Rossair
IT support, the phone system and a website that brings in enquiries, all looked after by one team.
0333 335 5020letstalk@networklondon.co.ukRemote supportClient portal
Network London helps firms of 20 to 250 people work towards ISO 27001: the gap analysis, the risk assessment, the policies and the evidence, led by Ian Welch, our Technical Director and an ISO 27001 lead implementer. Because we also look after your IT, the controls get built and run, not just written down.


Does any of this sound familiar?
ISO 27001 is a management system, not a certificate. The hard part is running it every month, and that is the part we're already doing for you.

We start with a gap analysis against the standard: what you already do, what is missing and what it would take to close the gap. Then the risk assessment, the Statement of Applicability, policies written for how your firm works, and the technical controls: access reviews, multi-factor authentication, encrypted devices, tested backups, logging and patching. We keep the evidence as we go, so the auditor sees a system that runs rather than a binder put together the week before.
Certification itself is carried out by an accredited certification body, which has to be independent of us. We prepare you for the audit, sit with you through it and fix any findings. The work is led by Ian Welch, a CISSP and ISO 27001 lead implementer with more than 25 years' experience, and Network London holds Cyber Essentials Plus.
Tell us who has asked for ISO 27001 and when they need it by. We'll tell you honestly what it would take.
Tell us what you needThe consultant who writes the access control policy is on the same team as the engineer who does the access review. Nothing falls between two suppliers.
Patch reports, backup tests, access reviews and incident logs are produced as part of looking after your IT, so the audit evidence is there without a scramble.
Not every firm needs the full certificate. If Cyber Essentials Plus and a good set of policies would satisfy the client asking, we'll say so.
Three of the 100+ businesses we look after, and what we do for them.
IT support, the phone system and a website that brings in enquiries, all looked after by one team.
Everyday support for 180 people, with access reviews and backup testing built into how they work.
A small team with serious duties to investors. We shaped their IT and cyber security policy and look after it day to day.
Jessica, our Operations Director, replies the same day. We talk about who has asked for ISO 27001, your deadline and what you have in place already.
We review your systems, policies and practices against the standard and give you a written view: what passes, what is missing and the order to fix it.
We put the controls and the management system in place, run it with you for long enough to produce evidence, then prepare you for the certification audit.
Your systems, policies and practices measured against every clause and control in the standard, with a written plan in priority order.
The risk register and the Statement of Applicability, built around your firm's actual systems and data rather than a generic list.
Information security, access control, acceptable use, supplier management, incident response and business continuity, written for how you work.
Multi-factor authentication, access reviews, encrypted and managed devices, patching, logging and tested backups, put in place by our engineers.
We run the internal audit and prepare the management review, which the certification body expects to see before it visits.
We prepare you for the certification audit, attend it with you and fix any nonconformities. The audit is carried out by an independent, accredited certification body.
After certification we keep the system running: access reviews, patching, backups, logs and the annual cycle of audits and reviews.
Most firms take Cyber Essentials Plus as a first step. We hold it ourselves and help you get there.
Jessica, our Operations Director, reads every enquiry and replies personally the same day. The first step is a conversation about your business, what's working and where you need help.
Prefer to talk? Call 0333 335 5020. A real person answers, always.
LM04.202, The Leather MarketThank you. Your message has been received and we'll be in touch shortly.
Something went wrong sending that. Please call 0333 335 5020 or email letstalk@networklondon.co.uk.
Tell us who is asking and when they need it. Jessica, our Operations Director, replies to every enquiry personally, the same day, and the first step is a conversation about your firm.
Tell us what you needIt depends on your size, how much you already have in place and how quickly you need it. After the gap analysis we give you a fixed quote for the consultancy. The certification body charges its own audit fee, which you pay to them directly; it depends on the size of your firm.
It depends on the size of your organisation and how complex your IT is. The management system has to run for long enough to produce evidence before the audit, so the timeline is set by that rather than by the paperwork. We give you a realistic date after the gap analysis.
Network London holds Cyber Essentials Plus. Our ISO 27001 work is led by Ian Welch, who is an ISO 27001 lead implementer. We don't claim a certificate we don't hold, and we'd expect you to check that of any consultant.
Ask whoever is asking. Many clients and insurers are satisfied by Cyber Essentials Plus and a sound set of policies. Larger clients, financial services firms and public sector tenders increasingly specify ISO 27001. We'll give you a straight view before you commit to the bigger project.
Yes, though it works best when one team is accountable for both the policy and the control. If your provider stays, we'll work with them. If you'd rather move your IT to us, we handle the handover first.
Yes. AI management (ISO 42001), business continuity (ISO 22301), GDPR and PCI DSS work follow the same pattern: a gap analysis, the policies and controls, then the evidence. Tell us which standard has been asked of you.

What Cyber Essentials and Cyber Essentials Plus cost, and how we get you through them.

Penetration testing scoped to what your clients asked for, with the findings fixed by the same team.

We look after your cyber security and help you answer the security questions your clients, insurers and investors send you.

Help with IT compliance, including Cyber Essentials, ISO 27001 and GDPR, from policies to the questionnaires your clients send.
Most of them are free. We'll send you our list of resources you and your team can use to improve your cyber security straight away. No technical knowledge needed.