Articles

My articles across various subject – all for you to review.


  • How to Choose an ISO 27001 Certification Body (UK Guide)

    Not all ISO 27001 certification bodies are equal. This guide explains UKAS-accredited and non-accredited bodies, how to shortlist, and what to ask.

    Choosing a certification body is one of the decisions that organisations leave until too late — and then rush. It matters more than people realise, both for the quality of the audit and for whether your certificate will be accepted by the customers you’re pursuing. This guide walks you through what to look for, the … Read more


  • How to Prepare for an ISO 27001 Stage 2 Audit

    How to prepare for an ISO 27001 Stage 2 audit; what evidence auditors examine, and how to make sure your team is ready on the day.

    The Stage 2 audit is the one that matters most. It’s the evidence-based assessment where your auditor moves beyond reviewing documents and starts looking at whether your ISMS is actually operating. Pass Stage 2 and you’re certified. Walk in unprepared and you risk major nonconformities that delay your certificate. This guide on hor to prepare … Read more


  • ISO 27001 Internal Audit Programme: How to Plan and Run It

    Here’s my guide on how to run an ISO 27001 internal audit programme – from an ISO consultant of dozens of projects.

    Introduction Most organisations know they need an internal audit. Far fewer know how to build a programme that satisfies the auditor, adds genuine value, and doesn’t consume weeks of calendar time each year. ISO 27001 Clause 9.2 requires you to conduct internal audits at planned intervals. But “planned intervals” is doing a lot of work … Read more


  • What is ISO 27001 2022? What Changed From 2013

    What is ISO 27001 2022 version? This guide explains what changed, what stayed the same, and what it means for organisations pursuing or maintaining certification.

    If you’ve been looking at ISO 27001 for a while, you may have noticed references to both “ISO 27001:2013” and “ISO 27001:2022.” These are two versions of the same standard — the 2022 edition is the current version, and it replaced the 2013 edition. This guide explains the key differences, what the update means for … Read more


  • Do I Need ISO 27001? How to Decide

    Asking yourself; Do I need ISO 27001? This guide walks you through the common triggers, who it’s really for, and how to make the decision objectively.

    I suspect many people out there are looking at standards and thinking: “Do I need ISO 27001?” The honest answer depends on your situation. ISO 27001 is not legally mandatory for most organisations — but it’s increasingly the de facto requirement for anyone selling to enterprise customers, public sector bodies, or organisations that take their … Read more


  • ISO 27001 vs PCI DSS: Which Do You Need?

    ISO 27001 vs PCI DSS — both relate to information security but they serve very different purposes. This guide helps you work out which one you need.

    ISO 27001 and PCI DSS are both security frameworks, and both can appear in customer questionnaires and compliance requirements. But they’re designed for very different purposes, they’re managed by different organisations, and compliance with one doesn’t automatically mean compliance with the other. This ISO 27001 vs PCI DSS guide explains what each one is, how … Read more


  • ISO 27001 Management Review: A Complete Guide

    Learn what an ISO 27001 management review is, who must attend, what it needs to cover, and how to run one that satisfies auditors.

    The management review is one of those ISO 27001 requirements that many organisations treat as a box-ticking exercise: a meeting that happens because the standard says it must, producing minutes that nobody reads. Shelfware. That’s a mistake. Not just because auditors can usually tell when a management review has been done properly versus written up … Read more


  • ISO 27001 for SaaS Companies: A Practical Guide

    ISO 27001 is increasingly a must-have for SaaS companies winning enterprise deals. This guide explains what it means in practice for software businesses.

    If you’re building a SaaS product and selling to enterprise customers, you’ve probably already been asked for ISO 27001. Or you know it’s coming. I certainly get a lot of small startups and SaaS companies approaching me for support in getting certified without overcomplicating things. This guide explains what ISO 27001 actually means for a … Read more


  • How to Prepare for an ISO 27001 Stage 1 Audit

    Learn what happens in an ISO 27001 Stage 1 audit, what the auditor is looking for, and how to be ready on the day so you can move confidently to Stage 2.

    If you go through an accredited certification process (for example, in the UK, a UKAS-certified body like BSI), you’ll undergo a two-stage audit for your ISO 27001 certification. The Stage 1 audit is the first (surprise!). It’s sometimes called the “documentary review” or the “readiness review” — and it’s the point at which your documentation … Read more


  • How to Complete an ISO 27001 Risk Assessment

    A practical, step-by-step guide to conducting an ISO 27001 risk assessment — covering methodology, scoring, and documentation that satisfies auditors.

    The risk assessment is the engine of your ISMS (Information Security Management System). It is the very heart of ISO 27001. Everything else (your controls, your Statement of Applicability, your risk treatment plan) flows from it. Get it right, and the rest of the implementation becomes much clearer. Get it wrong, and you’ll find yourself … Read more