Articles
My articles across various subject – all for you to review.
-
How to Create an ISO 27001 Supplier Review Process
My guide on how to create an ISO 27001 supplier review process. What you need to do and how frequently.
Supply chain attacks have become one of the most significant threats to organisational security. You don’t have to look far for examples; The SolarWinds compromise affected thousands of organisations through a single trusted software supplier. The MOVEit breach exposed data at hundreds of companies via a file transfer tool that many had not even classified … Read more
-
ISO 27001 Nonconformity and Corrective Action Guide
Learn how to handle an ISO 27001 nonconformity and corrective actions. My guide steps you through how they work and what to do.
An ISO 27001 nonconformity is not a failure of your organisation. It is a finding — a gap between what your ISMS says it does and what it actually does, or between what ISO 27001 requires and what you have in place. Every organisation that goes through a certification audit encounters them. The question is … Read more
-
ISO 27001 Continual Improvement: Making It Real
Learn how to implement ISO 27001 continual improvement, per clause 10 of the standard with my guide and tools.
Most organisations treat continual improvement as the part of ISO 27001 that comes after the real work is done. You get certified, log a few corrective actions, note “continual improvement” in your management review, and move on. The result is an ISMS that stays static, or even rolls backwards. Policies written at implementation sit unchanged … Read more
-
ISO 27001 Myths Busted: 10 Things People Get Wrong
ISO 27001 is widely misunderstood — too big, too expensive, too IT-focused. We bust 10 of the most persistent myths with facts, figures, and plain English.
ISO 27001 has a mythology problem. Over the years a set of persistent misconceptions have taken hold — that it’s only for large enterprises, that it’s a purely technical exercise, that it takes years and costs a fortune, and that once you’ve got the certificate you can forget about it. Most of these myths have … Read more
-
What Do ISO 27001 Auditors Actually Look For?
ISO 27001 auditors go well beyond checking your policy documents. Here’s what experienced ISO 27001 auditors actually look for.
There’s a common misconception about ISO 27001 audits: that if your documentation is in order, you’ll pass. Documentation matters…. but experienced auditors know that documentation is the easiest part to get right. What separates organisations that sail through their audit from those that collect nonconformities is whether the ISMS is actually operating — not just … Read more
-
ISO 27001 ROI: How to Measure the Value of Certification
ISO 27001 is an investment, but what do you actually get back? This guide explains how to measure the ISO 27001 ROI for certification.
The question comes up at your board presentation: “What do we actually get for this investment?” It’s a reasonable question. ISO 27001 certification isn’t cheap. A consultancy programme, a certification body, annual surveillance audits, and the internal time of everyone involved adds up. For small and medium-sized organisations, the total investment — including internal time … Read more
-
ISO 27001 and AI: What Organisations Need to Consider
AI tools like ChatGPT and Microsoft Copilot create new information security risks. Here’s how ISO 27001 and AI relate — and what you need to document.
Generative AI tools have moved from novelty to mainstream workplace tool in an astonishingly short time. ChatGPT, Microsoft Copilot, Google Gemini, and dozens of specialist AI tools are now in regular use across organisations of all sizes — often with little formal governance around how they’re used or what data is being shared with them. … Read more
-
ISO 27001 vs GDPR: How They Relate
ISO 27001 and GDPR are often mentioned together, but they’re very different things. This guide explains how they relate, where they overlap, and requirements.
ISO 27001 and GDPR are two of the most frequently mentioned compliance frameworks in the UK — and they’re often confused with one another, or assumed to be interchangeable. They’re not. This guide explains what each one is, how they differ, where they overlap, and what the practical implications are for organisations that need to … Read more
-
ISO 27001 Password Policy: How to Write One
Learn what an ISO 27001 password policy must contain, what auditors look for, and how to write one that works in practice — not just on paper.
The password policy is one of the most practically important documents in your ISMS — and one of the most commonly done poorly. Either it sets unrealistic requirements that no one follows, or it’s so vague it provides no real guidance. This guide explains what ISO 27001 requires for password management, how to write a … Read more
-
ISO 27001 for Law Firms: What You Need to Know
Law firms hold some of the most sensitive data imaginable. This guide explains how ISO 27001 applies to legal practices, what clients expect, and how to get certified.
Law firms occupy a uniquely sensitive position in the information security landscape. You hold client matter files, commercially sensitive documents, personal data, financial information, and in some cases material covered by legal professional privilege — all of which are of significant value to cybercriminals, competitors, and hostile state actors. The legal sector has also seen … Read more