top of page
Insights


The ISO 27001 Gap Analysis: What It Covers, What It Costs, and Why You Need One Before Committing
An ISO 27001 gap analysis is the essential first step before committing to certification. It tells you where you stand today, what needs to change, how much work is involved, and whether your timeline and budget are realistic. Without it, you are estimating blind.
Daniel Sampson
May 144 min read


How Long Does ISO 27001 Certification Really Take? Realistic Timelines by Company Size
How long does ISO 27001 take? It is the first question most organisations ask, usually because there is a deadline driving the enquiry. A contract that requires certification by Q3. An investor that wants to see a security framework before closing. A tender submission that demands evidence of information security governance.
Daniel Sampson
May 74 min read


ISO 27001 for Startups: How to Get Certified in 5–7 Months Without a GRC Team
ISO 27001 for startups is no longer a luxury reserved for companies with dedicated compliance teams and six-figure budgets. It has become a commercial necessity. If you are a post-seed or Series A company trying to close your first enterprise deal, pass investor due diligence, or win a place on a government framework, ISO 27001 certification is increasingly the gate you need to pass through.
Daniel Sampson
Apr 95 min read


How to Integrate ISO 27001 and ISO 42001 Into a Single Management System
If your organisation already holds ISO 27001 certification and is now developing, deploying, or using AI systems, you are in the strongest possible position to integrate ISO 42001 into your existing management system. Both standards follow the same Annex SL structure. That shared backbone means you are not building a second management system from scratch. You are extending the one you already have.
Daniel Sampson
Apr 74 min read


ISO 27001 and Investor Due Diligence: What Series A Companies Need to Know
You have just closed your term sheet. The champagne is barely flat when the investor’s due diligence checklist arrives. Somewhere around question fourteen, it asks about your information security framework. You check with your CTO. The honest answer is a shared Google Drive, a password manager you adopted six months ago, and a vague intention to “do something about security” next quarter.
Daniel Sampson
Apr 24 min read


How to Run an ISO 27001 Internal Audit: A Step-by-Step Guide for 2026
The days of ticking a box to satisfy audit requirements are over. In 2026, especially with the rise of AI driven threats and the enforcement of the EU AI Act and NIS2, your ISO 27001 Internal Audit must be more than a compliance check, it must be a demonstration of Risk Assu
It’s a common misconception in 2026 that because we are post Brexit, the EU AI Act doesn't apply to the UK. In reality, if your AI system has an output used within the EU, or if you have a single custom
Daniel Sampson
Feb 122 min read
bottom of page