Case study 01 · Management consultancy

ISO 27001 and SOC 2 certification—without losing momentum.

A 50-person business management consultancy needed to satisfy a major customer, strengthen its information-security estate and create a sustainable security programme.

From audit to ongoing leadershipWhat began as an independent security review became a successful certification programme and a continuing Fractional CISO relationship.
≈50employees
ISO 27001certification achieved
SOC 2 Type IIaudit completed
OngoingFractional CISO support
The challenge

Security had become a commercial requirement.

The consultancy’s main customer needed confidence that sensitive information was being managed securely. The organisation had grown quickly, but its policies, controls and staff practices needed a structured, risk-based review.

The immediate goal was successful ISO 27001 and SOC 2 Type II assurance. The wider requirement was to build a proportionate security capability that leaders, staff and customers could trust.

The approach

Practical change, built around the business.

01 · ASSESS

Understand the estate

Reviewed the organisation, technology, information flows and existing controls through a risk-based security audit.

02 · BUILD

Strengthen governance

Rewrote policies and clarified responsibilities so the control environment matched how the company actually operated.

03 · PREPARE

Bring people with us

Trained staff, assembled evidence and prepared teams to demonstrate consistent, effective security practices.

04 · LEAD

See it through

Led the organisation through ISO 27001 certification and its SOC 2 Type II audit, managing issues through to closure.

The outcome

Certification achieved. Customer confidence retained.

  • ISO 27001 certification achieved successfully
  • SOC 2 Type II assurance completed
  • Policies, training and risk management strengthened
  • The organisation’s main customer was satisfied to continue the relationship
  • Pallium Protect retained as the company’s Fractional CISO
Business impact

The work protected an important customer relationship while giving leadership a clear, sustainable way to manage cyber risk.

A similar challenge?

Turn assurance pressure into progress.

Get senior security leadership without the cost of a full-time CISO.