Beyond the Checklist (Book)

Beyond the Checklist

Start with what matters. Build what works.

A practical guide to building an ISO 27001 management system that works in the real world, without unnecessary documentation, evidence chasing, or compliance theatre.


Stop “Doing ISO” and Start Running a Secure Business.

If you’ve ever felt like your Information Security Management System (ISMS) is just a second job, you’re not alone. For most UK-based MSPs, engineering firms, and tech businesses, the road to ISO 27001 certification is paved with endless spreadsheets, boilerplate policies, and a two-week “audit scramble” that leaves the team exhausted and the business no safer than before.

Beyond the Checklist is not another textbook. It is a field guide for the pragmatic leader who wants to turn compliance into a competitive advantage without the documentation bloat.

Whether you are implementing ISO 27001:2022 for the first time or trying to rescue a failing system, this book moves you away from “checklist thinking” and toward a living management system that actually works in the real world.

Inside, you’ll discover:

  • The Watercooler Method: A blueprint for embedding security into your company culture, moving from “willful blindness” to a team of active “security sensors.”
  • Why Every Team Needs a “Barry”: How your most difficult, skeptical employees are actually your best assets for pressure-testing your controls before an auditor does.
  • Proportionate Risk Management: Learn how to stop treating every control as equally important and focus your energy on what would actually hurt your business.
  • From Audit Panic to Operational Rhythm: How to break down the “Annual Review” into micro-reviews that keep you compliant 365 days a year.

Written for COOs, IT Managers, and Compliance Leads, this book provides the “operational signal” you need to cut through the noise of traditional consultancy. It’s time to stop managing an audit and start managing your risk.

Get the practical ISO 27001 implementation guide that turns certification into a formality and security into your business’s greatest strength.


Who This Book Is For

This book is written for:

  • MSPs
  • Engineering firms
  • Logistics businesses
  • Technology companies
  • Operational leaders
  • Compliance teams

Especially those who are:

  • Overwhelmed by ISO 27001 documentation
  • Struggling with evidence collection
  • Preparing for ISO 27001 certification
  • Trying to rescue a failing ISMS

What You’ll Learn

Evidence by Design

How to make operational systems generate evidence naturally instead of chasing screenshots before the audit.

Scope Without Chaos

How to define practical ISO 27001 scope boundaries without creating unnecessary overhead.

Security Culture That Actually Works

Why awareness training alone fails, and how operational behaviours create better security outcomes.

Proportionate Risk Management

How to stop treating every control equally and focus on what genuinely matters.

From Audit Panic to Operational Rhythm

How to replace annual compliance chaos with sustainable operational cadence.


This Is Not Another ISO Template Book

This book does not:

  • Provide generic policy packs
  • Encourage documentation theatre
  • Treat ISO 27001 as a tick-box exercise

Instead, it focuses on:

  • Operational maturity
  • Evidence generation
  • Maintainable systems
  • Practical implementation

Chapter 1

ISO Won’t Help With That… Or Will It…?

We start by addressing one of the biggest criticisms of ISO 27001 of those who have been through it. It explains how to overcome those objections. People are often thinking (if they don’t say it out loud): “It’s all very well, but it isn’t going to help me make sure payroll goes out on time.”

“It isn’t going to make sure my engineers are onsite with the right information.”

“It won’t stop everything grinding to a halt when Alex is off and nobody else knows how the process works.”

“It won’t help if I can’t connect to the system in a field in Northamptonshire with no signal.”

These reactions are reasonable but we need to address them, because when people are sceptical or disengaged, the implementation rarely gets more sophisticated; instead, it tends to drift. Policies and controls exist on paper but aren’t followed consistently and workarounds become normal.

What often follows is a sustained effort to police controls, a cottage industry of reporting emerges and employees constantly picked at by their managers for ‘not following policy’. Over time that creates resentment and impacts real work. At that point, the organisation has ISO 27001 paper, but the system isn’t working and may be undermining what the business is trying to achieve.

Confidentiality, Integrity and Availability (CIA)

One reason this disconnect happens is that many people still think information security is just about cybersecurity, firewalls, malware, phishing and keeping attackers out. Those things are important, but they’re only part of the picture. ISO 27001 is concerned with confidentiality, integrity, and availability. That means not just keeping information secret (confidentiality), but making sure it’s accurate, up to date (integrity), and available (availability) when the business needs it.

Once you look at it that way, far more everyday business processes fall inside the scope of the system, payroll, field work, scheduling, reporting, handovers, not because they’re “IT”, but because they rely on information working properly. In the first few sections, I’ll label the concepts, just to establish the thinking, if it’s not already clear.

Paperwork Alone Cannot Keep You Safe

Eventually, the audit approaches. That is when the scramble starts. People chase gaps, pull together evidence, and there’s a spike in activity, not to improve how things work, but simply to get through the audit. The activity increases, but control doesn’t.

If you want people to engage, you need a different approach. Don’t defend ISO; connect it to real work. If you do that, you won’t need to “sell” the standard. Connect it to something people already care about, and that’s when you’ll see engagement shift. Start with their concerns and show them how they might be able to reduce firefighting and sleep better at night by revealing the dependencies underneath their daily tasks.

This should be your core approach throughout the implementation and into the continuous improvement phase. If you have to keep explaining why ISO 27001 matters, is it because people aren’t connecting it to the work they do? They might not even realise how critical their work is to the organisation, can you use that to help people engage with the standard?

Payroll Isn’t Just Payroll

When someone says, “ISO 27001 isn’t going to help me get payroll out on time,” don’t argue. Walk them through it instead. Ask, “Okay, what does payroll depend on to work?”

Let them answer, or guide them if needed:

  • The right people having access (Availability and Confidentiality).
  • The data being accurate (Integrity).
  • Interfaces need to work (Availability).
  • The system being “up” (Availability).
  • Leavers being removed properly (Integrity).
  • Changes not breaking things (Integrity or Availability).
  • The provider doing what they are supposed to do (Integrity or Availability).
  • Someone knowing what to do when something goes wrong (Availability, of knowledge information).

Map out your processes.

Then say, “That is the bit ISO is interested in.” Now the conversation has changed. You are no longer talking about “doing ISO”; you are talking about what makes payroll reliable.

How Does This Approach Help Bring People Along?

What you are doing in these conversations is shifting how people see the work. You are moving them from thinking “this is compliance” to understanding “this is what makes us resilient.” That is the bridge. Once people see that connection, they understand that it isn’t about making life harder; it is an enabler that helps reduce rework and firefighting.

When you hear, “It won’t make sure my engineers are onsite with the right information,” walk the chain again. What does that depend on?

  • Accurate scheduling – complete and accurate data entry (Integrity)
  • Current drawings or job packs – access to up-to-date accurate documents (Integrity or Availability)
  • Changes being communicated – changes are effectively communicated and reflected in documents and activity (Integrity)
  • The field app working in real conditions – does it work offline? (Availability)
  • Devices working and syncing properly – change reflect when connectivity is re-established (Integrity or Availability)

Then say, “That is information management. That is availability. That is integrity.” You don’t need to recite clauses. You just need to show that what they care about already sits inside the system.

Reality Wins

This is exactly what ISO 27001 should surface when it is used properly. The questions that really matter are: What information and systems do we rely on? Is information available when it’s needed? Does the process hold up in real conditions? Is data captured reliably? Is there a fallback when things fail?

Risk

Now risks become real and not just ‘AI give me the top ten risks for UK MSPs’. You can ask:

What’s the risk that these required systems and information become inaccurate, unavailable or exposed to people who shouldn’t have access to them?

What can we do to prevent that failure or recover if it happens?

Why Do People Struggle With ISO 27001?

People don’t reject ISO because they are difficult. They reject it because they have seen poor implementations before. They associate it with admin rather than outcomes, and no one has ever connected it to the work they actually do. Making that connection is your opening. If you do it well, you won’t need to push.

How to Run the Conversation

  1. Start with the work: Don’t say “we need ISO 27001.” Start with, here’s the business process, let’s walk it through.
  2. Map the dependencies: Look at access, information, availability, suppliers, and recovery.
  3. Highlight the fragility: Identify where things break and what materially hurts the business when it does.
  4. Connect it back: Explain, “This is what we are trying to get control over.”

No slides. No clause recital. Just reality.

What Will Emerge

You aren’t just implementing ISO 27001; you’re building a better and more resilient organisation. You’re forming reliable operations, clear ownership and fewer hidden dependencies. You are improving recovery when things go wrong and reducing the number of “we didn’t realise it worked like that” moments. ISO 27001 is simply the structure that helps you do that consistently.

The One-Person System Example

Every organisation has a human lynchpin, the go-to person who knows everything. When you ask what would need to be in place to manage that person’s absence without the company grinding to a halt, you are in ISO territory. You are talking about knowledge management, cross-training, and reducing fragility. That is the management system doing its job.

How This Maps to ISO 27001:2022

Clauses

What This Means in Practice

Operational problems usually come down to information, access, availability, or dependency. ISO 27001 becomes useful when it is connected to those conditions. If it isn’t connected, it becomes bureaucracy.

Control Areas to Consider

Points for Leaders

  • If you already have ISO 27001 and still don’t feel any safer, treat that as a system signal, not a motivation problem.
  • The paperwork exists, but the real question is whether the controls are used and relied on day to day.
  • Look for drift. Where are exceptions normal? Where do people bypass the “official” way because it is slower or unclear? That is where your real exposure sits.
  • Use operational conversations to rebuild the map. Start with a real outcome, like employees being paid on time, and follow the chain of access and dependencies underneath it.
  • When someone says “ISO won’t help with that,” don’t argue. Use it as a prompt: “What does this depend on?” That question surfaces weak points faster than any policy review.
  • Treat your asset view as a by-product of dependency mapping, not a spreadsheet exercise. The list you uncover in real meetings will be more accurate than one built in isolation.
  • If you are implementing for the first time, do this earlier than you think. It prevents you from building a system that looks complete but never gets traction.

Continue reading…