Our Services

Gap analysis

If you're not quite sure where you are on your information security journey, we can help you find out. Following an initial scoping questionnaire, we can spend a day or two with you (either on site or virtually) going through what you have in place and make recommendations that will strengthen the protection of your information assets.

Framework Implementation

More and more, businesses are being asked to provide evidence of accreditation to an information security standard in order to be able to handle data, particularly data that might include Personally Identifiable Information. The most common accreditations in the UK are Cyber Essentials and Cyber Essentials Plus, and ISO27001. We can guide you through the implementation of these standards so you can show your customers their data is safe with you.

Audit

Once you have decided to take the plunge and go for an accreditation, you may well feel confident putting together an Information Security Management System (ISMS) but perhaps not so confident talking the language of the auditors. We can provide a pre-audit readiness check as well as being there to represent your organisation during the audit.

Policy Writing

Information security doesn't start and end with a certificate. You may be aware that your information security practices could do with strengthening, but you may not be ready to go all the way down the road to accreditation. An updated policy suite can be a great place to start, allowing you to introduce latest best practices into your organisation. Whether it's tweaking what you've already got or starting from scratch, we can help.

Supply Chain Management

Supply chain management is currently one of the hottest topics in cyber security, so how confident are you in yours? You might be following best practices when it comes to protecting your data and your network, but are your key third parties? We can help you put a system in place that will help you understand the risks involved in bringing on new vendors and monitor your existing vendors (whilst maintaining those all important relationships).

From the other side, customers are carrying out more taxing due diligence, more often. If you are inundated with multi-page RFPs, we can assist with your responses.

GRC, Virtual CISO & Consultancy

We can offer Governance, Risk & Compliance and Virtual CISO functions for those organisations who recognise the need to have some of those options but don't have a full-time need for such positions. Whether that's signing off your policies, working with senior management to establish risk criteria, attending quarterly board meetings to meet compliance requirements or just being your dedicated security consultant, we can be there for you.

All rights reserved. Information Security Services Ltd