Security and compliance

10 ISO 27001 consultants

These ten ISO 27001 consultants help organizations build an information security management system (ISMS) and prepare for ISO 27001 certification, at consulting firms or through their own practices. A reader can learn how an experienced ISO 27001 consultant scopes an ISMS, runs the risk assessment and gets a company through its certification audit.

10 professionals10 companiesData retrieved September 29, 2026

Professionals to explore

01—10
  1. Andy Brophy

    LinkedIn

    Experience: Principal Consultant and Co Founder · Inavate Consulting Ltd

    Principal Consultant and Co Founder of Inavate Consulting Ltd since 2013, and Co-Founder of Red Island Consulting from 2001 to 2013. His profile says he has personally led over 200 ISO 27001 implementations worldwide and that Inavate Consulting works with organisations in more than 20 countries across the US, Europe, Asia and Australia.

  2. David Vitic

    LinkedIn

    Experience: InfoSec Manager & ISO 27001 Lead Auditor Founder · ISMS Boutique

    InfoSec Manager & ISO 27001 Lead Auditor Founder at ISMS Boutique since 2025, which his profile says offers ISO 27001 in 16 weeks and CISO advisory for tech companies, audit firms and energy utilities. He was Head of Tech-driven Audits & Assessments at Eraneos (2023–2025) and worked in Cyber & Digital Risk Consulting at KPMG Switzerland (2021–2022).

  3. Deepak Varma

    LinkedIn

    Experience: ISO & GRC Consultant · VicByte IT Consultancy

    ISO & GRC Consultant at VicByte IT Consultancy since 2024, leading ISO/IEC 27001 gap assessments for SMEs before certification audits and designing ISMS frameworks including risk registers, the Statement of Applicability and policies. He was Assistant Manager at Tata Steel (2018–2023) and Executive at Reliance Industries Limited (2013–2017).

  4. Lee Kelvin

    LinkedIn

    Experience: Cyber Security Consultant ISO27001 ISO27701 ISO22301 IEC62443 · KPMG Taiwan

    Cyber Security Consultant ISO27001 ISO27701 ISO22301 IEC62443 at KPMG Taiwan since 2023, covering ISMS planning and implementation and coaching customers through ISO 27001 third-party verification. He was Security Consultant Manager at BCCS (2019–2023) and IT Section Manager at FOXCONN EMEA (2002–2008).

  5. Paulo Alexandre Porfirio

    LinkedIn

    Experience: President · ISO Consulting LLC

    President of ISO Consulting LLC since 2011. He was an ISO 27001 Qualified Lead Auditor (2009–2012), BSI ISO 27001 qualified Tutor at BSI (2009–2012) and Information Security Consultant Auditor at Criterselect (2009–2012). His profile says he helps companies achieve ISO 27001 certification and cites more than 50 ISO 27001 implementations and more than 1,585 international audit days.

  6. Paulo Buijs

    LinkedIn

    Experience: Senior GRC & Information Security Consultant vCISO ISO 27001 Lead Implementer · Security Consultants Ltd (OU)

    Senior GRC & Information Security Consultant vCISO ISO 27001 Lead Implementer at Security Consultants Ltd (OU) since 2025, and founder of Security Office Online since 2021. He was Cybersecurity & ISO 27001 Consultant at Copilex (2024–2025) and Senior ISO 27001 Project Manager & Consultant at b-next AG (2022–2024). His headline lists ISO 27001, SOC 2, DORA and NIS2 work as a freelance consultant in the EU.

  7. Shane Feeney

    LinkedIn

    Experience: Senior Information Security Consultant · Cemax Consulting

    Senior Information Security Consultant at Cemax Consulting since 2010. His profile says he helps companies attain ISO27001 certification and advises on implementing best practices economically, has implemented several ISMS and guided companies to ISO27001, and lists expertise in ISO/IEC 27001, NIST 800-53 and 800-171, and the Australian Government ISM.

  8. Stuart Rowson

    LinkedIn

    Experience: ISO 27001 Consultant · Wolf Info Sec Limited

    ISO 27001 Consultant at Wolf Info Sec Limited since 2022, working self-employed as an ISO 27001 auditor, implementer and consultant for clients in the engineering and IT service industry. He has also been Audit Associate at NQA since 2025 and was Associate Auditor at BM TRADA Certification (2022–2025).

  9. Tristan Roth

    LinkedIn

    Experience: Founder - ISO 27001 consultant and lead auditor · Better ISMS

    Founder - ISO 27001 consultant and lead auditor at Better ISMS since 2023, supporting companies and startups in certification projects and providing outsourced internal audits. He was ISO 27001 manager and Risk Management specialist at Kantox (2022–2025), where his profile says he built the ISMS and the enterprise risk management program, and IT Risk and Cyber Consultant - GRC IT at BNP Paribas PF for eXalt (2019–2022).

  10. Youri Biesmans

    LinkedIn

    Experience: Information Security Consultant ISO 27001 Implementation Coach · Toreon

    Information Security Consultant ISO 27001 Implementation Coach at Toreon since 2014, and owner of BS Consulting BV since 2011. The profile also lists Information Security Consultant roles at Ministerie van Defensie (from 2020) and the Ministry of Foreign Affairs Belgium (2014–2020). His headline describes him as a CISO, ISO 27001 implementation coach and ISO 27001 internal auditor.

Choose the right perspective

Match the consultant's usual client to your organization, since a startup seeking its first certificate and a larger company adding frameworks such as SOC 2 or NIS2 need different support. Ask each person how many certification audits they have taken clients through and how they split work between their team and yours.

Questions to take into the conversation

  1. 01How do you scope an ISMS so that it covers what auditors expect without slowing down the business?
  2. 02What gaps do you most often find in a first ISO 27001 readiness assessment?
  3. 03How should a company prepare its staff and evidence for the Stage 1 and Stage 2 certification audits?

About this directory

This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.

Request a correction or removal

Other perspectives in Security and compliance