Define the ISMS
We agree the scope, business context, stakeholders, information and accountable owners before writing documents.
Information security management
ISO/IEC 27001 is not simply a folder of security policies. It requires an information security management system that connects business context, risk, leadership, controls, evidence and continual improvement. We help turn that structure into a working programme your team can operate and explain.
How we can help
Build and prepare an ISO/IEC 27001 information security management system with practical gap analysis, risk treatment, documentation and audit readiness support.
More than paperwork
Strong ISO 27001 preparation begins with the organisation's services, obligations, information, suppliers and risk appetite. Policies then support those realities rather than existing as generic documents that nobody uses.
We connect governance and technical delivery so that decisions in the risk register, Statement of Applicability and policies can be demonstrated in Microsoft 365, endpoints, networks, backups, supplier management and day-to-day working practices.
Audit preparation
Auditors will expect the scope, risks, selected controls and operating evidence to agree. We help organise records, identify contradictions and close practical gaps before they become findings under time pressure.
Preparation can include internal audit support, management review inputs, corrective actions and rehearsal of how responsible people explain their part of the ISMS.
Build progressively
Cyber Essentials can provide useful evidence across access, secure configuration, updates, firewalls and malware protection. ISO 27001 is broader: it adds governance, risk management, business context, suppliers, people, continuity and continual improvement.
Where both are planned, we can sequence the work so the technical baseline supports the wider ISMS rather than being repeated as a separate project.
Simple process
We agree the scope, business context, stakeholders, information and accountable owners before writing documents.
Risks are assessed consistently, controls are selected for a reason and practical remediation is assigned and tracked.
The ISMS is exercised through objectives, evidence, internal review and corrective action before independent certification audit.
Independent decisions stay independent
Wrexham Tech Support provides implementation and readiness support. ISO/IEC 27001 certification is awarded only after a successful independent audit by a certification body; choose an appropriately accredited body for your needs.
Read the official ISO/IEC 27001 overviewConnected assurance
Use the framework that fits the requirement, then reuse compatible controls and evidence without confusing one standard for another.
Practical readiness support for Cyber Essentials, ISO 27001, Defence Cyber Certification, DSPT, PCI DSS and the NCSC Cyber Assessment Framework.
View readiness support Certification supportPrepare confidently for Cyber Essentials and Cyber Essentials Plus with practical gap analysis, remediation and evidence support.
View readiness support UK defence supply chainPrepare for Defence Cyber Certification and Cyber Security Model v4 requirements with scope, control, SAQ, improvement-plan and evidence support.
View readiness support Essential services & resilienceAssess and improve cyber resilience against the NCSC Cyber Assessment Framework with outcome mapping, evidence review and prioritised remediation support.
View readiness supportCommon questions
Still unsure? A quick message is enough—we will point you in the right direction.
No. We help design, implement and prepare your ISMS. Certification is a separate independent decision made by your chosen certification body.
It depends on scope, size, current maturity and the amount of evidence already operating. A focused organisation with good existing controls may move quickly; a larger or less documented environment normally needs a staged programme.
Yes. We can test whether the policies match the actual environment, map them to risks and controls, identify missing records and retain useful work rather than replacing it unnecessarily.
Yes. We can prepare the organisation, coordinate evidence and help address findings while keeping the independent auditor's role separate.
Ready when you are