---
title: "ISO 27001 Consultant London | Network London"
url: https://www.networklondon.co.uk/cybersecurity/iso-27001-consultant
description: "ISO 27001 consultancy in London led by a lead implementer. Gap analysis, risk assessment, policies and controls, then the audit, from the team who run your IT."
publisher: Network London
legal_name: Verdani Solutions Group Limited
---

# ISO 27001 consultant in London, from the team who run your IT

Network London helps firms of 20 to 250 people work towards ISO 27001: the gap analysis, the risk assessment, the policies and the evidence, led by Ian Welch, our Technical Director and an ISO 27001 lead implementer. Because we also look after your IT, the controls get built and run, not just written down.

- Led by an ISO 27001 lead implementer
- Controls put in place by the people who run your systems
- Evidence kept current for the audit and for client questionnaires

## A client or investor has asked whether you're ISO 27001 certified

Does any of this sound familiar?

- A tender or questionnaire asks for ISO 27001 and the honest answer is “not yet”.
- You have a folder of policies from a template that nobody follows.
- Quotes from consultancies assume you have an IT team to do the technical work. You don't.

ISO 27001 is a management system, not a certificate. The hard part is running it every month, and that is the part we're already doing for you.

## Gap analysis, risk assessment, policies, controls, then the audit

We start with a gap analysis against the standard: what you already do, what is missing and what it would take to close the gap. Then the risk assessment, the Statement of Applicability, policies written for how your firm works, and the technical controls: access reviews, multi-factor authentication, encrypted devices, tested backups, logging and patching. We keep the evidence as we go, so the auditor sees a system that runs rather than a binder put together the week before.

Certification itself is carried out by an accredited certification body, which has to be independent of us. We prepare you for the audit, sit with you through it and fix any findings. The work is led by Ian Welch, a CISSP and ISO 27001 lead implementer with more than 25 years' experience, and Network London holds **Cyber Essentials Plus**.

Tell us who has asked for ISO 27001 and when they need it by. We'll tell you honestly what it would take.

## What you get from an ISO 27001 consultant who also runs your IT

- **One team for the policy and the control**: The consultant who writes the access control policy is on the same team as the engineer who does the access review. Nothing falls between two suppliers.
- **Evidence that keeps itself current**: Patch reports, backup tests, access reviews and incident logs are produced as part of looking after your IT, so the audit evidence is there without a scramble.
- **Honest scope**: Not every firm needs the full certificate. If Cyber Essentials Plus and a good set of policies would satisfy the client asking, we'll say so.

- **20** years looking after business IT
- **100+** businesses across the world trust us with their IT
- **24/7** support, with a real person on the phone

## Who we work with

Three of the 100+ businesses we look after, and what we do for them.

### Rossair

IT support, the phone system and a website that brings in enquiries, all looked after by one team.

[Read the story](https://www.networklondon.co.uk/case-studies#rossair)

### LAMDA

Everyday support for 180 people, with access reviews and backup testing built into how they work.

[Read the story](https://www.networklondon.co.uk/case-studies#lamda)

### A private equity firm

A small team with serious duties to investors. We shaped their IT and cyber security policy and look after it day to day.

[Read the story](https://www.networklondon.co.uk/case-studies#private-equity)

## How ISO 27001 work starts

1. **A conversation about who is asking**: Jessica, our Operations Director, replies the same day. We talk about who has asked for ISO 27001, your deadline and what you have in place already.
2. **A gap analysis in plain English**: We review your systems, policies and practices against the standard and give you a written view: what passes, what is missing and the order to fix it.
3. **Build, run, then audit**: We put the controls and the management system in place, run it with you for long enough to produce evidence, then prepare you for the certification audit.

## What our ISO 27001 consultancy includes

- **Gap analysis**: Your systems, policies and practices measured against every clause and control in the standard, with a written plan in priority order.
- **Risk assessment and Statement of Applicability**: The risk register and the Statement of Applicability, built around your firm's actual systems and data rather than a generic list.
- **Policies written for your firm**: Information security, access control, acceptable use, supplier management, incident response and business continuity, written for how you work.
- **Technical controls**: Multi-factor authentication, access reviews, encrypted and managed devices, patching, logging and tested backups, put in place by our engineers.
- **Internal audit and management review**: We run the internal audit and prepare the management review, which the certification body expects to see before it visits.
- **Audit preparation and support**: We prepare you for the certification audit, attend it with you and fix any nonconformities. The audit is carried out by an independent, accredited certification body.
- **Keeping it running**: After certification we keep the system running: access reviews, patching, backups, logs and the annual cycle of audits and reviews.
- **Cyber Essentials Plus on the way**: Most firms take Cyber Essentials Plus as a first step. We hold it ourselves and help you get there.

## Tell us what you need

Jessica, our Operations Director, reads every enquiry and replies personally the same day. The first step is a conversation about your business, what's working and where you need help.

Prefer to talk? Call [0333 335 5020](tel:+443333355020). A real person answers, always.

Thank you. Your message has been received and we'll be in touch shortly.

Something went wrong sending that. Please call [0333 335 5020](tel:+443333355020) or email [letstalk@networklondon.co.uk](mailto:letstalk@networklondon.co.uk?subject=Network%20London%20-%20IT%20services%20query).

## Been asked for ISO 27001?

Tell us who is asking and when they need it. Jessica, our Operations Director, replies to every enquiry personally, the same day, and the first step is a conversation about your firm.

### How much does ISO 27001 consultancy cost?

It depends on your size, how much you already have in place and how quickly you need it. After the gap analysis we give you a fixed quote for the consultancy. The certification body charges its own audit fee, which you pay to them directly; it depends on the size of your firm.

### How long does ISO 27001 take?

It depends on the size of your organisation and how complex your IT is. The management system has to run for long enough to produce evidence before the audit, so the timeline is set by that rather than by the paperwork. We give you a realistic date after the gap analysis.

### Is Network London ISO 27001 certified?

Network London holds Cyber Essentials Plus. Our ISO 27001 work is led by Ian Welch, who is an ISO 27001 lead implementer. We don't claim a certificate we don't hold, and we'd expect you to check that of any consultant.

### Do we need ISO 27001, or is Cyber Essentials Plus enough?

Ask whoever is asking. Many clients and insurers are satisfied by Cyber Essentials Plus and a sound set of policies. Larger clients, financial services firms and public sector tenders increasingly specify ISO 27001. We'll give you a straight view before you commit to the bigger project.

### Can you do ISO 27001 if another company looks after our IT?

Yes, though it works best when one team is accountable for both the policy and the control. If your provider stays, we'll work with them. If you'd rather move your IT to us, we handle the handover first.

### Do you also cover ISO 42001, ISO 22301, GDPR and PCI DSS?

Yes. AI management (ISO 42001), business continuity (ISO 22301), GDPR and PCI DSS work follow the same pattern: a gap analysis, the policies and controls, then the evidence. Tell us which standard has been asked of you.

## Also from Network London

- [Cyber Essentials cost and process](https://www.networklondon.co.uk/cybersecurity/cyber-essentials-cost): What Cyber Essentials and Cyber Essentials Plus cost, and how we get you through them.
- [Penetration testing](https://www.networklondon.co.uk/cybersecurity/penetration-testing): Penetration testing scoped to what your clients asked for, with the findings fixed by the same team.
- [Cyber security](https://www.networklondon.co.uk/service/cyber-security): We look after your cyber security and help you answer the security questions your clients, insurers and investors send you.
- [IT compliance](https://www.networklondon.co.uk/service/managed-it-compliance): Help with IT compliance, including Cyber Essentials, ISO 27001 and GDPR, from policies to the questionnaires your clients send.

## The Cyber Security Vault: 22+ tools and apps

Most of them are free. We'll send you our list of resources you and your team can use to improve your cyber security straight away. No technical knowledge needed.

---

Network London, LM04.202, The Leather Market, Weston Street, London SE1 3ER. Telephone 0333 335 5020. letstalk@networklondon.co.uk. Network London is a trading name of Verdani Solutions Group Limited, which owns the Network London trade mark. Verdani Solutions Group Limited is registered in England and Wales, company number 11357867.
