ISO 27001 is an investment, but what do you actually get back? This guide explains how to measure the ISO 27001 ROI for certification.
guides
ISO 27001 Password Policy: How to Write One
6 April 2026
By Alan Parker
Learn what an ISO 27001 password policy must contain, what auditors look for, and how to write one that works in practice — not just on paper.
ISO 27001 for Law Firms: What You Need to Know
6 April 2026
By Alan Parker
Law firms hold some of the most sensitive data imaginable. This guide explains how ISO 27001 applies to legal practices, what clients expect, and how to get certified.
Not all ISO 27001 certification bodies are equal. This guide explains UKAS-accredited and non-accredited bodies, how to shortlist, and what to ask.
How to Prepare for an ISO 27001 Stage 2 Audit
5 April 2026
By Alan Parker
How to prepare for an ISO 27001 Stage 2 audit; what evidence auditors examine, and how to make sure your team is ready on the day.
What is ISO 27001 2022? What Changed From 2013
5 April 2026
By Alan Parker
What is ISO 27001 2022 version? This guide explains what changed, what stayed the same, and what it means for organisations pursuing or maintaining certification.
Do I Need ISO 27001? How to Decide
5 April 2026
By Alan Parker
Asking yourself; Do I need ISO 27001? This guide walks you through the common triggers, who it's really for, and how to make the decision objectively.
ISO 27001 for SaaS Companies: A Practical Guide
4 April 2026
By Alan Parker
ISO 27001 is increasingly a must-have for SaaS companies winning enterprise deals. This guide explains what it means in practice for software businesses.
How to Prepare for an ISO 27001 Stage 1 Audit
4 April 2026
By Alan Parker
Learn what happens in an ISO 27001 Stage 1 audit, what the auditor is looking for, and how to be ready on the day so you can move confidently to Stage 2.
ISO 27001 Asset Register: How to Build One
3 April 2026
By Alan Parker
Learn how to build an ISO 27001 asset register that satisfies Control 5.9, keeps auditors happy, and is actually useful for managing your information assets.