Security and compliance
10 ISO 27001 consultants
These ten ISO 27001 consultants help organizations build an information security management system (ISMS) and prepare for ISO 27001 certification, at consulting firms or through their own practices. A reader can learn how an experienced ISO 27001 consultant scopes an ISMS, runs the risk assessment and gets a company through its certification audit.
Professionals to explore
01—10Andy Brophy
LinkedInExperience: Principal Consultant and Co Founder · Inavate Consulting Ltd
Principal Consultant and Co Founder of Inavate Consulting Ltd since 2013, and Co-Founder of Red Island Consulting from 2001 to 2013. His profile says he has personally led over 200 ISO 27001 implementations worldwide and that Inavate Consulting works with organisations in more than 20 countries across the US, Europe, Asia and Australia.
David Vitic
LinkedInExperience: InfoSec Manager & ISO 27001 Lead Auditor Founder · ISMS Boutique
InfoSec Manager & ISO 27001 Lead Auditor Founder at ISMS Boutique since 2025, which his profile says offers ISO 27001 in 16 weeks and CISO advisory for tech companies, audit firms and energy utilities. He was Head of Tech-driven Audits & Assessments at Eraneos (2023–2025) and worked in Cyber & Digital Risk Consulting at KPMG Switzerland (2021–2022).
Deepak Varma
LinkedInExperience: ISO & GRC Consultant · VicByte IT Consultancy
ISO & GRC Consultant at VicByte IT Consultancy since 2024, leading ISO/IEC 27001 gap assessments for SMEs before certification audits and designing ISMS frameworks including risk registers, the Statement of Applicability and policies. He was Assistant Manager at Tata Steel (2018–2023) and Executive at Reliance Industries Limited (2013–2017).
Lee Kelvin
LinkedInExperience: Cyber Security Consultant ISO27001 ISO27701 ISO22301 IEC62443 · KPMG Taiwan
Cyber Security Consultant ISO27001 ISO27701 ISO22301 IEC62443 at KPMG Taiwan since 2023, covering ISMS planning and implementation and coaching customers through ISO 27001 third-party verification. He was Security Consultant Manager at BCCS (2019–2023) and IT Section Manager at FOXCONN EMEA (2002–2008).
Paulo Alexandre Porfirio
LinkedInExperience: President · ISO Consulting LLC
President of ISO Consulting LLC since 2011. He was an ISO 27001 Qualified Lead Auditor (2009–2012), BSI ISO 27001 qualified Tutor at BSI (2009–2012) and Information Security Consultant Auditor at Criterselect (2009–2012). His profile says he helps companies achieve ISO 27001 certification and cites more than 50 ISO 27001 implementations and more than 1,585 international audit days.
Paulo Buijs
LinkedInExperience: Senior GRC & Information Security Consultant vCISO ISO 27001 Lead Implementer · Security Consultants Ltd (OU)
Senior GRC & Information Security Consultant vCISO ISO 27001 Lead Implementer at Security Consultants Ltd (OU) since 2025, and founder of Security Office Online since 2021. He was Cybersecurity & ISO 27001 Consultant at Copilex (2024–2025) and Senior ISO 27001 Project Manager & Consultant at b-next AG (2022–2024). His headline lists ISO 27001, SOC 2, DORA and NIS2 work as a freelance consultant in the EU.
Shane Feeney
LinkedInExperience: Senior Information Security Consultant · Cemax Consulting
Senior Information Security Consultant at Cemax Consulting since 2010. His profile says he helps companies attain ISO27001 certification and advises on implementing best practices economically, has implemented several ISMS and guided companies to ISO27001, and lists expertise in ISO/IEC 27001, NIST 800-53 and 800-171, and the Australian Government ISM.
Stuart Rowson
LinkedInExperience: ISO 27001 Consultant · Wolf Info Sec Limited
ISO 27001 Consultant at Wolf Info Sec Limited since 2022, working self-employed as an ISO 27001 auditor, implementer and consultant for clients in the engineering and IT service industry. He has also been Audit Associate at NQA since 2025 and was Associate Auditor at BM TRADA Certification (2022–2025).
Tristan Roth
LinkedInExperience: Founder - ISO 27001 consultant and lead auditor · Better ISMS
Founder - ISO 27001 consultant and lead auditor at Better ISMS since 2023, supporting companies and startups in certification projects and providing outsourced internal audits. He was ISO 27001 manager and Risk Management specialist at Kantox (2022–2025), where his profile says he built the ISMS and the enterprise risk management program, and IT Risk and Cyber Consultant - GRC IT at BNP Paribas PF for eXalt (2019–2022).
Youri Biesmans
LinkedInExperience: Information Security Consultant ISO 27001 Implementation Coach · Toreon
Information Security Consultant ISO 27001 Implementation Coach at Toreon since 2014, and owner of BS Consulting BV since 2011. The profile also lists Information Security Consultant roles at Ministerie van Defensie (from 2020) and the Ministry of Foreign Affairs Belgium (2014–2020). His headline describes him as a CISO, ISO 27001 implementation coach and ISO 27001 internal auditor.
Choose the right perspective
Match the consultant's usual client to your organization, since a startup seeking its first certificate and a larger company adding frameworks such as SOC 2 or NIS2 need different support. Ask each person how many certification audits they have taken clients through and how they split work between their team and yours.
Questions to take into the conversation
- 01How do you scope an ISMS so that it covers what auditors expect without slowing down the business?
- 02What gaps do you most often find in a first ISO 27001 readiness assessment?
- 03How should a company prepare its staff and evidence for the Stage 1 and Stage 2 certification audits?
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal