Insights / Client Results

ISN: an ISO 27001 program aligned to the business, certified in eight months.
After certifying to ISO 9001, ISN wanted an ISO 27001 program that fit how the business actually runs. We designed the ISMS with them, coached the team through implementation, and stood by them through the certification audits. Certification landed in eight months.
At a glance.
Company
ISN
Dallas-based supply chain risk management software leader; platform ISNetworld® supports contractor and supplier management, performance benchmarking, and data insights.
Industry
Software: Supply Chain Risk Management
Identifying, assessing, and mitigating disruptions across contractor and supplier ecosystems.
Size
Large enterprise
550+ employees across four locations.
Condition, action, outcome.
The engagement moved in three steps: understand what ISN needed the program to do, design and coach the team through the ISMS, and stand alongside them through the external certification audits.
Condition: post ISO 9001, ISN needed a functionally lean ISO 27001 program aligned to best practices without the bloat of unnecessary regulations and processes. Action: Semper Sec ran a full program design session to establish process risk owners, align the business to the ISO 27001 Information Security Management System, and develop context and scope; then coached the team on ISMS program management and acted as an audit ally during the external certification audits. Outcome: ISN achieved ISO 27001 certification in eight months, on time and in budget, integrated with their existing ISO 9001 processes, with a flexible but managed framework the business runs without significant ongoing consultant help.
- ConditionPost ISO 9001, ISN needed a lean ISO 27001 program aligned to the business, not a bolt-on for the audit.
- ActionDesign the ISMS with the business: process risk owners, context and scope, and coaching through implementation and the certification audits.
- OutcomeISO 27001 certified in eight months, on time and in budget, integrated with ISO 9001, run by the business.
Condition.
ISN had already achieved ISO 9001 and knew they needed ISO 27001 next. The desired state was clear: a functionally lean information security management system aligned to best practices, without the bloat of unnecessary process. Just as important, ISN did not want to bolt a second program onto the business. They wanted an ISMS that shared operating discipline with the existing quality program and that the business could run without a permanent consulting bench.
Action.
Early in the engagement we ran a full program design session with ISN. Together we established process risk owners, aligned the business to the ISO 27001 ISMS, and developed the context and scope the program would operate against. From there we coached the team on ISMS program management week by week, using our crawl, walk, run approach to keep an intimidating standard tractable for the people who would live with it. During the external certification audits we stayed on the field with them as an audit ally, not a translator.
Outcome.
ISN certified to ISO 27001 in eight months, on time and in budget. The ISMS integrated with the existing ISO 9001 processes, and ISN gained a stronger contextual understanding of risk as the program went into steady-state operation. The team ended the engagement running the program themselves, with a flexible but managed framework and no need to retain a significant ongoing consulting footprint.
What changed for the business.
Certified in eight months, on time and in budget
ISO 27001 achieved without a schedule slip or budget escalation.
One integrated program
ISO 27001 processes integrated with the existing ISO 9001 quality program instead of running parallel to it.
Better contextual risk understanding
Risk decisions grounded in ISN’s own business context, not a generic control list.
Run by the business, not a consultant
A flexible but managed framework the team now operates without significant ongoing consultant help.
In comparison to other consultants, Semper Sec felt like a partnership the whole time, even during the audit. It felt like a collaboration throughout, versus being told what to do.
Belinda Field, Vice President, ISN
Related.
Service line
Build and Implement
Design the operating model, then stand up the controls, workflows, and adoption behind it.
Expertise
Frameworks & Regulations
The frameworks and standards, including ISO 27001, that shape unified GRC obligations.
Client Result
Crelate: ISO 27001 in six months, no new headcount
How a 50-person SaaS certified in six months while running a data center migration.
Start with the program, not the framework.
Talk with a senior advisor about the decisions, ownership, and operating capability your organization needs next.
A conversation with a senior practitioner, not a sales gatekeeper.