ISO 27001 implementation and certification readiness
From current state to a passed certification audit, with a fixed scope agreed before we start.
Business impact analysis, continuity and recovery plans, and exercises that show the plans work when something goes wrong. Structured as a management system and taken to certification if ISO 22301 is a requirement for you.
Which processes matter most, how long each can be down, and what people, systems and suppliers they depend on.
The realistic disruptions for your organisation: power and connectivity loss, key people unavailable, a supplier failing, ransomware, flooding at the site.
Recovery strategies, continuity plans and runbooks that someone can follow at two in the morning.
A tabletop exercise with your management team, then a technical recovery test, with lessons captured and plans updated.
If you want the certificate, we structure the work as a business continuity management system and prepare you for the audit.
From current state to a passed certification audit, with a fixed scope agreed before we start.
Independent internal audits, surveillance preparation and the 2013 to 2022 transition for companies that already hold ISO 27001.
Get ready for Sri Lanka’s PDPA, whose core obligations commence on 1 January 2027, and align the work with ISO 27001 so you do it once.
Forty-five minutes, no charge. We ask about your organisation, what is driving the project and what you already have in place, then send a written proposal with a fixed scope and fee.