ISO 27001 consultant in Newcastle upon Tyne

Newcastle, Gateshead and North Tyneside are 20 minutes from our Durham office, so on-site workshops are straightforward. You get a practitioner in the room for the sessions that need it, a live management system in your own workspace, and support through stage 1 and stage 2.

What we do for Newcastle upon Tyne organisations

On-site or remote gap analysis

A clause-by-clause and Annex A assessment against ISO/IEC 27001:2022, delivered at your office or over video, with a phased plan and named owners.

Risk assessment run with your team

A working risk register built in session — assets, threats, treatments and owners — not a template left for you to interpret.

Policies and Statement of Applicability

AI-assisted drafting reviewed line by line, so wording reflects how your organisation actually operates rather than a generic pack.

Internal audit and management review

Clauses 9.2 and 9.3 run properly before the certification body arrives, with findings closed and evidence verified.

Stage 1 and stage 2 attendance

Preparation sessions, evidence rehearsal and someone alongside your team during the certification assessment.

The platform after handover

Risks, controls, owners and evidence stay in your own workspace, so surveillance year one is maintenance rather than another project.

Local scope and coverage

Our office is at Portland House, Belmont Business Park, Belmont, Durham DH1 1TW. Newcastle is a 20-minute drive or a 15-minute train from Durham, so on-site kick-off, risk workshops and audit days are booked without travel charges.

  • Newcastle upon Tyne city centre and Quayside
  • Gateshead and Team Valley
  • North Tyneside, Wallsend and Cobalt Park
  • Sunderland and Washington
  • Northumberland and Cramlington
  • Remote across the rest of the UK

Prefer to talk first? Call +44 7876 191172 or use the contact page.

Regional work we have delivered

Client names are withheld under NDA; these are anonymised summaries of engagements in the North East.

SaaS scale-up, Newcastle

ISO 27001:2022 achieved ahead of an enterprise procurement deadline, with Microsoft 365 and Entra evidence collected automatically instead of by screenshot.

Managed service provider, Gateshead

Client-facing Trust Centre published alongside certification, cutting inbound security questionnaire effort by roughly half.

Engineering firm, Tyne and Wear

ISO 27001 integrated with an existing ISO 9001 system so one internal audit programme and one management review cover both standards.

Other standards supported locally

Working outside the North East? Remote ISO consultancy covers the rest of the UK on the same methodology.

Free ISO 27001 readiness assessment for Newcastle upon Tyne organisations

Instant download, no sales call. We reply within one business day.

Answers buyers, procurement and auditors want

Are you actually based in Newcastle?+

Our office is in Durham, about 20 minutes away, and Newcastle upon Tyne is a core service area. On-site kick-off, risk workshops, internal audit fieldwork and stage 2 attendance are all delivered in person across Tyne and Wear at no travel cost.

What does an ISO 27001 consultant in Newcastle cost?+

Consultancy is quoted per phase — gap analysis, implementation, assurance and certification support — rather than by day, so you can see what each stage costs. Certification body fees are separate and typically £4,000 to £9,000 across the three-year cycle for an organisation under 50 people.

How quickly can we certify?+

Three to four months to stage 1 is realistic where reasonable practice already exists; six months is typical from a standing start. Deadlines driven by tenders or enterprise procurement are usually the reason clients come to us, and we plan backwards from them.

Do you work with the region's tech and digital sector?+

Yes — most of our regional work is with software, managed services and professional-services firms, which is also where the platform's Microsoft 365, Entra, Intune and Defender evidence automation saves the most time.

Can you support SOC 2 as well as ISO 27001?+

We build the control set against ISO 27001:2022 Annex A and map it to the SOC 2 Trust Services Criteria, so a single evidence base serves both. The attestation itself is issued by a licensed CPA firm.

Is remote delivery an option instead?+

Entirely. Certification bodies assess your management system, not how it was built, and remote audits are routine. Many Newcastle clients mix an on-site kick-off with remote fortnightly sessions.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.