Skip to content
Skyie GlobalInfoTech
A woman examines documents, holding a pen over a table in a bright indoor setting.
Assurance

Security audits & ISO lead auditor services

Audits led by a certified ISO/IEC 27001 Lead Auditor — findings you can act on, evidence you can show.

An audit is only worth what you can do with it. Too many arrive as a spreadsheet of non-conformities with no sense of which ones would actually hurt, and no path to closing them.

Our assurance practice is led by a certified ISO/IEC 27001 Lead Auditor. We run gap analyses and readiness assessments against ISO/IEC 27001:2022, the internal audit programme the standard requires, second-party audits of your suppliers, Cyber Essentials and Cyber Essentials Plus readiness, and technical security testing. Every finding comes with a severity, a root cause and a remediation that a real team can deliver.

We also say plainly what we are not. We are not a UKAS-accredited certification body, and we do not issue ISO certificates. We get you ready for the certification audit, and we run the internal and supplier audits the standard requires — the certification decision belongs to an accredited body, which is exactly as it should be.

Capabilities

What we actually do.

ISO 27001 gap analysis & readiness

Your current position against ISO/IEC 27001:2022 clauses 4–10 and the 93 Annex A controls, with a prioritised route to a Stage 1 and Stage 2 certification audit.

ISMS internal audit programme

The internal audit programme clause 9.2 requires — planned, executed and reported by a Lead Auditor, with non-conformities, corrective actions and management review inputs.

Supplier & second-party audits

Audit your critical suppliers and processors against your own control bar, with a report you can put in front of a client, a regulator or an insurer.

Cyber Essentials & Cyber Essentials Plus readiness

The five technical controls assessed honestly, remediation scoped, and your estate prepared for the assessment rather than surprised by it.

Technical security testing

Vulnerability assessment, application and infrastructure penetration testing, cloud configuration review and secure-architecture review — findings ranked by real exploitability.

Policy, risk & Statement of Applicability

A risk methodology and register that survive scrutiny, an ISMS policy set people will follow, and a Statement of Applicability with justified inclusions and exclusions.

How we work

The shape of an engagement.

01

Scope

We agree the ISMS scope, the standard and the audit objectives, then confirm what evidence exists before we start — so the fieldwork is spent on findings, not on chasing documents.

02

Audit

Document review, control testing, interviews and technical verification. Findings are raised as we go, so nothing in the final report is a surprise on the day.

03

Report

Non-conformities and observations with severity, root cause, affected controls and a remediation plan — written for the team that has to fix it, with an executive summary for the board.

04

Close

Corrective actions tracked to closure, evidence verified, and a re-audit or management-review pack ready for your certification body.

Platforms & frameworks

What we work with.

Standards we audit against

  • ISO/IEC 27001:2022 & Annex A
  • ISO/IEC 27002:2022 control guidance
  • ISO/IEC 27701 privacy information management
  • ISO/IEC 42001 AI management systems
  • ISO 22301 business continuity
  • ISO 9001 quality management

Schemes & regimes

  • Cyber Essentials & Cyber Essentials Plus
  • SOC 2 readiness
  • UK GDPR & Data Protection Act 2018
  • NIS2 & DORA readiness
  • PCI DSS scoping support
  • NCSC Cyber Assessment Framework

Technical testing

  • Web & API penetration testing
  • Infrastructure & network testing
  • Cloud configuration review
  • Identity & access review
  • Secure architecture review
  • Phishing & social-engineering simulation

What you get

  • Gap analysis against ISO/IEC 27001:2022
  • Prioritised remediation plan with owners and effort
  • Internal audit reports and non-conformity register
  • Risk register and Statement of Applicability
  • Supplier audit reports you can share
  • Technical test reports with ranked, evidenced findings

Who we work with

  • Financial services & fintech
  • Legal & professional services
  • Healthcare & life sciences
  • Technology & SaaS
  • Recruitment & staffing
  • Public sector & not-for-profit

Not on the list? The constraint we design to is regulatory exposure, not sector — talk to us about yours.

Skyie Global is not a UKAS-accredited certification body and does not issue ISO certificates. We deliver readiness, internal audit and supplier audit services led by a certified ISO/IEC 27001 Lead Auditor; certification audits are carried out by an accredited certification body.

Common questions

Questions we get asked.

Can you certify us to ISO 27001?

No — and nobody who is also your consultant should. Certification is issued by a UKAS-accredited certification body after a Stage 1 and Stage 2 audit. We prepare you for it, run the internal audits the standard requires, and support you through the certification audit itself.

What is the difference between an internal audit and a gap analysis?

A gap analysis measures you against the standard before you have an ISMS, to plan the work. An internal audit is a recurring clause 9.2 requirement once the ISMS exists, testing that your own controls operate as documented.

How long does ISO 27001 readiness take?

For a small, well-run organisation with good engineering practice, typically three to six months from gap analysis to Stage 2. Larger or less mature estates take longer — the honest constraint is usually evidence history, since auditors want to see controls operating over time.

Do you test as well as audit?

Yes. Documentation audits alone miss real exposure, so we pair control testing with technical verification — vulnerability assessment, penetration testing and cloud configuration review — and reconcile the two in one report.

Related practices

Products that carry this

  • Trustiey

    Vendor trust and compliance posture, continuously evidenced.

  • Skyie Vault

    Encrypted document storage with keys that stay on UK soil.

  • Glancio

    Status and uptime monitoring with an audit trail you can show a regulator.

Ready when you are

Start with a conversation, not a proposal.

Thirty focused minutes. Tell us the problem and the constraints, and we will tell you honestly whether we are the right people for it.