Building an ISO 27001 practice to serve a national advisory client base
UK accountancy and advisory firm · public and private sector clients
A UK accountancy and advisory firm had a four-person cyber security team, a fragmented offering and growing client demand it could not meet.
The challenge
The team had no coherent framework for what it sold, how it delivered or how it priced. The market was accelerating on ISO 27001 and GDPR, the firm was growing, and the practice needed to be rebuilt and scaled without disrupting the client relationships already in place.
What we did
How it was delivered.
-
01
Redesigned the service suite
ISO 27001 implementation and audit, GDPR compliance, Cyber Essentials and broader governance advisory, designed as a coherent and deliverable offering rather than a collection of one-off engagements.
-
02
Grew the team from four to twelve
Recruited, onboarded and developed the team while running live client programmes. The practice scaled from four people to twelve across the build period.
-
03
Delivered through an acquisition
Programmes delivered on time and on budget as the firm was acquired. Client continuity maintained throughout, no programme disrupted.
The outcome
A twelve-person cyber security practice with a coherent service suite and a portfolio of delivered ISO 27001 and GDPR programmes, intact through a firm acquisition.
4 to 12
team built while delivering live ISO 27001 and GDPR programmes
Start a conversation
Tell us where the business is losing time, money or momentum.
We reply within one working day with an honest view — and if we can't help, who's better placed.