ISO 27001

Certified, without grinding the team to a halt

When customers, partners, or investors require an ISO 27001 certification from you, I help you get there – on a path that stays affordable and that your team can keep running on its own afterwards.

A bundled stack of security policies with a padlock and a checkmark

The path to certification often feels long and bureaucratic: a mountain of requirements and documents to work through, and plenty of new rules to put in place across the company. Make the wrong trade-offs along the way and two things happen – it gets very expensive and time-consuming, and you still don't end up feeling any more secure.

There is a leaner way: with tools you already have, a few targeted additions, and security rules documented where the work happens anyway. In practice that looks something like this:

  • Policies as versioned pages in your wiki or Git repo – with a change history instead of Word document versions.
  • Security incidents in the ticket system you already use – GitHub, Jira, Linear.
  • Code changes with review and a green test run; your pull requests are the evidence for the audit.
  • Access and devices through your identity provider such as Microsoft 365 or Okta – wired directly into device management.
  • Passwords and keys in the team password manager, not in chats or files.
  • Risks, measures, and suppliers in a few maintained lists or one deliberately chosen tool – not a platform of its own.

Pragmatic

The approach

  • Privacy-friendly

    Tools hosted and contracted in the EU, as little personal data as possible, no employee surveillance. Security should not come at the expense of your staff.

  • Low cost

    Preference for tools you already use: source control, password manager, device management. Instead of one large software licence, only a few targeted additions.

  • Little ongoing effort

    The security rules live as plain text files in your source control, the documents for the audit are generated automatically, checks run inside your existing workflows. Audit preparation takes days, not weeks.

  • Still the real thing

    The certification covers everything the ISO/IEC 27001:2022 standard requires. No “certificate light”.

Results

What you end up with

  • A manageable set of rules – around 20 short policies, versioned and exportable as PDF.
  • A way of handling risks that takes one to two hours per quarter.
  • A clear overview of which security measures apply to you and why.
  • Fixed dates for the internal check and the yearly review by management.
  • Onboarding and offboarding checklists that actually get used.
  • A list of your important systems and suppliers – without duplicate upkeep.

Proven

In practice

  • Built and guided to certification for a team of around 20 people (internal and external): a provider of digital health and consumer apps with a B2B software business.
  • Certified against ISO/IEC 27001:2022 for several years. The yearly surveillance audits recently returned only minor notes and no serious findings.
  • Additionally backed by an external security test (penetration test).

Working together

How it works

From the initial stocktake to the certification audit usually takes three to six months, at roughly one day of effort per week on your side.

  1. Stocktake

    What is in scope, what already exists, where the gaps are.

  2. Build

    Introduce rules, risks, and measures – kept lean.

  3. Let it settle

    Apply the measures in everyday work, run one internal check.

  4. Certification & handover

    Support the audit, then hand operation over to the team.

Sounds like your situation? The About page lists the ways to reach me.