Articles

My articles across various subject – all for you to review.


  • How to Conduct an ISO 27001 Management Review (Template Included)

    My guide on how to conduct an ISO 27001 Management Review of your ISMS. Included agenda template

    The management review is one of those ISMS activities that organisations often get wrong in one of two ways. Either it becomes a formality — a brief meeting where management nods along while the ISMS lead presents a slide deck, then signs the minutes — or it becomes an unwieldy marathon that nobody wants to … Read more


  • ISMS Document Control: How to Manage It Properly

    How to manage your ISMS documentation. Read my guide on how to implement ISO 27001 document control and meet the requirements of the standard.

    Document control is one of those requirements that organisations either over-engineer into a bureaucratic nightmare or under-deliver on to the point where an auditor cannot find what they need. Both failure modes are common. The right approach sits between them: a consistent, proportionate system that keeps your ISMS documentation accurate, accessible, and trustworthy — without … Read more


  • ISO 27001 Penetration Testing: What the Standard Actually Requires

    Learn what the standard really requires around ISO 27001 and penetration testing

    Penetration testing is one of the most widely misunderstood requirements in ISO 27001. Consultants frequently tell clients they need annual pen tests to achieve certification. Organisations buy pen tests as an ISO 27001 checkbox exercise. And the common assumption — that pen testing is a mandatory requirement of the standard — is repeated frequently enough … Read more


  • How to Write an ISO 27001 ISMS Scope Statement (With Examples)

    How to write your ISO 27001 scope statement for your ISMS with examples of what works and what doesn’t

    The ISMS scope statement is one of the first documents you need to produce when implementing ISO 27001 — and one of the most consequential. Get it right and your certification effort stays focused and proportionate. Get it wrong and you either spend the next year trying to certify things that did not need to … Read more


  • ISO 27001 Risk Treatment Options: Accept, Mitigate, Transfer, Avoid

    How to handle risk treatment under ISO 27001 clause 6. Common options and the key aspects of a risk treatment plan.

    Risk assessment tells you what your risks are. Risk treatment is what you decide to do about them. For many organisations going through ISO 27001 implementation, the assessment itself gets the most attention — identifying assets, threats, vulnerabilities, and likelihood ratings. But the treatment decisions are where the real work happens, and where auditors spend … Read more


  • ISO 27001 Surveillance Audits: What to Expect

    What happens after certification? The ISO 27001 surveillance audit in years 1 and 2, and the recertification audit in year 3 process explained.

    Getting ISO 27001 certified is the milestone most organisations focus on. What comes after it — the ongoing audit cycle that keeps the certificate valid — is less well understood, and the gap in preparation often shows. Certification is issued for three years. During that period, your certification body conducts surveillance audits — typically in … Read more


  • How to Handle a Data Breach Under ISO 27001

    How to create an ISO 27001 Data Breach Procedure in order to handle incidents within the scope of your ISMS

    A data breach does not announce itself. It might surface as an unusual login alert at 11pm, a supplier calling to say they have received a strange email from your domain, a member of staff reporting that they sent a client file to the wrong person, or a ransomware notification on a Monday morning. In … Read more


  • ISO 27001 Training and Awareness: Building Your Programme

    Most ISO 27001 training programmes are built to satisfy an auditor, not to change behaviour. Staff complete an annual e-learning module, click through the acknowledgement, and forget 80% of it within a week. The organisation ticks the box, the auditor sees a completion record, and twelve months later the phishing simulation results look exactly the … Read more


  • How to Create an ISO 27001 Supplier Review Process

    My guide on how to create an ISO 27001 supplier review process. What you need to do and how frequently.

    Supply chain attacks have become one of the most significant threats to organisational security. You don’t have to look far for examples; The SolarWinds compromise affected thousands of organisations through a single trusted software supplier. The MOVEit breach exposed data at hundreds of companies via a file transfer tool that many had not even classified … Read more


  • ISO 27001 Nonconformity and Corrective Action Guide

    Learn how to handle an ISO 27001 nonconformity and corrective actions. My guide steps you through how they work and what to do.

    An ISO 27001 nonconformity is not a failure of your organisation. It is a finding — a gap between what your ISMS says it does and what it actually does, or between what ISO 27001 requires and what you have in place. Every organisation that goes through a certification audit encounters them. The question is … Read more