Security Leadership
What Is ISO 27001? The Complete Business Leader’s Guide to Certification
ISO 27001 is the international standard for information security management. Here’s what it means in practice, what it costs, and what it gets you.
Get Expert AdviceCommon Misconceptions
The most common misconceptions about this role:
- A client or procurement team has asked for ISO 27001 certification.
- You don’t know what it involves, how long it takes, or what it costs.
Our Methodology
The ISO 27001 Certification Journey: 6 stages from gap assessment to certification, with timeline and cost guide.
What Starkhorn Brings
Daniel Jacobs: 20+ years in technology and security, 15+ of them in leadership roles. VetPartners (BC Partners, GBP1.2bn), Jardine Motors Group (GBP2bn). Published author. PRINCE2, ITIL, IIM Full Member. ISO 27001 advisory. Link to readiness assessment tool.
Starkhorn does not subcontract or use associate networks. You work directly with Daniel Jacobs from the first conversation through to delivery.
Who This Is For
This service is designed for:
- CEOs and operations directors at businesses with regulated or enterprise clients
This is not the right fit for: Businesses already ISO 27001 certified.
Frequently Asked Questions
What is an ISO 27001 gap analysis and why does my organisation need one?
ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). It sets out how to manage information security through governance, risk assessment and a set of controls, so that protection is deliberate and reviewed rather than ad hoc.
Is this tool an ISO 27001 audit or certification?
No. This is a free self-assessment based on your own answers. It gives you a readiness signal and highlights gaps. ISO 27001 certification is awarded only by an accredited certification body after a formal external audit. This tool cannot grant, guarantee or substitute for that.
What are the Annex A control themes?
ISO 27001:2022 groups its 93 Annex A controls into four themes: organisational (37 controls), people (8), physical (14) and technological (34). This tool covers all four, plus the governance and risk requirements from the standard’s main clauses.
How is my score calculated?
You answer 24 questions across six areas, each scored from 1 (weakest) to 4 (strongest). We normalise your total to a 0 to 100 scale, where all weakest answers score 0 and all strongest answers score 100. There is no hidden floor, so the score reflects your real answers.
What does a typical Starkhorn engagement cost?
Engagements are structured as monthly retainers or fixed-term day-rate assignments. The cost depends on scope and time commitment. We are transparent about pricing from the first conversation and will give you a clear indication on the call.
What experience does Starkhorn bring?
Starkhorn is led by Daniel Jacobs, with 20+ years in technology and security, 15+ of them in leadership roles. He has served as CIO, CISO, and interim technology director for organisations including VetPartners (BC Partners-backed, GBP1.2bn) and Jardine Motors Group (GBP2bn turnover). He holds PRINCE2, ITIL Foundation, and is a Full Member of the Institute of Interim Management.
Do I need a full-time CISO or will a virtual CISO suffice?
For most SMEs and PE-backed businesses, a virtual or fractional CISO provides everything a full-time hire would at a fraction of the cost. Unless your sector requires a dedicated CISO under regulation, a virtual arrangement is almost always the smarter choice.
What is the first step to working with Starkhorn?
Book a no-obligation conversation using the link on this page. In 30 minutes we will understand your situation, tell you honestly whether we are the right fit, and outline what a first engagement would look like. There is no sales process and no pressure.
Next step
Talk to a Senior Technology Leader
Starkhorn provides fractional CIO, CISO, and interim technology leadership for growing businesses. If you would like to understand whether this kind of support makes sense for your situation, book a no-obligation conversation.
Book a Conversation