I'm a PECB-certified ISO/IEC 27001 Lead Implementer and I led Propel Finance, an FCA-regulated fintech, to ISO 27001 certification in October 2023, owning the ISMS scope, control set, internal audit and management review end to end.
I know what auditors look for, and I know how to build an information security management system that the business actually runs rather than a binder of policies nobody reads.
How I help
- Gap analysis against ISO/IEC 27001:2022 and Annex A
- Defining ISMS scope, context and interested parties
- Risk assessment methodology, risk register and Statement of Applicability
- Writing proportionate policies, procedures and control evidence
- Internal audit, management review and corrective-action tracking
- Preparing your team for Stage 1 and Stage 2 certification audits
- Mapping controls across NIST CSF 2.0, Cyber Essentials and PCI DSS so evidence is collected once
Who it's for
Scale-ups and SMEs that need certification to win enterprise or financial-services contracts, and organisations that already hold the certificate but want an ISMS that survives contact with real engineering teams.
What you get
- A clear roadmap to certification with realistic timelines
- A risk-based control set sized to your business
- Audit-ready evidence with named owners
- Hands-on support through the external audit