Services

Information Security & ISO Compliance

From ISO 27001 certification to Cyber Essentials and supply chain due diligence - practical, hands-on information security support built around what your business actually needs.

Why information security matters - and why it's often mishandled

Information security is one of the most technically complex and fast-moving areas of business compliance. ISO standards, Cyber Essentials, supplier assurance, and staff awareness all interact - and the consequences of getting it wrong range from certification failure to significant reputational and financial damage.

Most SMEs either over-engineer their approach (chasing standards they don't need) or under-invest (assuming they're too small to be a target). Neither is right. Elmar's approach is proportionate: we identify what your actual risk profile demands, build the right controls, and put in place the ongoing processes that keep them working.

Peter Berry holds ISO Lead Auditor qualifications across ISO 27001, 9001, 14001, 45001, and 50001, and has built and managed information security programmes within major UK regulated organisations. That's the level of experience your business gets - without the overhead of a full-time hire.

What We Cover

Focus areas

Our information security work spans the full lifecycle - from baseline assessments through certification and into long-term programme management.

How to Work With Us

Engagement options

Two ways to access our information security expertise - structured around your business's current stage and budget.

Retainer

Outsourced ISO Management

Ongoing expert oversight - no full-time hire needed.

We act as your embedded information security and ISO function. Includes continuous risk monitoring, surveillance audit prep, management review support, and a dedicated point of contact for day-to-day queries.

  • Dedicated named consultant
  • Monthly or quarterly review cadence
  • Continuous risk register maintenance
  • Annual internal audit programme
  • Surveillance & recertification preparation
  • Staff awareness sessions (on request)

Fixed-Fee Project

ISO Implementation

A clear scope, a defined output, a single invoice.

Scoped project engagements for organisations pursuing initial certification or remediating an identified gap. Deliverables, timelines, and fees are agreed upfront - no surprises.

  • Gap analysis & readiness assessment
  • Full policy and procedure suite
  • Risk assessment & Statement of Applicability
  • Internal audit & corrective action plan
  • Management review facilitation
  • Certification body liaison support

Consultancy Support

Building your internal security capability

Not every organisation needs a managed outsourced function. If your team wants to manage information and cyber security independently, our Consultancy Support model gives you the expert foundation and guidance to do it confidently.

We provide targeted support only when you need it, with no ongoing contract required. From Cyber Essentials through to ISO 27001, you get guidance at every step while building the internal skills and confidence to maintain compliance independently over time.

The goal is a strong, lasting foundation, the right frameworks and processes from the beginning, and a team that is genuinely equipped to manage information and cyber security day to day.

Expert help at the start while your team runs day-to-day security internally

Targeted support only when you need it, with no ongoing contract required

Clear guidance from Cyber Essentials through to ISO 27001 certification

Staff equipped to manage information and cyber security with confidence

The right frameworks and processes built in from the beginning

A strong, secure foundation that keeps you compliant as you grow

The Certification Journey

What to expect from start to certification

Whether you are pursuing ISO 27001, ISO 9001, ISO 14001, ISO 45001, or ISO 50001, the certification journey follows the same structured path. Elmar guides you through each stage.

  1. 01

    On-site initial assessment and gap analysis

    We assess your current position against the standard's requirements, map existing controls, and produce a prioritised action plan.

  2. 02

    Bespoke documentation preparation

    We prepare policies, procedures, and documented information that reflect how your organisation actually operates, not off-the-shelf templates.

  3. 03

    Hands-on implementation and team mentoring

    We work alongside your team to embed the required processes and build the skills to maintain them independently.

  4. 04

    Rigorous internal audit

    A full internal audit against the standard before the external auditor arrives, finding and addressing issues in advance.

  5. 05

    Certification audit and on-site support

    We prepare you thoroughly for Stage 1 and Stage 2 audits and are available to support you on the day.

Related Insights

Ready to start?

Talk to us about your information security needs

Whether you are pursuing first-time ISO 27001 certification, Cyber Essentials, or need ongoing compliance management, get in touch for a no-obligation conversation.

Book a Free Introductory Call