Articles
My articles across various subject – all for you to review.
-
ISO 27001 Asset Register: How to Build One
Learn how to build an ISO 27001 asset register that satisfies Control 5.9, keeps auditors happy, and is actually useful for managing your information assets.
The asset register is one of those ISO 27001 requirements that sounds straightforward but often catches organisations out in the audit. Either it’s too high-level to be useful, or it’s so granular that it becomes impossible to maintain. Virtually everyone assumes it’s just about tracking laptops, desktops, phones, etc. It’s more than that. It includes … Read more
-
How to Write an Information Security Policy (ISO 27001)
Learn how to write an information security policy under ISO 27001 – What it must contain, what auditors look for, and how to make it work for your organisation.
An information security policy is a foundational document of your ISO 27001 Information Security Management System (ISMS), or any serious approach to security in a business. It lays out your stall and tells everyone what the organisation’s expectations are regarding security, pointing to sub-policies where necessary. It’s the first thing most auditors will ask to … Read more
-
ISO 27001 for Small Businesses: A Practical Guide
This guide explains how ISO 27001 for small businesses can make sense and how to implement and certify without a big budget or a dedicated compliance team.
ISO 27001 has a reputation for being complicated, expensive, and built for large organisations. That reputation isn’t entirely fair — but it has kept many small businesses from pursuing certifications they genuinely need. This ISO 27001 for small businesses guide cuts through the noise of larger enterprises and explains what ISO 27001 actually looks like … Read more
-
How Long Does ISO 27001 Take?
How long does ISO 27001 take? I explore a realistic timeline for ISO 27001 from kick-off to certified and what speeds the process up and what slows it down.
“How long does ISO 27001 take and how much” is often the first email I get from someone enquiring about ISO 27001. I can understand that, but asking how long ISO 27001 takes is a bit like asking how long it takes to refit a bathroom. The answer will depend on all sorts of things. … Read more
-
ISO 27001 for Startups: What You Need to Know
How we target ISO 27001 can differ between different types of businesses, and where you are on that journey. Learn how I approach ISO 27001 for startups.
Introduction You’re within touching distance of landing your first serious enterprise prospect. The sales call went well… but, then the security questionnaire arrives — and somewhere near the top is a question you’ve been dreading: “Are you ISO 27001 certified?” For most startups, this is the moment ISO 27001 stops being abstract and becomes urgent. … Read more
-
What Happens If You Fail an ISO 27001 Stage 2 Audit?
Failing an ISO 27001 Stage 2 audit doesn’t mean the end of your certification journey. Here’s what actually happens — and how to avoid being in that position.
The short answer is: it’s not the end-of-the-world event you probably fear. But it might be annoying, potentially expensive, time-consuming, and entirely avoidable with the right preparation. Here’s what actually happens when a Stage 2 audit doesn’t go to plan — and what I’ve seen first-hand when an organisation pushes into audit before they’re ready. … Read more
-
The ICO Fined Capita £14 Million. Here’s What It Means for Smaller Businesses.
In October 2025, Capita received the ICO’s largest ever fine — and ISO 27001 was specifically mentioned in the findings. Here’s what UK SMEs should take from it
In October 2025, outsourcing giant Capita received the largest fine in the Information Commissioner’s Office (ICO) history — £14 million — following a ransomware attack in 2023 that exposed the personal data of 6.6 million people. It’s easy to read a headline like that and assume it has nothing to do with your business. My … Read more
-
Stuck at 60%: Why Your ISO 27001 Project Stalled – And How to Get Moving Again
It’s common to see an ISO 27001 project stalled at 60% – Learn how to deal with stolen attention, lost owners, fuzzy scope and perfectionism stopping it.
ISO 27001 isIf you feel like your ISO 27001 project stalled – It’s mostly done but never quite gets over the line, you’re in very good company. I regularly hear some variation of: “We’re about 60–80% there… we’ve written a lot of documents, done some risk work, but we just haven’t finished it off.” Let’s … Read more
-
Mastering ITIL Practices: A Comprehensive Guide to Streamlining IT Services
Learn about mastering itil practices in the context of ITIL 4, with clear explanations, everyday examples and tips you can use with a real IT team.
Streamlining IT services requires a solid grasp of ITIL practices within the IT Service Management framework. Struggling with service disruptions, slow response times, and user dissatisfaction? You’re not alone. The inability to efficiently manage IT services can spell disaster for your career and your organisation. The key to overcoming these challenges lies in mastering ITIL … Read more
-
Exploring ITIL Best Practices
Learn about exploring itil best practices in the context of ITIL 4, with clear explanations, everyday examples and tips you can use with a real IT team.
Introduction to ITIL Best Practices Establishing ITIL best practices is crucial within IT service management to achieve operational excellence and deliver outstanding value to customers and stakeholders. ITIL, or the Information Technology Infrastructure Library, has long been revered for its comprehensive framework that guides organisations in efficiently managing and delivering IT services. The latest evolution, … Read more