glacierr
get in touch
typical engagement
scoped to you · fixed fee

service · 03iso/iec 27001:2022 aligned

cybersecurity policy framework development

clear requirements, written down.

We develop a tailored cybersecurity policy framework aligned to ISO/IEC 27001:2022 — setting clear security requirements, defining responsibilities and giving your security programme the documented governance it needs.

iso/iec 27001:2022 policy hierarchy named owners new or refresh fixed fee
▼
new

a framework built from scratch

update

a gap analysis and refresh of what you already have

27001

built on ISO/IEC 27001:2022 policy requirements

01what changes for you

what changes for you.

Requirements the business has agreed, owners who review them, and documents people can actually follow.

01

clear security requirements

What good looks like, written down and agreed across the business.

02

defined responsibilities

Named policy owners, approvers and review cycles.

03

stronger governance

A clear hierarchy linking policies, standards and procedures.

04

aligned to the standard

Mapped to ISO/IEC 27001:2022 to support compliance readiness.

05

tailored, not templated

Written for your organisation, risks and ways of working.

06

documents people use

Plain-English policies staff can follow — not shelfware for the auditor.

02what we typically find

written years ago. owners long gone.

Policies written years ago, copied from templates or scattered across SharePoint. Owners have moved on, requirements contradict each other, and the next audit exposes the gaps. Two routes in: build a new framework from scratch, or review and update the policies you already have.

43%
of UK businesses reported a breach or attack in the last 12 months
31%
have a board member responsible for cybersecurity
15%
formally review risks from immediate suppliers

03our approach

five stages, one framework.

Five stages, each with a gate you sign — from understanding your context to policies agreed and adopted. Senior consultants only.

01

understand your context

02

review what exists

03

design the framework

04

draft the policies

05

agree and adopt

04what you get

what you get.

Tailored to your route and scope.

05who it's for

who it's for.

ciso & security

A framework to govern the programme.

cio & it directors

Clear requirements for the teams that build.

head of infosec

Owned, reviewable policy documents.

risk leaders

Governance evidence for audit and assurance.

Sources: DSIT, Cyber Security Breaches Survey 2025/26 (30 April 2026).

shall we get on with it?

Scoped to your organisation, starting point and standards — fixed scope, fixed fee. A policy nobody can follow doesn't protect anyone.

also from glacierr.