The situation
Big organisations buy carefully. Before they sign, they send a security questionnaire, ask which certifications you hold, and want to know where their data lives and what happens when something breaks. A small company has to answer all of that with a fraction of the people a large one has.
This is the same cybersecurity awareness SaaS company as the platform rebuild, over the same seven years. Selling security awareness raised the bar further: our own security had to hold up to the scrutiny we were asking customers to apply to themselves.
What I did
I took the company through ISO 27001:2022 certification and kept it there. That meant policies people could actually follow, controls that matched how we worked rather than how a template assumed we worked, and evidence ready before an auditor or a buyer asked for it.
The CTO role went well beyond technology. Recruitment, budgets, operations, and board and investor communication all sat with me, and enterprise readiness touched every one of them. A buyer's questionnaire asks about people and suppliers, not only about encryption.
It also leaned on the platform itself. Zero downtime and 100% SLA adherence over three years made the uptime questions easy to answer honestly.
The result
- nonconformances across three ISO 27001:2022 audit cycles
- 0nonconformances across three ISO 27001:2022 audit cycles
- enterprise and public sector clients
- 200+enterprise and public sector clients
Zero nonconformances three times running is not luck. It comes from building controls into the way a company already works, so the audit checks what happens every day rather than what was tidied up the week before.
What it means for you
If a bigger customer has just sent you a security questionnaire, or asked whether you hold Cyber Essentials or ISO 27001, you are not behind. You are at the point where small companies either grow up or stall.
I help companies get ready for enterprise buyers: find the gaps, put in the minimum credible set of policies and controls, and answer questionnaires honestly. I prepare companies for certification. I am not a certification body, and I will not pretend an audit is a formality.
If you want to read first, start with what ISO 27001 involves for a small company or how to answer a supplier security questionnaire.