SteadySec Your retained security partner

At full delivery capacity until the end of 2026.

ISO 27001 readiness

We build the ISMS, implement the controls, and prepare you for audit over time - structured so the system holds up when an auditor, a customer, or an incident tests it.

ISO 27001 works as a way of running security that your team uses day to day, not as a document project.

Where This Fits

Who this is for

This is you

Your company

  • 20-50+ people and growing
  • Security is becoming a real function
  • You face formal demands for evidence

What is pushing you

  • Enterprise customers expect certification
  • Tenders require ISO 27001
  • Investors raise it during due diligence
  • Internal maturity makes it the next step

How we do it

  • Instead of a template ISMS bought off the shelf, we build an ISMS scoped to your real business.

  • Instead of treating certification as a one-off documentation exercise, we give every control a named, accountable owner.

  • Instead of a certificate over a system nobody actually runs, we leave you with a system that holds up at the next audit.

The Problem

The certificate is not the system

Most failed ISO 27001 projects fail the same way. The company buys a policy pack, fills in the names, and treats the standard as a documentation exercise. Then the auditor asks for the evidence that a control ran, and there is none, because nobody was ever made responsible for running it.

ISO 27001 is two things at once. Clauses 4 to 10 describe a management system : how security gets decided, reviewed and improved. Annex A lists the controls that system chooses from. A template gives you a version of the second and none of the first, and the first is what an auditor tests hardest.

Scope and context

Which parts of the business, which locations, which systems, and which interested parties the ISMS covers. A scope drawn too wide costs money for years; drawn too narrow, a customer rejects the certificate.

Risk assessment and treatment

A repeatable method, a risk register that names real risks rather than categories, and a treatment plan that says what is being done, by whom, and by when.

Statement of Applicability

Every Annex A control marked as applicable or not, with the justification and the implementation status. It is the first document an auditor opens and the one most often written last.

Roles, competence and awareness

Named owners for the ISMS and for each control, evidence that the people holding those roles are competent to hold them, and awareness activity that actually happened.

Internal audit and management review

An internal audit programme covering the whole system over the cycle, and a management review with real inputs: risks, incidents, objectives, audit findings, and decisions taken.

Nonconformity and improvement

Findings recorded, root causes identified, corrective actions closed. An ISMS with no findings in a year is not a clean system, it is an unused one.

Annex A adds 93 controls in four themes. You do not implement all of them. You justify each one, in writing, in the Statement of Applicability .

Organisational

37 controls

Policies, supplier and cloud security, incident management, continuity, classification, and legal and contractual duties.

People

8 controls

Screening, terms of employment, awareness, disciplinary process, and what happens when someone leaves or changes role.

Physical

14 controls

Secure areas, equipment, clear desk and screen, media handling, and the physical side of remote working.

Technological

34 controls

Access control, cryptography, logging and monitoring, secure development, vulnerability management, backup, and network security.

The Audit

What certification actually tests

Certification is issued by an independent accredited body, not by an advisor. Knowing what that body looks at is what turns a readiness project from a guess into a plan.

Stage 1: documentation review

The auditor checks that the management system exists on paper and is ready to be tested: scope, policy set, risk assessment, Statement of Applicability, internal audit programme, and management review. The output is a list of what must be closed before Stage 2.

Stage 2: implementation audit

The auditor samples the controls and asks for evidence that they ran. Not "do you have an access review policy" but "show me the last three access reviews, and show me what happened to the accounts you found". This is where a template ISMS fails.

Surveillance and recertification

Certification runs on a three-year cycle with a surveillance audit in each of the two intervening years. The system has to keep producing evidence between audits, which is the part that lapses when the readiness project ends and nobody owns the ISMS.

Where our work stops is worth stating plainly. We build the system, prepare the evidence and coordinate with the certification body. We do not audit you and we do not issue the certificate: an advisor who does both is a conflict the accreditation rules exist to prevent. If certification is not actually the goal and you want working controls first, the CIS Controls baseline is the cheaper honest answer, and it converts into an ISMS later.

The Roadmap

Five phases

1

Readiness assessment

Scope, interested parties, customer and security drivers, an asset and process overview, existing controls, and a clear gap analysis against ISO 27001.

2

ISMS foundation

ISMS scope, risk methodology, asset register, risk register, statement of applicability, the policy set, and named control owners.

3

Control implementation

Access control, supplier management, incident management, backup and recovery, vulnerability management, logging and monitoring, security awareness, and secure development where relevant.

4

Evidence and internal audit preparation

Evidence collection, management review, internal audit support, corrective actions, and coordination with the certification body.

5

Retainer maintenance

Ongoing ISMS operations, quarterly risk register updates, control checks, supplier evidence, and audit readiness between certification cycles.

Start Here

How to start

The same four steps for every engagement here. You can stop after step two and owe nothing.

  1. 1

    Run the Discovery Calculator

    Free

    About four minutes, no sign-up. It runs in your browser and nothing is sent anywhere unless you choose to send it.

  2. 2

    Send me the result

    Free

    I reply with a recommendation for your situation - including when the honest answer is that you do not need me yet.

  3. 3

    Starter Assessment (€1,900) or Starter Month (€2,900)

    Fixed price, one-off

    The paid entry, and the only one. It ends with a roadmap of the major milestones and a recommended retainer tier.

  4. 4

    Continue on a retainer

    From €950 a month

    If the roadmap makes sense to both of us, implementation runs inside the retained engagement. Part of what you paid for the starter door is credited against it.

How this becomes a retainer

An ISMS only holds if it is operated: the review cycle, the risk register, and audit readiness between certification cycles all keep running. The starter door produces the roadmap; the retained engagement is where it gets built. One senior practitioner, a fixed monthly hour cap, and a tier set after the starter door rather than guessed before it.

What is not included

Certification is issued by an independent accredited body, not by us. We prepare you for it and coordinate with the certification body; management owns risk acceptance and the final decisions.

Certification is a milestone. The real product is an ISMS your company actually uses.