ISO 27001 and SOC 2 certification—without losing momentum.
A 50-person business management consultancy needed to satisfy a major customer, strengthen its information-security estate and create a sustainable security programme.
Security had become a commercial requirement.
The consultancy’s main customer needed confidence that sensitive information was being managed securely. The organisation had grown quickly, but its policies, controls and staff practices needed a structured, risk-based review.
The immediate goal was successful ISO 27001 and SOC 2 Type II assurance. The wider requirement was to build a proportionate security capability that leaders, staff and customers could trust.
Practical change, built around the business.
Understand the estate
Reviewed the organisation, technology, information flows and existing controls through a risk-based security audit.
Strengthen governance
Rewrote policies and clarified responsibilities so the control environment matched how the company actually operated.
Bring people with us
Trained staff, assembled evidence and prepared teams to demonstrate consistent, effective security practices.
See it through
Led the organisation through ISO 27001 certification and its SOC 2 Type II audit, managing issues through to closure.
Certification achieved. Customer confidence retained.
- ISO 27001 certification achieved successfully
- SOC 2 Type II assurance completed
- Policies, training and risk management strengthened
- The organisation’s main customer was satisfied to continue the relationship
- Pallium Protect retained as the company’s Fractional CISO
The work protected an important customer relationship while giving leadership a clear, sustainable way to manage cyber risk.
Turn assurance pressure into progress.
Get senior security leadership without the cost of a full-time CISO.

