether this package fits.