Two senior consultants discussing an information security management system
ISO 27001 consultancy

Senior advisory for an ISMS that already exists.

For organisations with a certified or largely complete information security management system, we provide flexible, senior-level input — on retainer or ad hoc — for the decisions that come after certification, not before it.

Surveillance cycles supported
3
Response time
48hrs
Retainer days
2-6
Illustrative figures
The challenge

Certification is a point in time. Running an ISMS isn't.

Getting certified against ISO/IEC 27001:2022 is a defined project with a clear end point. Keeping the management system relevant for the following one, two or three years — through surveillance audits, business change and evolving customer expectations — is a different kind of work, and it rarely fits neatly into anyone's existing job description.

The person who led certification often moves on to other priorities once the certificate is issued, leaving the ISMS with a named owner who is stretched across IT, compliance and day-to-day operations. Management review meetings happen because the calendar says they should, not because they're driving real decisions.

Business change is constant and the ISMS has to keep up: a new office, a cloud migration, an acquisition, a new supplier handling customer data, a product line that changes the risk profile entirely. Each of these can shift the scope statement or the Statement of Applicability, and each one is easy to defer until a surveillance audit forces the question.

Risk decisions get harder as the business grows, not easier. Accepting a residual risk, choosing between two treatment options, or deciding how far to push back on a customer's security demands all benefit from an independent, experienced view — but that view isn't always available internally, and bringing in a full project team for a single decision is disproportionate.

Customer assurance work grows alongside the certificate rather than shrinking once it's achieved. Security questionnaires, due diligence calls and contract schedules referencing ISO 27001 land more frequently, and someone credible needs to own the responses without it becoming a full-time distraction from actually running the ISMS.

None of this needs a project. It needs a consistent, senior point of contact who already understands your ISMS and can be called on when a decision needs weighing up properly, without re-explaining your business from scratch every time.

  • Surveillance audits treated as a fire drill rather than routine business
  • Scope changes made informally and never reflected in the Statement of Applicability
  • Risk decisions deferred because no independent view is readily available
  • Customer due diligence responses drafted under time pressure with no consistent owner
Our approach

A consistent senior consultant, engaged the way your business actually works.

We agree the shape of the engagement to suit you — a monthly retainer of a set number of days, a quarterly check-in tied to management review, or purely ad hoc support billed for the time used. There's no fixed project plan because the work itself doesn't arrive on a fixed schedule.

You get a named senior consultant, not a rotating pool. They learn your business, your risk appetite and your ISMS documentation once, and stay involved so every subsequent conversation builds on the last rather than starting from a briefing document.

Ahead of each surveillance audit we review what's changed since the last visit or certification — scope, risk register, incidents, corrective actions — and run a short internal check so any drift from the Statement of Applicability is caught and corrected before your certification body finds it.

When a scope change comes up, we assess the impact properly: what it does to your risk profile, whether it needs notifying to your certification body, and what documentation needs updating, rather than letting it sit as an informal decision that only surfaces at the next audit.

For contentious or high-stakes risk decisions, we provide a written, evidenced view of the options and their consequences, so the decision-maker — often a board or senior leadership team — has something concrete to work from and a record of why the decision was made.

We attend management review where it adds value, report on ISMS performance in terms a board will actually engage with, and step back where an internal team is capable of running things day to day. The point of this service is competent independent input, not dependency.

  • Named senior consultant retained for continuity across the relationship
  • Surveillance audit readiness reviews ahead of each certification body visit
  • Scope and Statement of Applicability updates when the business changes
  • Board-level reporting on ISMS performance and risk, in plain language
What's included

Everything in the engagement, set out up front.

Engagements are scoped to what you need — from a light-touch retainer to intensive support around a particular audit or business change — with clear reporting throughout.

Surveillance audit preparation

Readiness reviews ahead of your certification body's annual visits, closing gaps before they're raised as findings.

Scope and SoA maintenance

Assessment and documentation of the impact when your business, technology or supplier base changes.

Risk decision support

Independent, evidenced input on contentious or high-consequence risk treatment decisions.

Customer assurance

Review and drafting support for security questionnaires, due diligence and contract security schedules.

Management review and reporting

Attendance and input at management review, with ISMS performance reported in board-appropriate language.

Continual improvement

Ongoing recommendations against clause 10 requirements, informed by internal audit and incident data.

Deliverables

What you receive.

  • Agreed engagement structure and reporting cadence
  • Surveillance audit readiness reports
  • Updated Statement of Applicability following scope changes
  • Risk decision briefings with documented options
  • Customer questionnaire and due diligence response support
  • Management review input and minutes contribution
  • Quarterly or ad hoc ISMS health summary
  • Direct access to a named senior consultant
Who it suits

Built for organisations that need the work done properly.

Recently certified organisations

The ISMS is certified but the internal team is new to running it day to day and wants experienced backup.

Businesses without a full-time security lead

A virtual CISO style arrangement gives board-level input without carrying a full-time senior hire.

Organisations facing frequent scope change

Growth, acquisition or new products mean the ISMS needs regular reassessment rather than a one-off review.

Teams under customer assurance pressure

Security questionnaires and due diligence requests have grown beyond what internal capacity can absorb calmly.

Outcomes & benefits

What changes once the work is done.

The value shows up as fewer surprises at audit and faster, better-evidenced decisions the rest of the year.

Clean surveillance audits

Certification bodies find a management system that's been kept current, not one refreshed the week before their visit.

An ISMS that reflects the business

Scope and the Statement of Applicability stay aligned to what the organisation actually does.

Faster, better risk decisions

Senior input available when a decision needs weighing up, rather than deferred until it becomes urgent.

Credible customer responses

Security questionnaires and due diligence packs answered consistently and defensibly.

Board confidence

Leadership sees ISMS performance reported clearly, in terms that support real governance decisions.

No dependency

Internal teams retain ownership of the ISMS; we add capability where it's genuinely needed.

We don't manufacture ongoing work to justify a retainer.

This is a service built around genuine need rather than a fixed monthly fee for its own sake. If a quarter is quiet because the ISMS is stable and nothing material has changed, we say so, and the engagement reflects that. Retainers can flex down as well as up, and ad hoc arrangements exist for exactly this reason.

We're not a certification body and we don't sit on the other side of your audit. Our role is to make sure the ISMS is in good order before your certification body arrives, and to help you interpret and act on findings afterwards — the certification decision itself always rests with the accredited body carrying out your audits.

Where a client's needs grow beyond advisory input — a significant rebuild of the risk framework, a new certification scope, or a return to something closer to full implementation work — we say so plainly and scope it as a separate piece of work, rather than stretching a retainer to cover it badly.

Consultants are UK-based and senior, with time spent on-site where it adds value across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, and the rest handled remotely. You keep the same person across the relationship, which matters when the conversation is about risk your organisation actually carries.

Frequently asked questions

Questions we are asked most often.

Is this the same as your ISO 27001 implementation support?

No. Implementation support is a defined project to build an ISMS from scratch through to certification readiness. Consultancy is an ongoing, flexible advisory arrangement for organisations that already have a certified or largely complete ISMS and need senior input on demand rather than a fixed project team.

Do you work on a retainer or ad hoc basis?

Both. Some clients retain a fixed number of days a month for ongoing advisory input, management review attendance and surveillance audit preparation. Others call on us for specific decisions — a scope change, a supplier risk question, a new business line — and pay only for the time used.

Can you help us prepare for a surveillance audit?

Yes, this is one of the most common reasons clients engage us. We review changes made since certification or the last surveillance visit, check the risk register and Statement of Applicability are still current, and run a short readiness session so nothing in the audit comes as a surprise.

We already have an ISMS manager — how does this fit alongside them?

We work alongside your internal owner, not instead of them. Most engagements provide senior second-opinion input on risk decisions, scope changes and control design, plus capacity for peaks in workload such as a customer due diligence exercise or a new certification scope. Your team keeps ownership of the ISMS day to day.

Can you act as a virtual CISO for information security governance?

Yes. Where an organisation needs board-level information security input without a full-time hire, we provide a consistent senior consultant who attends management review, reports risk in language the board understands, and makes recommendations grounded in your actual risk appetite rather than generic best practice.

How do you handle customer security questionnaires and due diligence requests?

We review incoming questionnaires and due diligence packs, draft or check responses against your certified ISMS and current control evidence, and flag anywhere a customer's expectations exceed what's currently in scope so you can make an informed commercial decision before responding.

What happens if a risk decision is contentious internally?

We provide an independent, evidenced view — what the risk actually is, the realistic options and the likely audit or commercial consequence of each. The decision remains yours; our role is to make sure it's made with clear information rather than the loudest voice in the room, and that it's documented properly.

Do you get involved if our ISMS scope needs to change?

Yes, scope changes — a new office, an acquisition, a new product line, a change of cloud provider — are a regular reason clients call us. We assess the impact on your Statement of Applicability and risk register, update the documentation, and liaise with your certification body where a scope change needs to be notified.

Need a senior second opinion on your ISMS?

Tell us where you are — recently certified, mid-surveillance-cycle, or facing a scope change — and we'll suggest an engagement shape that fits.

Talk to a consultant