ISO 27001 work as part of a security subscription
Secured by FM CyberSecurity combines security operations, advice and ISO 27001 preparation. Here is what to clarify when buying that work as a subscription.
The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.
ISO 27001 creates recurring work: access reviews, risk decisions, supplier assessments, internal audits and follow-up on findings. A subscription can give those tasks continuing ownership, provided the agreement is clear about what the provider does and what remains with the business.
Secured by FM CyberSecurity brings security operations, advice and ISO 27001 preparation into one offering for small and medium-sized businesses.
What the service brings together
The offering combines security tooling, vulnerability management, application security, a vCISO and work on the information security management system. FM’s own agentic SOC provides monitoring around the clock, built on CrowdStrike.
That SOC arrangement belongs to Secured. CrowdStrike Falcon Complete is a separate managed-response offering staffed by CrowdStrike.
For ISO 27001 preparation, the practical work includes defining scope, documenting how controls operate and organising evidence for assessment. The business still needs to approve policies, accept risks and provide the people who own its processes.
Keep preparation and certification separate
FM can support preparation. An independent certification body performs the certification assessment and makes its decision.
Agree readiness milestones against the actual starting point. A business that needs to introduce controls will have a different plan from one that already operates them and needs better records.
If a proposal includes a guarantee, read its written scope: the agreed window, customer obligations, exclusions and precisely which costs are covered if another attempt is needed. A commercial guarantee does not bind the certification body’s decision.
Look beyond the first audit
The agreement should explain what happens after certification. Who maintains the risk register? Who follows up an overdue review? How are significant system changes added to scope? What evidence is available for surveillance?
Also clarify ownership and access. The organisation should be able to retrieve its policies, records and findings, including at the end of the contract. A monthly price needs a clear list of included tools, services and external audit costs.
Use the cost guide to compare proposals. Choose a subscription because its responsibilities and ongoing work fit your business, with a management system your people can understand and operate.