Webinar

11:00 am
|
Wednesday
|
24
June
2026

We will highlight five essential ‘must dos’ that consistently distinguish organisations that simply meet ISO 27001 requirements from those that use them to strengthen performance and resilience.

Read more
USB stick, Padlock, Keys
Webinar

11:00 am
|
Wednesday
|
8
July
2026

Many PRPs remain uncertain of what STAIRs will mean in practice when this new statutory framework comes into effect.  The impact is expected to be highly significant. This session will set out the practical steps PRPs can take now to get ready for these new Requirements.  

Read more
USB stick, Padlock, Keys
Webinar

11:00 am
|
Wednesday
|
15
July
2026

This session will show you exactly what assessors look for, where organisations commonly fall short, and how to position your submission for a smooth, successful outcome.

Read more
USB stick, Padlock, Keys
Find out more events
Neil Jones
|
Senior Consultant at URM
|
Published on
05
June
2026

URM’s blog breaks down how to effectively implement ISO 42001, where it differs from other ISO standards, and the common certification pitfalls to avoid

Read more
Cyber Security
Published on
21/5/2026
Understanding Defence Cyber Certification (DCC)

URM’s blog explains how the DCC works, who needs it, the benefits of certification, with clear guidance on how to approach compliance and avoid common mistakes.

Cyber Security
Published on
21/5/2026
Cyber Security and the Board: The UK Cyber Resilience Pledge in Focus

URM’s blog explains the purpose, structure and content of the Government’s new Cyber Resilience Pledge, and what it means for organisations across the UK.

Artificial Intelligence
Published on
8/5/2026
Artificial Intelligence Frameworks and Regulations: ISO 42001, the NIST AI RMF and the EU AI Act

URM’s blog explores 3 leading AI governance frameworks and regulations, how they complement and differ & what they mean for organisations working with AI.

Find out more blogs
InfoSec Insider
Season
2
, Episode
38
(
88
)

Business Approaches to Risk Management

In this episode of InfoSec Insider, Wayne Armstrong and Chris Heighes, both Senior Consultants at URM, offer key advice on effective approaches to cyber and information security risk management from a business perspective.  Chris and Wayne draw upon their combined 45 years of experience in information security and risk management to discuss:

  • What good, risk-based decision-making actually looks like in practice, and where it most commonly breaks down
  • The most concerning information security risks of today that do not get enough attention at the board or executive level
  • How organisations can move away from checklist-driven compliance and towards meaningful cyber risk management that supports business objectives
  • How organisations should rethink ownership and accountability for information security risk in light of growing dependence on cloud services and third-party providers
  • The capability or mindset they believe information security leaders must develop now to remain effective risk advisers in the coming years.

Listen to the episode
Find out more podcasts
|

By completing the quiz, you will gain a clearer understanding of how organisations prepare for, respond to, and recover from disruption, and why business continuity is a shared responsibility rather than a purely technical or specialist function.

Take the quiz
Find out more quizzes

ISO 27001 FAQs

How long does it take to implement ISO 27001?

There is no straightforward answer to this question as it depends on the size and complexity of your organisation, what systems and processes are already in place and what resources are available.  However, in URM’s experience it typically takes between 6 and 9 months for a small, low complexity organisation to fully implement ISO 27001.  

With larger, more complex environments, 9 to 18 months is closer to the norm for fully establishing an ISMS. This naturally assumes that the appropriate resources are made available to achieve the desired outcomes.

Apart from the existing maturity of operational practices and controls and availability of in-house resource, another key determinant in how long an ISO 27001 implementation will take place will be the support and involvement of senior management.  URM has seen organisations achieve very aggressive timescales in implementing and achieving ISO 27001 certification where Senior Management has prioritised the project, often associated with being awarded a significant client project.

Is there a legal requirement to comply with or be certified to ISO 27001?

There is, generally, no direct legal requirement for compliance as such, indicating why many people choose to use the word conformance rather than compliance.  Organisations choose whether or not to implement the requirements of ISO 27001 based upon the benefits that would be gained by doing so. However, you should pay close attention to any contractual obligations you may have for protecting the information of clients and other stakeholders.  

There is an increasing trend where customers require third party suppliers to implement or certify to ISO 27001, thus making it a legal requirement, by virtue of a contract.

What does ISO 27001 require you to do?

A key requirement of ISO 27001 is that you adopt a risk-based approach when implementing your ISMS.  You are also required to ensure that certain processes are in place to ensure effective and proactive management and continuous improvement.  

These requirements are broken down into 7 major clauses, which deal with context of the organisation, leadership, planning, support, operation, performance evaluation and improvement.  These clauses are consistent with other ISO Management system standards such as ISO 9001 and ISO 22301, and is known as the harmonised structure.

When was ISO 27001 last updated?

The current version of the Standard, ISO/IEC 27001:2022 replaced the 2013 version of the Standard on 25 October 2022.  As of 1 May 2024, all initial and recertification assessments must be conducted against ISO 27001:2022 and, on 31 October 2025, all ISO 27001:2013 certificates will be withdrawn.  Whilst the management system clauses received a relatively minor makeover in order to harmonize ISO 27001 with other standards, the information security controls contained within Annex A were completely restructured with some controls being merged with others as well as 11 new ones being introduced.

Read more
Find out more FAQs
Release date:
17
April
2026

In this document, we outline the key changes to Cyber Essentials and Cyber Essentials Plus scheme and what they mean for you as applicants.

Read more
Find out more white papers
Course type: 
Online
Introduction to ISO 42001
DATE:
24
June 2026
-
24
June 2026
Location:

One-day Course provides essential guidance to organisations embarking on an Artificial Intelligence (AI) journey.

Register
USB stick, Padlock, Keys
Course type: 
Online
PCIRM
DATE:
14
September 2026
-
21
September 2026
Location:

All you need to know about the information risk management, conducting risk assessments and developing risk treatment plans.

Register
USB stick, Padlock, Keys
Scheduled courses
Having been involved in over 450 successful ISO 27001 certifications, URM Consulting Services (URM) is ideally placed to advise you on the essential activities and tasks you will need to carry out in order to maintain and improve your ISO 27001 auditing function and programme.
Find out more
"
URM's diligence during these audits has resulted in the business as a whole pulling together to collectively ensure that we up to par with the requirements. While our working relationship with URM’s consultant is fantastic, we are held to account for every bullet point of every requirement on every audit, which is precisely what we expect.
Open Banking Platform
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.