ISO 27001

iso 27001 consultancy cost uk a compass round case short needle

ISO 27001 Consultancy Cost UK: Timeline, Pricing & Preparation

ISO 27001 consultancy is the largest controllable line in most UK certification budgets, and the one buyers understand least. This guide prices it properly: 2026 UK day rates by consultant type, fixed-price bands by headcount, the day count behind each deliverable, five engagement models compared, a month-by-month timeline from scoping call to certificate, ten preparation steps that remove billable days from the quote, and a full three-year cost of ownership worked through one 45-person business.

Read more
cyber security audit cost uk what smes pay a tape measure case blade tongue

Cybersecurity Audit Cost UK: What SMEs Should Expect to Pay

Cyber security audit” is not one product in the UK — it is five, priced between roughly £400 and £25,000, and most overspending comes from buying a level of assurance nobody asked for. This guide prices Cyber Essentials, Cyber Essentials Plus, posture reviews, vulnerability assessments and ISO 27001 certification side by side, explains the day-rate arithmetic behind every quote, shows exactly which scope decisions move the number, and costs one 40-person firm five different ways.

Read more
penetration testing frequency a shield with magnifying glass

Penetration Testing Frequency: Proven Rules for Safer IT

Once a year is a floor, not a schedule. This guide sets out how often a business should conduct penetration testing and why the calendar date matters far less than what changed in the estate since the last report. It covers the twelve-month baseline and where it comes from, the seven change triggers that should force an unscheduled round, exactly what PCI DSS, ISO 27001, SOC 2, Cyber Essentials Plus and NIS2 actually require, where vulnerability scanning stops and human testing starts, indicative UK programme costs at every cadence, and how to build a calendar that survives a year of competing priorities.

Read more
cybersecurity risk register template smes a upright board of blank tiles

Cybersecurity Risk Register: Proven Template for Safe SMEs

Most cybersecurity risk register templates are built for banks and abandoned by small businesses within a fortnight. This guide strips the document back to the eleven fields that earn their place, gives likelihood and impact scales anchored to time and money rather than adjectives, and shows a worked register for a sixty-person firm with real rows, owners and treatment decisions. It also covers the four treatment options and how to use each one honestly, a two-afternoon build method, the review cadence and out-of-cycle triggers that stop the register rotting, and when a spreadsheet stops being enough.

Read more
supplier cyber-risk assessment - supplier cyber risk assessment checklist a concentric cube rings plinth

Supplier Cyber-Risk Assessment: Essential Safe Checklist

Most supplier assurance programmes send a spreadsheet, receive a spreadsheet and file it — producing documentation rather than assessment. This guide sets out a working supplier cyber-risk assessment checklist as a seven-step programme: building an honest supplier inventory from four independent sources, scoring inherent risk before you contact anyone, tiering the base so effort follows exposure, the ten control domains the checklist must cover, choosing an assessment method that matches the tier, demanding the evidence artefact behind every claim, converting answers into residual risk and a dated decision, handling concentration and fourth-party risk, turning findings into remediation with deadlines and consequences, monitoring continuously between reviews, and closing the loop properly at offboarding.

Read more
third-party cybersecurity questionnaire - third party cybersecurity questionnaire template a central hub six satellite nodes plinth

Third-Party Cybersecurity Questionnaire: Proven Risk Guide

Most supplier security questionnaires are inherited spreadsheets that produce documented false assurance rather than real risk reduction. This guide provides a working third-party cybersecurity questionnaire template: the eight domains it must cover, the full 47-question Tier 1 set written as closed questions, a three-tier model so you stop sending 180 rows to low-risk suppliers, a four-outcome scoring rubric that produces decisions instead of percentages, the evidence artefact to demand behind every claim, the red flags that separate a filed document from a real finding, a mapping to Cyber Essentials, ISO 27001 and NIS2 Article 21, and the contract clauses that turn questionnaire answers into enforceable obligations.

Read more
iso 27001 readiness assessment checklist a shield tick hexagonal plinth

ISO 27001 Readiness Assessment: Essential Risk Checklist

An ISO 27001 readiness assessment is the honest audit you run on yourself before a certification body runs one on you. This checklist walks through the mandatory requirements of Clauses 4 to 10, scores the 93 Annex A controls across the four 2022 themes, sets out the documented information an auditor asks for by name, and names the seven gaps that turn up in almost every first assessment. It covers a maturity scoring method that produces a remediation plan rather than a dashboard, realistic remediation timescales per gap type, the difference between doing the assessment in-house, consultant-led or platform-led, and the single biggest predictor of failing Stage 2.

Read more
iso 27001 certification cost uk smes a certificate seal on stacked coin discs

ISO 27001 Certification Cost: The Smart, Essential UK SME Guide

The realistic ISO 27001 certification cost for a UK SME lands between roughly £6,000 and £48,000 in the first year, and almost none of that sits on a single invoice. This guide splits the number into certification body audit fees, external support, tooling and internal staff time, benchmarks each by headcount, explains how audit days are calculated, sets out a realistic six to twelve month timeline from gap analysis to certificate, and lists nine levers that genuinely reduce spend without putting the audit outcome at risk.

Read more
CHAT