Skip to content

Compliance readiness

ISO 27001 Readiness

ISO 27001 is the security standard enterprise buyers ask for by name. How much work it takes depends on your size and where your security stands today, so we scope the path to fit your company.

Book a discovery call

What ISO 27001 is

ISO 27001 is the international standard for managing information security. At its centre is an Information Security Management System, the ISMS. That is the collection of policies, decisions and everyday processes a company uses to keep its information safe, managed as one system.

The standard is built around risk. Rather than hand you a fixed technical checklist, it has you weigh the risks specific to your business and pick controls to match. Annex A is a reference catalogue of controls to draw on and check your selection against, and you record which ones apply and why.

An independent body, accredited to audit against the standard, reviews your ISMS and issues the certificate when it holds up. The certificate then follows a three-year cycle with checks along the way.

Why it is worth doing

Certification is a sales asset. It carries weight because the work behind it protects the business itself.

Protects your revenue

Security failures cost money and stall deals. A working information security programme protects the revenue and profitability that everything else depends on.

Keeps you serving customers

Your customers depend on you being there. The standard makes you plan for the disruptions that would otherwise take you offline, so a bad day does not become a lost customer.

Upholds your reputation

Trust is hard to win and easy to lose. Certification is proof to customers, partners and investors that you take the security of their data seriously.

Supports your legal and regulatory duties

The rules on how you handle data keep tightening. ISO 27001 gives you a structured way to track those duties and the controls behind them, so you can show customers and regulators you take them seriously.

Plan, Do, Check, Act

A system you keep running

Scoped to a company your size, ISO 27001 comes down to a set of decisions about who owns security, the risks that matter to you, and the controls that address them. The standard runs them as a continuous cycle, so once it is in place each round keeps your security current as the company grows.

P

Plan

Decide your scope, assess the risks that matter to you, and choose the controls that address them.

D

Do

Put those controls and your risk treatment into day-to-day operation.

C

Check

Monitor how it works, run an independent internal audit, and review it with management.

A

Act

Fix what the checks surface and keep improving, so the system stays current.

How we get you ready

The certification audit itself is run by an accredited body. Our job is to get you ready for it, and to leave you with a programme you can keep.

See where you stand

A gap analysis against the standard. What you already have, what is missing, and how far the gap goes.

A roadmap sized to you

A path to audit-readiness scoped to where you are. We rank what matters first, so the work keeps moving.

Build the programme

We help you put the policies, controls and evidence in place that an auditor expects, built to be used day to day.

What you walk away with

A clear view of where you stand, a roadmap to audit-readiness, and the policies, controls and evidence in place to back it. A management system your team actually runs, so certification is the result of how you work day to day.

If you would like us to stay on and keep the programme running as you grow, that is work we are happy to take on.

Not sure you are ready to aim at ISO 27001 yet? The Custos Secure Baseline gets your security to the level enterprise security reviews expect, and that baseline is the natural first step on the path to certification.

See the baseline

Ready to start on ISO 27001?

A 30-minute discovery call to see how far you are from audit-ready and what the path looks like for you.

Book a discovery call