Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Iseo Blue Limited: ISO 27001 Consultancy, Support & Training ## Sitemaps [XML Sitemap](https://iseoblue.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [ISO 27001 for Accountants and Financial Services Firms](https://iseoblue.com/post/iso-27001-for-accountants-and-financial-services-firms/): Financial services and accountancy firms face relentless pressure to protect sensitive client information, maintain regulatory compliance, and demonstrate robust information security. The Financial Conduct Authority, the Information Commissioner’s Office, and professional bodies including the ICAEW and ACCA have set high expectations for how firms must safeguard data. For many firms, ISO 27001 certification has become not merely a competitive advantage but an essential requirement to satisfy regulatory obligations, retain clients, and defend against the increasingly sophisticated threats targeting the financial services sector. - [ISO 27001 Recertification: What Happens After 3 Years](https://iseoblue.com/post/iso-27001-recertification-what-happens/): Achieving ISO 27001 certification is significant. Maintaining it is the longer game — and one that catches organisations off guard more often than the initial certification does. - [ISO 27001 Certification for SaaS Companies: Your Questions Answered](https://iseoblue.com/post/iso-27001-certification-for-saas-companies/): SaaS companies pursuing ISO 27001 certification tend to arrive at the process with a specific set of questions — some of which differ meaningfully from those asked by traditional enterprises. The nature of SaaS businesses creates particular scoping considerations, supplier dependencies, and commercial drivers that shape how certification works in practice. - [ISO 27001 Business Continuity Planning](https://iseoblue.com/post/iso-27001-business-continuity-planning/): Business continuity planning is one of the areas where organisations implementing ISO 27001 frequently ask the same question: is a full Business Continuity Plan required to achieve certification? The honest answer is that the standard requires specific, defined things — and a comprehensive BCP is not always one of them. What it does require is proportionate and often misunderstood. - [Can You Self-Certify for ISO 27001? (And Should You?)](https://iseoblue.com/post/can-you-self-certify-for-iso-27001/): The short answer is yes — you can self-declare conformity with ISO 27001 without engaging a certification body. - [How to Pass Your ISO 27001 Audit First Time](https://iseoblue.com/post/how-to-pass-your-iso-27001-audit-first-time/): Most organisations that fail their ISO 27001 audit — or receive more findings than expected — do not fail because they have poor security. They fail because of avoidable preparation mistakes: documentation that does not match practice, processes that exist on paper but not in operation, and gaps that a structured pre-audit review would have identified. - [ISO 27001 Audit Findings: How to Respond to Nonconformities](https://iseoblue.com/post/iso-27001-audit-findings-how-to-respond-to-nonconformities/): Receiving a nonconformity from your ISO 27001 auditor is not a crisis. It is a structured event with a defined process, a clear timeline, and a straightforward set of requirements. Most organisations that respond well to nonconformities achieve certification — or maintain it — without significant difficulty. Most organisations that struggle do so not because the findings are too serious, but because their corrective action process is poorly structured. - [ISO 27001 Certification Without a Consultant: Is It Possible?](https://iseoblue.com/post/iso-27001-certification-without-a-consultant/): The short answer is yes — many organisations achieve ISO 27001 certification without engaging an external consultant, and some of them do so efficiently. The longer answer is that whether you should depends on what you already have in-house, how much time your team can commit, and what you are willing to learn as you go. - [ISO 27001 Certification: UKAS vs Non-UKAS — Does It Matter?](https://iseoblue.com/post/iso-27001-certification-ukas-vs-non-ukas/): When you are choosing a certification body for ISO 27001, one of the first things you will encounter is the question of accreditation. Some certification bodies hold accreditation from UKAS — the United Kingdom Accreditation Service, or its equivalent in other countries. Others do not. The difference in cost can be significant. Whether the difference matters depends entirely on why you want the certificate. - [What Is a UKAS-Accredited ISO 27001 Certificate?](https://iseoblue.com/post/what-is-a-ukas-accredited-iso-27001-certificate/): A UKAS-accredited ISO 27001 certificate is one issued by a certification body that has itself been assessed and approved by the United Kingdom Accreditation Service. Understanding what that means — and why enterprise buyers increasingly specify it — is important for anyone evaluating a supplier’s security credentials or pursuing certification for commercial purposes. - [How to Conduct an ISO 27001 Management Review (Template Included)](https://iseoblue.com/post/how-to-conduct-an-iso-27001-management-review/): The management review is one of those ISMS activities that organisations often get wrong in one of two ways. Either it becomes a formality — a brief meeting where management nods along while the ISMS lead presents a slide deck, then signs the minutes — or it becomes an unwieldy marathon that nobody wants to attend. - [ISMS Document Control: How to Manage It Properly](https://iseoblue.com/post/iso-27001-document-control/): Document control is one of those requirements that organisations either over-engineer into a bureaucratic nightmare or under-deliver on to the point where an auditor cannot find what they need. Both failure modes are common. The right approach sits between them: a consistent, proportionate system that keeps your ISMS documentation accurate, accessible, and trustworthy — without drowning your ISMS lead in version numbers and approval workflows. - [ISO 27001 Penetration Testing: What the Standard Actually Requires](https://iseoblue.com/post/iso-27001-penetration-testing/): Penetration testing is one of the most widely misunderstood requirements in ISO 27001. Consultants frequently tell clients they need annual pen tests to achieve certification. Organisations buy pen tests as an ISO 27001 checkbox exercise. And the common assumption — that pen testing is a mandatory requirement of the standard — is repeated frequently enough that it has become accepted wisdom. - [How to Write an ISO 27001 ISMS Scope Statement (With Examples)](https://iseoblue.com/post/how-to-write-an-iso-27001-scope-statement/): The ISMS scope statement is one of the first documents you need to produce when implementing ISO 27001 — and one of the most consequential. Get it right and your certification effort stays focused and proportionate. Get it wrong and you either spend the next year trying to certify things that did not need to be certified, or you discover during your Stage 1 audit that key services and processes are not included and the scope needs to be rewritten. - [ISO 27001 Risk Treatment Options: Accept, Mitigate, Transfer, Avoid](https://iseoblue.com/post/iso-27001-risk-treatment-options/): Risk assessment tells you what your risks are. Risk treatment is what you decide to do about them. For many organisations going through ISO 27001 implementation, the assessment itself gets the most attention — identifying assets, threats, vulnerabilities, and likelihood ratings. But the treatment decisions are where the real work happens, and where auditors spend significant time reviewing the quality of your thinking. - [ISO 27001 Surveillance Audits: What to Expect](https://iseoblue.com/post/iso-27001-surveillance-audit/): Getting ISO 27001 certified is the milestone most organisations focus on. What comes after it — the ongoing audit cycle that keeps the certificate valid — is less well understood, and the gap in preparation often shows. - [How to Handle a Data Breach Under ISO 27001](https://iseoblue.com/post/iso-27001-data-breach-procedure/): A data breach does not announce itself. It might surface as an unusual login alert at 11pm, a supplier calling to say they have received a strange email from your domain, a member of staff reporting that they sent a client file to the wrong person, or a ransomware notification on a Monday morning. In most cases, the first few hours are chaotic, information is incomplete, and the pressure to respond immediately conflicts with the need to understand what has actually happened before taking action. - [ISO 27001 Training and Awareness: Building Your Programme](https://iseoblue.com/post/iso-27001-training-and-awareness-programme/): Most ISO 27001 training programmes are built to satisfy an auditor, not to change behaviour. Staff complete an annual e-learning module, click through the acknowledgement, and forget 80% of it within a week. The organisation ticks the box, the auditor sees a completion record, and twelve months later the phishing simulation results look exactly the same as the year before. - [How to Create an ISO 27001 Supplier Review Process](https://iseoblue.com/post/how-to-create-an-iso-27001-supplier-review-process/): ISO 27001 Supplier reviews push companies to take supplier security seriously. Controls 5.19 to 5.22 establish a framework for identifying, assessing, contracting with, and continuously reviewing the suppliers that have access to your information or systems. - [ISO 27001 Nonconformity and Corrective Action Guide](https://iseoblue.com/post/iso-27001-nonconformity-guide/): An ISO 27001 nonconformity is not a failure of your organisation. It is a finding — a gap between what your ISMS says it does and what it actually does, or between what ISO 27001 requires and what you have in place. Every organisation that goes through a certification audit encounters them. The question is not whether you will get nonconformities (spoiler alert, you will and you should), but how effectively you handle them when you do. - [ISO 27001 Continual Improvement: Making It Real](https://iseoblue.com/post/iso-27001-continual-improvement/): In ISO 27001 continual improvement is directly addressed by Clause 10 of the standard, but its inputs come from almost every other clause. Done properly, it is the mechanism that transforms ISO 27001 from a one-time certification project into a management system that improves over time. - [ISO 27001 Myths Busted: 10 Things People Get Wrong](https://iseoblue.com/post/iso-27001-myths/): ISO 27001 has a mythology problem. Over the years a set of persistent misconceptions have taken hold — that it's only for large enterprises, that it's a purely technical exercise, that it takes years and costs a fortune, and that once you've got the certificate you can forget about it. - [What Do ISO 27001 Auditors Actually Look For?](https://iseoblue.com/post/what-do-iso-27001-auditors-look-for/): There's a common misconception about ISO 27001 audits: that if your documentation is in order, you'll pass. - [ISO 27001 ROI: How to Measure the Value of Certification](https://iseoblue.com/post/iso-27001-roi/): The question comes up at your board presentation: "What do we actually get for this investment?" - [ISO 27001 and AI: What Organisations Need to Consider](https://iseoblue.com/post/iso-27001-and-ai/): Almost every small business I engage with is asking 'What about ISO 27001 and AI?'. They want to know how AI needs to be considered, where do AI tools fit in the ISMS? What risks do they introduce? And what do auditors expect to see? - [ISO 27001 vs GDPR: How They Relate](https://iseoblue.com/post/iso-27001-vs-gdpr/): ISO 27001 and GDPR are two of the most frequently mentioned compliance frameworks in the UK — and they're often confused with one another, or assumed to be interchangeable. They're not. - [ISO 27001 Password Policy: How to Write One](https://iseoblue.com/post/iso-27001-password-policy/): The password policy is one of the most practically important documents in your ISMS — and one of the most commonly done poorly. Either it sets unrealistic requirements that no one follows, or it's so vague it provides no real guidance. - [ISO 27001 for Law Firms: What You Need to Know](https://iseoblue.com/post/iso-27001-for-law-firms/): More often than not, my clients are tech companies or startups, but I thought I'd approach the subject of ISO 27001 for law firms, so here are my thoughts. - [How to Choose an ISO 27001 Certification Body (UK Guide)](https://iseoblue.com/post/how-to-choose-an-iso-27001-certification-body-uk/): Choosing a certification body is one of the decisions that organisations leave until too late — and then rush. It matters more than people realise, both for the quality of the audit and for whether your certificate will be accepted by the customers you're pursuing. - [How to Prepare for an ISO 27001 Stage 2 Audit](https://iseoblue.com/post/how-to-prepare-for-an-iso-27001-stage-2-audit/): This guide on hor to prepare for an ISO 27001 stage 2 audit tells you exactly what auditors look at in Stage 2, how to prepare your evidence, and how to make sure your team is ready. - [ISO 27001 Internal Audit Programme: How to Plan and Run It](https://iseoblue.com/post/iso-27001-internal-audit-programme/): This guide on the ISO 27001 internal audit programme explains exactly what that means, how to structure an annual audit, and how to run individual audits efficiently — including what to actually look at, how to record findings, and how to close them properly before your certification body shows up. - [What is ISO 27001 2022? What Changed From 2013](https://iseoblue.com/post/iso-27001-2022/): If you've been looking at ISO 27001 for a while, you may have noticed references to both "ISO 27001:2013" and "ISO 27001:2022." These are two versions of the same standard — the 2022 edition is the current version, and it replaced the 2013 edition. - [Do I Need ISO 27001? How to Decide](https://iseoblue.com/post/do-i-need-iso-27001/): I suspect many people out there are looking at standards and thinking: "Do I need ISO 27001?" - [ISO 27001 vs PCI DSS: Which Do You Need?](https://iseoblue.com/post/iso-27001-vs-pci-dss/): This ISO 27001 vs PCI DSS guide explains what each one is, how they differ, and how to decide which one — or both — your organisation needs. - [ISO 27001 Management Review: A Complete Guide](https://iseoblue.com/post/iso-27001-management-review/): That's a mistake. Not just because auditors can usually tell when a management review has been done properly versus written up after the fact, but because a good ISO 27001 management review is genuinely valuable for your ISMS. It's the moment where senior management engages with your security posture and makes decisions that keep the system improving. - [ISO 27001 for SaaS Companies: A Practical Guide](https://iseoblue.com/post/iso-27001-for-saas-companies/): If you're building a SaaS product and selling to enterprise customers, you've probably already been asked for ISO 27001. Or you know it's coming. I certainly get a lot of small startups and SaaS companies approaching me for support in getting certified without overcomplicating things. - [How to Prepare for an ISO 27001 Stage 1 Audit](https://iseoblue.com/post/how-to-prepare-for-an-iso-27001-stage-1-audit/): Many organisations are nervous about going into their ISO 27001 Stage 1 audit, but they shouldn't be as it's designed to be a readiness check, not a pass-or-fail test. But going in underprepared will create problems that slow down your path to Stage 2. - [How to Complete an ISO 27001 Risk Assessment](https://iseoblue.com/post/how-to-complete-an-iso-27001-risk-assessment/): This guide walks you through the entire ISO 27001 risk assessment process, from choosing a methodology to producing the documentation auditors want to see. - [ISO 27001 Asset Register: How to Build One](https://iseoblue.com/post/iso-27001-asset-register-how-to-build-one/): This guide explains what an ISO 27001 asset register needs to contain, how to build one that works in practice, and the common mistakes to avoid. - [How to Write an Information Security Policy (ISO 27001)](https://iseoblue.com/post/how-to-write-an-information-security-policy/): An information security policy is a foundational document of your ISO 27001 Information Security Management System (ISMS), or any serious approach to security in a business. It lays out your stall and tells everyone what the organisation's expectations are regarding security, pointing to sub-policies where necessary. It's the first thing most auditors will ask to see, and it's the document that sets the tone for everything else. - [ISO 27001 for Small Businesses: A Practical Guide](https://iseoblue.com/post/iso-27001-for-small-businesses/): This ISO 27001 for small businesses guide cuts through the noise of larger enterprises and explains what ISO 27001 actually looks like for a small team. - [How Long Does ISO 27001 Take?](https://iseoblue.com/post/how-long-does-iso-27001-take/): "How long does ISO 27001 take and how much" is often the first email I get from someone enquiring about ISO 27001. I can understand that, but asking how long ISO 27001 takes is a bit like asking how long it takes to refit a bathroom. The answer will depend on all sorts of things. - [ISO 27001 for Startups: What You Need to Know](https://iseoblue.com/post/iso-27001-for-startups/): This ISO 27001 for startups guide is specifically for startups (and small businesses): what ISO 27001 means for you, what you actually need to do, and how to get certified without it consuming your entire year. - [What Happens If You Fail an ISO 27001 Stage 2 Audit?](https://iseoblue.com/post/what-happens-if-you-fail-iso-27001-stage-2-audit/): The short answer is: it's not the end-of-the-world event you probably fear. But it might be annoying, potentially expensive, time-consuming, and entirely avoidable with the right preparation. - [The ICO Fined Capita £14 Million. Here’s What It Means for Smaller Businesses.](https://iseoblue.com/post/ico-fine-iso-27001-capita/): In October 2025, outsourcing giant Capita received the largest fine in the Information Commissioner's Office (ICO) history — £14 million — following a ransomware attack in 2023 that exposed the personal data of 6.6 million people. - [Stuck at 60%: Why Your ISO 27001 Project Stalled – And How to Get Moving Again](https://iseoblue.com/post/stalled-iso27001/): ISO 27001 isIf you feel like your ISO 27001 project stalled - It's mostly done but never quite gets over the line, you’re in very good company. I regularly hear some variation of: - [Mastering ITIL Practices: A Comprehensive Guide to Streamlining IT Services](https://iseoblue.com/post/mastering-itil-practices/): Streamlining IT services requires a solid grasp of ITIL practices within the IT Service Management framework. - [Exploring ITIL Best Practices](https://iseoblue.com/post/exploring-itil-best-practices/): Establishing ITIL best practices is crucial within IT service management to achieve operational excellence and deliver outstanding value to customers and stakeholders.  - [ITSM vs ITIL: Understanding the Difference](https://iseoblue.com/post/itsm-vs-itil/): IT Service Management, or ITSM, is identified as a comprehensive strategic initiative aimed at the effective design, delivery, management, and enhancement of IT services within an organisation. - [Evaluating IT Service Strategy Performance](https://iseoblue.com/post/evaluating-it-service-strategy-performance/): Measuring and understanding performance plays a pivotal role in strategic decision-making, where being 'data-driven' is increasingly important. ## Pages - [Free ISO 9001 Toolkit Free Download](https://iseoblue.com/iso-9001/iso-9001-toolkit/): FREE ISO 9001 TOOLKIT - [ISO9001](https://iseoblue.com/iso-9001/): Quality Management - [ISO 9001 Consultancy Services](https://iseoblue.com/iso-9001-consultancy-services/): ISO 9001 · Internal audit & coaching · For UK small businesses - [ISO-9001-Interest](https://iseoblue.com/iso-9001-interest/) - [Cyber Security Survey Results](https://iseoblue.com/cyber-security-survey-results/): SURVEY REPORT - [Receipt Page](https://iseoblue.com/receipt-view/): Receipt - [Profile](https://iseoblue.com/profile/) - [Reset Password](https://iseoblue.com/reset-password/) - [Registration Success](https://iseoblue.com/registration-success/): Welcome! - [Registration](https://iseoblue.com/registration/) - [Cyber Security Survey](https://iseoblue.com/cyber-security-survey/): Information Security Management - [ISO 27001 Tools And Services](https://iseoblue.com/iso-27001/iso-27001-basics/iso-27001-tools-and-services/): Tools & Services - [ISO 27001 Explained](https://iseoblue.com/iso-27001/iso-27001-basics/iso-27001-explained/): ISO 27001 explained... - [Post List](https://iseoblue.com/post-list/): {{post_meta key:rank_math_description}} - [Information Security Health-Check](https://iseoblue.com/iso-27001/information-security-health-check/): Information Security - [ISO 27001 Services](https://iseoblue.com/iso-27001/iso-27001-information-security-services/): ISO 27001 - [ISO 27001 Checklist: Everything You Need to Get Certified](https://iseoblue.com/iso-27001/iso-27001-checklist/): ISO 27001 CHECKLIST - [Cookie Policy (UK)](https://iseoblue.com/cookie-policy-uk/) - [What is an ISMS](https://iseoblue.com/iso-27001/what-is-an-isms/): Information Security Basics - [ISO 27001 Requirements](https://iseoblue.com/iso-27001/iso-27001-requirements/): Before diving in, it helps to understand that ISO 27001 requirements come in two distinct forms — and confusing them is one of the most common mistakes organisations make. - [ISO 27001 Tools](https://iseoblue.com/iso-27001/iso-27001-tools/): Free resources from Iseo Blue - [ISO 27001 Complexity & Cost Calculator](https://iseoblue.com/iso-27001/iso-27001-complexity-cost-calculator/): Not sure how much, how long, or how complex your ISO 27001 implementation will be? Find out here with my rapid calculator tool. - [ISO 27001 SoA Assessment Tool](https://iseoblue.com/iso-27001/iso-27001-soa-assessment-tool/): Not sure which of the Annex A controls apply to your business? This tool can help you decide. - [ISO 27001 Gap Analysis Tool](https://iseoblue.com/iso-27001/iso-27001-gap-analysis-tool/): Find out how close you are to 27001, if you are entirely new, or if you have an ISMS you want to evaluate. - [ISO 27001 Internal Audit Service](https://iseoblue.com/iso-27001/iso-27001-internal-audit/): The ISO 27001 internal audit service is priced at a fixed fee of £2,500 + VAT (where applicable). - [My Toolkits](https://iseoblue.com/iso-27001/toolkits/): Iseo Blue Toolkits - [GDPR for Small Businesses](https://iseoblue.com/gdpr/): Information Security Management - [ISO 27001 Cloud Controls – How SMEs should approach them](https://iseoblue.com/iso-27001/annex-a/cloud-first/): Information Security Management - [ISO 27001 Control 5.9 Inventory of Information](https://iseoblue.com/iso-27001/annex-a/control-5-9/): ISO 27001 Control 5.9 asks organisations to develop and maintain an inventory of information and other associated assets, including their owners. - [The Full List of ISO 27001 Controls – Explained](https://iseoblue.com/iso-27001/annex-a/iso-27001-controls-list/): Information Security Management - [Free ISO 27001 Toolkit Pack](https://iseoblue.com/27001-getting-started/): Free Download · ISO/IEC 27001:2022 - [Cyber Security Compliance: Understanding the Different Standards (UK Guide)](https://iseoblue.com/iso-27001/security-compliance-standards/): Cyber security compliance is no longer optional for growing businesses. - [Cyber Essentials vs ISO 27001: Which Does Your UK Business Need?](https://iseoblue.com/iso-27001/cyber-essentials-vs-iso-27001/): If you sell to UK businesses or the public sector, you’ve almost certainly seen both Cyber Essentials (CE / CE Plus) and ISO 27001 on security questionnaires. They’re related, but not interchangeable. - [ISO 27001 vs SOC 2: Which Do You Need? (UK Guide)](https://iseoblue.com/iso-27001/iso-27001-vs-soc-2/): If you sell mainly in the UK or Europe, people ask for ISO 27001. If you sell to US tech, SaaS or enterprise customers, they often ask for SOC 2. Increasingly, UK firms are being asked for both SOC 2 and ISO 27001, with many organizations now pursuing both SOC frameworks to benefit from their complementary strengths and overlapping requirements. Adoptech+2Assent Risk Management+2 - [How to Create an ISO 27001 Incident Response Plan](https://iseoblue.com/iso-27001/implementation-guides/incident-response-plan/): Information Security Management - [ISO 27001 Scope: How to Define It (Examples & Pitfalls)](https://iseoblue.com/iso-27001/implementation-guides/isms-scope/): This guide walks you through how to define your ISO 27001 scope using documents from my toolkit: - [ISO 27001 Internal Auditor: Role, Process & Best Practices](https://iseoblue.com/iso-27001/implementation-guides/internal-audit/): An ISO 27001 internal auditor is the person responsible for independently assessing your ISMS against the requirements of the standard. They examine whether your controls are implemented, operational and effective — and report their findings formally before your external certification audit. - [ISO 27001 Certification Process (Stage 1, Stage 2 and Ongoing Audits)](https://iseoblue.com/iso-27001/certification-guides/certification-process/): The ISO 27001 certification process consists of two stages of audits and typically spans a three-year cycle. - [ISO 27001 Certification in the UK: UKAS vs Non-Accredited](https://iseoblue.com/iso-27001/certification-guides/paths-to-certification/): Information Security Management - [ISO 27001 Implementation Guides](https://iseoblue.com/iso-27001/implementation-guides/): This step-by-step ISO 27001 implementation guide walks you through each stage of the process — from building a business case to achieving certification — so you can plan, execute, and maintain your ISMS effectively. - [ISO 27001 Technological Controls Explored](https://iseoblue.com/iso-27001/annex-a/technological-controls/): Technological controls protect the systems, software, and data that power your organisation.