Behind the Scenes of an ISO 27001 Certification Project
Updated: Sep 2
Real engagements often teach more than general advice, so from time to time we share anonymised lessons from work we've done with accountancy and professional services firms — what went well, what was harder than expected, and what we'd tell another firm facing the same situation.
What tends to surprise firms
Almost every engagement, whether a Cyber Essentials Plus audit or an ISO 27001 gap analysis, surfaces at least one issue the firm didn't know it had — an old account that was never disabled, a backup that hadn't actually been tested, a supplier relationship no one had reviewed in years. These aren't signs of a poorly run firm; they're simply what surfaces once someone looks properly.
What made the difference
In the engagements that went smoothly, partner-level buy-in early on made a consistent difference — security work that has visible leadership support moves faster and sticks better than work treated as a purely IT project.
If you'd like to talk through a similar situation at your own firm, we're happy to have that conversation.

Comments