// ISO 27001

ISO 27001 consultants — pragmatic certification, run as part of a Fractional CIO engagement.

The compliance capability inside our Fractional CIO practice. We stand up an ISMS you can actually operate, close gaps against Annex A, and get you through Stage 1 and Stage 2 audits without the theatre.

Sydney operating base · On-site across NSW · Remote across Australia

Outcomes

What you get out of it

  • A right-sized ISMS you’ll still be running two years after audit
  • A defensible Statement of Applicability
  • Risk assessment methodology mapped to real business risks
  • The Annex A control set implemented at the right depth
  • Internal audit and management review cadence that isn’t theatre
  • A clean run through Stage 1 and Stage 2 with your chosen CB
Engagements

How we work with you

01

ISO 27001 gap analysis

Structured review against ISO/IEC 27001:2022 clauses and Annex A. Output: a prioritised gap list with effort, owner and target date.

02

ISMS design & buildout

The full artefact set an assessor expects — scope, policy suite, risk methodology, SoA, procedures — sized to your organisation.

03

Risk assessment & treatment

A repeatable risk methodology that maps to real business risks, not a spreadsheet nobody reads. Includes treatment plans with owners.

04

Annex A control implementation

Practical implementation of the 93 Annex A controls at the depth your risk appetite justifies — no over-engineering.

05

Internal audit programme

A rolling internal audit calendar, competency-appropriate auditors, and management review cadence that actually surfaces issues.

06

Certification support

Certification body selection guidance, Stage 1 readiness, Stage 2 support and non-conformance response — through to certificate.

ISO 27001 control mapControl mapFCX-CM-02
ISO 27001 and ISO 42001 control map showing shared, AI-specific and information security controls with implementation status
ISO control map (FCX-CM-02) — ISO/IEC 27001 information security controls mapped against ISO/IEC 42001 AI management controls, with overlap and gaps marked.
Our edge

Why FORTE/CYBERx Advisory

Not another consulting firm. Former enterprise CIOs bringing operator-grade cyber and AI leadership to Australian SMEs.

01

One accountable CIO, not a panel

Cyber strategy, compliance and AI sit with one operator who has led technology inside banking, healthcare, higher education and government.

02

AI-ready, not AI-hyped

ISO 42001 practitioners. We secure the enterprise for AI before spinning up flashy tools. Frameworks first, tooling second.

03

Three capabilities, one programme

Cybersecurity strategy, ISO 27001 and ISO 42001 compliance, and AI consulting delivered as one plan with shared evidence and a single audit cycle.

04

Local, but not small

Sydney-based, delivering across NSW. On-site when it matters, remote-first when it does not.

05

Platform-augmented delivery

Every engagement includes FORTE/CYBERx platform access. Our consultants use it live in your board meetings — you keep using it after we leave.

Talk it through

Ready to scope this engagement?

Share the decision or constraint. A senior operator replies within one business day — no sales pod, no scripted discovery.

Native secure submission. Your details are never sold or shared.

Prefer to work independently?

Pressure-test the decision in the Platform.

Run two full decision analyses free, compare practical paths and create a Decision Record and Tactical Plan.

Try the Platform
Common questions

Frequently asked

How long does ISO 27001 take end-to-end?+

For a mid-sized SME with no prior ISMS, budget six to nine months from kickoff to Stage 2 audit. Faster is possible with an experienced internal team; slower is common when a business tries to do it in the background of everything else.

ISO/IEC 27001:2022 vs 2013 — what changed?+

Annex A was restructured from 114 controls into 93 across four themes (Organisational, People, Physical, Technological), and 11 controls are net new — including threat intelligence, cloud services, data leakage prevention and secure coding.

Do we need every Annex A control?+

No. The Statement of Applicability is where you justify which controls apply and why. A good SoA is defensible, not maximalist.

Can this run alongside ISO 42001?+

Yes, and it should. We run joint 27001 + 42001 programmes so shared evidence, controls and audit cycles reduce total overhead by 25–40 percent versus running them sequentially.

Which certification bodies do you work with?+

JAS-ANZ accredited CBs across Australia. We’ll match you to a CB whose auditors know your sector and whose commercial position fits your budget and timeline.

What if we’re only doing this because a client asked?+

Very common. We’ll shape the scope to the specific client requirement and design the ISMS so it can grow if commercial pressure demands wider coverage later — without a rebuild.

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.