I help small companies get ISO 27001 certified. Without the bloat, the jargon, or the six-figure invoice.
I’m Alan. Iseo Blue is just me, and that’s the point. Thirty years in IT governance, the last decade specialising in ISO 27001, and a stubborn belief that small businesses deserve to be certified without paying enterprise prices for an enterprise headache.
⊙ Based in Berkshire, UK ⊙ Clients in the UK, EU, US & Australia
⊙ Dozens of UKAS-accredited certifications
Alan Parker, ISO 27001 Consultant
30+ years in IT governance, ISMS & project delivery
THE FRUSTRATION
Why I started Iseo Blue
For most of my career, I sat inside organisations watching how information security was actually done, and how it was sold. The pattern that bothered me most was simple: small companies were being charged enterprise prices for an enterprise problem they didn’t have.
A 25-person SaaS company lands an enterprise customer. Procurement asks for ISO 27001. Within a fortnight, someone has sold them an £80,000 engagement, a 400-page system of shelfware, and a year-long project run by people who have never had to do their own payroll.
None of that helps a small business get certified. It just helps the consultancy bill more hours. The certificate is the same certificate. The audit is the same audit. The only thing that scales with company size is the cost of the people standing between you and your certificate.
Iseo Blue exists because I think there is a much smaller, much more honest version of this job, and small companies deserve it.
WHAT YOU USUALLY GET
A complex ISMS framework forced onto your business
A 200-slide kickoff deck and a steering committee
A junior consultant working from a checklist
£40k+ in fees, billed by the hour, scope creeping
A black box you can’t maintain after they leave
WHAT YOU GET WITH ME
An ISMS sized and shaped to fit your actual business
A plain-English plan you can understand in one sitting
One person (me) from the first call to your certificate
A fixed fee, agreed up front, with no surprise extras
You own it. You can keep it running after I’m gone.
THE APPROACH
Minimal Viable Compliance
I call my way of working Minimal Viable Compliance. It is the smallest, cleanest, most defensible ISMS that gets you certified, fits how you actually work, and keeps running once I’m out of the picture. Everything I do flows from that one idea.
“The certificate is the same certificate, whether you spend £3,000 or £30,000. The question is how much pain and how much process you carry forward with you.”
01
Right-sized, not enterprise-sized
If you’re a 30-person startup, you don’t need a control set built for a bank. I scope your ISMS to your actual business, risks, and headcount. Nothing for show. Nothing for the consultancy’s portfolio.
02
Plain English, throughout
You’ll never see me ship a document you can’t read. SoA, Annex A, control owners, residual risk: I’ll introduce the jargon as we go, in words you’ll recognise. If a policy reads as if it were written for an auditor rather than your team, it’s the wrong policy.
03
You own it. I’m here to coach.
This is the bit big consultancies hate. I’m not building you a black box to lock you into year upon year of fees. You and your team will own the ISMS by the time we’re done. I show you how it works, you sign off on every decision, and on the day I leave, you can keep going on your own.
THE APPROACH
What working with me actually looks like
A typical engagement runs three to six months for a company of ten to a hundred people. Here is what we’ll actually do together, step by step.
1. Discovery call
30 min – Free
We have a free, no-pressure 30-minute chat. You tell me where you are, why you need ISO 27001, and what’s already in place. I tell you, honestly, whether I can help, what it will take, and roughly what it’ll cost. If we’re not a fit, I’ll say so and point you elsewhere.
2. Scope & Plan
Week 1 to 2
I learn your business properly. How you work, who does what, what tools you use, where the data sits, who your customers are. Then we agree on a scope that matches reality and a plan you can actually deliver alongside your day job.
3. Build the ISMS together
Weeks 3 to 10
Over a series of sessions, we go through it together, step by step. By the end of this phase, you’ll know every policy, every control, and why each one is there. No “because the consultant said so”.
4. Internal audit
Weeks 11 to 12
We run an internal audit (a requirement of ISO 27001). I find the gaps before the auditor does. We close them. By the time the real audit comes round, your team will know exactly what’s going to be asked and have the evidence ready.
5. Certification audit
Audit Day
You are now ready for your ISO 27001 audit. I can help you select the right type of auditor and save you high costs and headaches.
IS THIS A FIT?
Who I work with, and who I don’t
I’d rather tell you straight up than waste an hour of your time on a discovery call. If you recognise yourself on the left, we’ll get on. If you recognise yourself on the right, I’m probably not your person, and that’s fine.
This is for you if
The kind of company I help certify, week in, week out.
✓ You’re a 10 to 250-person company, and you need ISO 27001 to win or keep an enterprise contract.
✓ You’re the founder, IT lead, or ops director, and you want to actually understand your ISMS, not just be handed one.
✓ You’re a tech, SaaS, professional services firm, agency, or anything with a sensible scope.
✓ You’d rather a weekly 30-minute call than a quarterly steering committee.
✓ You want the certificate, but you also want to come out the other side a more grown-up business.
This isn’t for you if
Said plainly so neither of us wastes a discovery call.
× You’re a large enterprise with an internal compliance team. You don’t need me; you need a contractor.
× You want a paid stamp without doing any of the work. ISO 27001 isn’t sold that way, and I can’t help you fake it.
× You prefer 200-slide kickoff decks to a shared Google doc and a weekly call.
× You’re looking for a “we’ll run your ISMS forever” arrangement. There are firms that do that. I can introduce you. It isn’t me. Just drop me an email
IN THEIR WORDS
What it’s like, from the people who’ve done it
The quotes that mean the most to me aren’t about the certificate. They’re about the experience of working together: down-to-earth, right-sized, no fluff.
“
Alan was a great, down-to-earth, no-nonsense help in achieving our UKAS-accredited ISO 27001 certification. He kept pace at each stage, without any extra guff.
Bryn
Periculum Security Group · UK
“
Alan’s expertise allowed us to successfully implement ISO 27001 in a right-sized and efficient manner for our start-up.
Erica Burns
Oxipital AI · USA
“
We sailed through our assessment. Highly recommend!
Jenna Cooper,
Helpthemove
“
Alan’s expertise was central to guiding our company to achieve ISO 27001 certification
Julian Longson,
Pole Star Global
“
We highly recommend Alan for his excellent support and expertise. He demonstrated great ability to answer our questions with clarity and provided thorough guidance throughout the entire process.
René Berg Jensen,
Phoenix Design Aid, Spain
OFF THE CLOCK
Three things that aren’t on my CV
MY DOG
My dog is a working cocker spaniel and the strangest creature on the planet. He’s my best friend, and I will tell you about him if you give me any encouragement at all.
BERKSHIRE
I live in Berkshire, UK with my family. If you’re nearby and want to do a kickoff in person rather than on Teams, I’m in.
THE REASON FOR ALL OF THIS
A wife I love very much and two boys who amaze me every day, often in ways I didn’t ask for. They’re the reason I quit the corporate ladder and the reason Iseo Blue is one person. I work to live; I don’t live to work.
Right, shall we have a proper chat?
Thirty minutes. No hard sell. Tell me where you are with ISO 27001, and I’ll tell you, honestly, whether I can help, what it would take, and what it would cost.
Or, before we talk, check out the following;
→ 14 free ISO 27001 templates (5,000+ downloads)