The $120,000 Lesson Brindlewood Logistics Learned at Surveillance
Maria Castellano took the Director of IT job at Brindlewood Logistics with one big item on her scorecard: get the company ISO 27001 certified before the fiscal year ended, because Brindlewood's largest customer — a national retailer worth roughly $2.3 million a year in freight brokerage revenue — had just added a certification requirement to its master services agreement renewal. Maria had never run an ISMS implementation before. She had eleven weeks of runway, a 180-person company with no security function to speak of, and a board that wanted a certificate, not a lecture on risk management theory.
So she did what a lot of first-time compliance owners do: she hired a well-reviewed boutique consultant, a solo practitioner named Tom Ferris who ran a firm called Ferris GRC Advisory. Tom was good. He wrote every policy from Brindlewood's information security policy down to its clear desk policy. He built the risk register, ran the risk assessment workshops himself with department heads, drafted the Statement of Applicability, prepared the internal audit, and coached the executive team through both certification audit stages. Five months after Maria signed the engagement letter, Brindlewood had its certificate, the retailer renewed the contract, and everyone moved on to the next fire.
Thirteen months later, the surveillance auditor showed up for the first annual check-in — and the wheels came off. The risk register hadn't been updated since the month of certification, because no one inside Brindlewood had ever actually run the risk assessment process themselves; Tom had run it for them. Two of the four named risk owners couldn't describe their own treatment plans when the auditor asked. A new cloud vendor Brindlewood had onboarded eight months earlier — a transportation management SaaS platform holding customer shipment and pricing data — had never been added to the Statement of Applicability or assessed as a supplier risk. Corrective actions from Brindlewood's own internal audit, conducted by an external contractor Tom had subcontracted, had never been tracked to closure because nobody owned that job once Tom's engagement ended.
The auditor issued two major nonconformities and gave Brindlewood ninety days to close them or risk suspension of the certificate — the same certificate underpinning the retailer contract. Maria re-hired Tom at a rush-rate premium, brought in a second consultant to run gap remediation in parallel, and put two internal staff on overtime for six weeks. By the time the dust settled, direct remediation spend, consulting fees, and the productivity cost of pulling four managers off their day jobs added up to just north of $120,000 — plus a tense sixty-day extension negotiated with the retailer's procurement team, who were not thrilled to learn their vendor's "certified" ISMS had been running on autopilot for over a year.
Nothing Tom Ferris did was wrong, exactly. He delivered a working ISMS and a passed certification audit, which is what he was hired to do. The failure was Brindlewood's: it outsourced not just the building of the ISMS but the understanding of it, and nobody planned for the day the consultant's contract ended. That gap — between "we got certified" and "we can sustain this" — is where a shocking number of ISO 27001 programs quietly die. I've watched it happen at logistics companies, SaaS startups, manufacturers, and law firms across fifteen-plus years of consulting engagements, and the pattern is always the same: the resourcing decision made in month one determines whether the ISMS is still alive in year three.
Who This Is For
This article is for the person who owns the decision of how to resource an ISO 27001 implementation — a founder, CISO, IT director, or compliance lead who hasn't yet committed to a model and wants a clear-eyed comparison before they sign anything. You'll walk away with a side-by-side comparison of the three realistic resourcing models (fully in-house, consultant-led or hybrid, and managed service or vCISO), a framework for matching the model to your organization's size, budget, and maturity, the one independence rule that trips up more companies than any control gap does, and a practical playbook for selecting, scoping, and managing a consultant so you don't end up as Brindlewood did. Whichever path fits your situation, the goal by the end is the same: a certified ISMS that your own people can run, defend, and improve without an outside vendor holding the only set of keys. If terms like ISMS, Statement of Applicability, or risk treatment plan are new to you, keep PentesterWorld's ISO 27001 glossary of terms open in another tab as you read — this article assumes you're already past the "what is ISO 27001" stage and focused specifically on the resourcing decision.
Three Ways to Resource an ISO 27001 Implementation
Every organization I've worked with ends up choosing from the same three basic models, whether or not they frame it that way at the outset. The labels vary — some people say "DIY," others say "co-sourced" — but the underlying trade-offs are consistent: how much internal capacity and expertise you have going in, how fast you need to move, how much budget you can commit, and how much you value building durable in-house capability versus buying a faster result. None of the three is objectively "better." All three can get you certified. The mistake I see most often isn't picking the "wrong" model in some absolute sense — it's picking a model that doesn't match the organization's actual capacity and then being surprised when it strains under that mismatch.
Model 1: Fully In-House Implementation
In the fully in-house model, your own employees do everything: gap analysis, policy writing, risk assessment, control implementation, internal audit, and audit liaison, using internal knowledge, published guidance, templates, and self-training rather than a paid outside implementer. Some organizations bring in a certification body only at the very end for the actual audits — which is unavoidable, since no organization certifies itself — but everything upstream of that is done by internal staff, sometimes with input from a single trainer course or a documentation toolkit.
This same three-way resourcing decision shows up almost identically in the SOC 2 readiness market, where organizations weigh in-house readiness work against consultant-led gap assessments — the underlying trade-offs of speed, cost, and internal ownership transfer directly across frameworks.
The upside is control and knowledge retention: the people who wrote the risk register are the same people who have to defend it eighteen months later, so there's no "where did this document come from" mystery at surveillance. It's also usually the cheapest option in direct fees, since you're not paying consulting day rates. The downside is equally real: someone on staff has to develop genuine ISO 27001 expertise from scratch, which takes time, and that person is usually doing this on top of an existing job. In-house programs I've seen take the longest to reach certification — commonly 9 to 18 months for a first-timer, compared to 4 to 9 months with experienced outside help — because the internal team is learning the standard, building templates, and making (and correcting) first-timer mistakes as they go, all in whatever hours are left over from their day jobs. It works well for organizations that already have someone with genuine information security or GRC background, that have the patience for a longer runway, and that place a high premium on total internal ownership. Whichever model you land on, a solid reference like PentesterWorld's Complete ISO 27001 Implementation Guide eBook is worth keeping on hand — teams going fully in-house lean on it heavily, and even consultant-led teams find it useful for sanity-checking a consultant's recommendations against the standard.
Model 2: Consultant-Led or Hybrid Implementation
The consultant-led (or hybrid) model is what Brindlewood used: an outside consultant or boutique advisory firm does some or most of the implementation work, working alongside a smaller internal team that provides subject-matter input, makes decisions, and — in a well-run hybrid engagement — does an increasing share of the hands-on work as the project matures. This is the most common model I encounter in mid-market companies, and for good reason: it combines outside expertise (someone who has actually built ISO 27001 risk registers and Statements of Applicability dozens of times before) with a realistic internal time commitment.
The speed advantage is real and significant. An experienced consultant has already made the mistakes your internal team would otherwise make for the first time — over-scoping the ISMS, writing a 40-page policy nobody will read, building a risk methodology so complex nobody can run it after year one. That experience compresses the timeline: I've run hybrid implementations from kickoff to Stage 2 certification in as little as four months for a well-prepared 60-person software company, versus the 12-plus months an internal team with no prior ISO experience often needs for the same scope. The financial cost is the trade-off — consulting fees for a mid-market hybrid engagement commonly run from $25,000 to $90,000-plus depending on scope, organization size, and how much of the work the consultant actually does versus advises on — and the knowledge-retention risk is the one Brindlewood ran into: if the consultant does too much of the thinking and too little of the teaching, the organization ends up with a certificate but not a capability.
Model 3: Managed Service, vCISO, or "ISO 27001-as-a-Service"
The third model has grown fast in the last several years: a managed service, virtual CISO (vCISO) arrangement, or a bundled "ISO 27001-as-a-service" offering, where an outside firm doesn't just implement the ISMS but continues running significant parts of it on an ongoing subscription or retainer basis — monitoring controls, maintaining the risk register, running internal audits, managing the GRC platform, and often providing a named person who functions as your outsourced security leader for audit and board purposes.
This model suits organizations that fundamentally don't have — and don't plan to build — a dedicated internal security or compliance function: a 40-person fintech that needs certification to close enterprise deals but has no appetite to hire a full-time compliance manager, for instance. It's also increasingly common among managed service providers and MSPs themselves, who often adopt an as-a-service model both for their own certification and as a bundled offering they resell to clients — a dynamic specific enough to warrant its own dedicated treatment (see "ISO 27001 for MSPs and IT Service Providers," a topic worth its own future article on this topic). The benefit is continuity: because the same firm that built the ISMS is also the one keeping it alive, you avoid the Brindlewood scenario where the builder walks away and takes the operating knowledge with them. The risk is a different flavor of dependency — instead of a one-time knowledge gap after a project ends, you have an ongoing structural reliance on a vendor for something increasingly core to how customers and auditors judge your trustworthiness. If that vendor relationship sours, gets acquired, raises its rates sharply, or simply loses the account manager who understood your environment, you can be left more exposed than a company that built (even slowly) its own muscle. It's also usually the highest ongoing cost of the three models, though it avoids a large one-time implementation spend.
"The question I ask every prospective client isn't 'can you afford a consultant' — it's 'what happens in your company eighteen months from now when the consultant's phone number doesn't work anymore.' If nobody can answer that, we're not ready to start." — Renata Aldous, Principal Consultant, Cascade Assurance Partners
Side-by-Side Comparison: All Three Models
No single model wins on every dimension, which is exactly why this decision deserves more thought than "let's just hire someone." The table below reflects patterns I've observed across dozens of engagements — treat the ratings as directional, not scientific, since every organization's starting point differs.
Table 1: Resourcing Model Comparison
Dimension | Fully In-House | Consultant-Led / Hybrid | Managed Service / vCISO |
|---|---|---|---|
Upfront cost | Lowest direct fees; highest internal time cost | Moderate to high one-time fee | Lower one-time cost; ongoing subscription/retainer |
Speed to certification | Slowest (typically 9–18 months for first-timers) | Fastest (often 4–9 months) | Fast to moderate (4–10 months), continues post-certification |
Control over process | Highest | High, shared with consultant | Moderate — vendor drives much of the operating cadence |
Access to specialist expertise | Lowest initially (must build it) | Highest — experienced practitioner from day one | High, but often generalist across many clients |
Internal knowledge retention | Highest by default | Depends entirely on engagement design | Lowest unless deliberately engineered |
Long-term sustainability (post-certification) | Strong if the team stays intact | Weak unless knowledge transfer is planned | Strong while the contract lasts; fragile if it ends |
Best suited to | Orgs with existing GRC/security talent and time | Mid-market orgs needing speed + expertise | Small orgs with no plan to build an internal function |
Biggest risk | Slow progress, reinventing the wheel, first-timer mistakes | Certificate without capability (the Brindlewood problem) | Structural vendor dependency |
Typical illustrative fee range* | $0 direct fees, but 0.3–0.75 FTE for 9–18 months | $25,000–$90,000+ one-time, scope-dependent | $2,000–$8,000+/month ongoing, plus a smaller setup fee |
*Illustrative figures for planning conversations only — get a scoped quote for your organization. For a fuller breakdown of where implementation money actually goes, see the realistic ISO 27001 budget breakdown, and run your own numbers through PentesterWorld's ISO 27001 Certification Cost Calculator before you commit to a model.
When Each Model Actually Fits
The comparison table tells you the trade-offs in the abstract. In practice, the right model is usually obvious once you're honest about three variables: how big and mature the organization is, how much budget is genuinely available, and how much internal appetite exists for owning security long-term versus treating it as a one-time project.
Table 2: Matching the Model to Your Situation
Organization Profile | Likely Best Fit | Why |
|---|---|---|
Startup (under ~25 employees), no dedicated security hire, investor or customer deadline | Consultant-led hybrid, tightly scoped | Speed matters more than internal muscle at this stage; see ISO 27001 for startups for a lean-scope approach |
Small business (25–100 employees), one IT/ops generalist wearing the compliance hat | Managed service / vCISO, or light-touch hybrid | Rarely enough spare capacity to run the ISMS unaided long-term; see ISO 27001 for small businesses |
Mid-market (100–500 employees) with an IT or risk function but no ISO experience | Consultant-led hybrid with explicit knowledge-transfer milestones | Best balance of speed and building internal capability |
Larger enterprise with existing security/GRC team, no prior ISO cert | Hybrid, consultant advisory only, most execution in-house | Internal team has the horsepower; needs expert guidance, not a builder |
Any organization that already holds a related certification (SOC 2, ISO 9001) | Lean in-house or light consultant advisory | Existing management-system muscle transfers well; see ISO 27001 vs SOC 2 vs NIST CSF for overlap |
Organization with high staff turnover in the compliance function | Managed service / vCISO | Continuity matters more than ownership when the internal seat keeps changing hands |
Highly regulated or high-risk-appetite industry needing deep customization | Fully in-house or consultant-advisory only | Off-the-shelf hybrid playbooks often under-fit specialized risk environments |
A pattern worth naming explicitly: budget is rarely the deciding factor I see companies think it is. The more common deciding factor is capacity — do you have someone who can spend real, protected hours each week on this for the next several months? Organizations that answer "sort of, when things are quiet" almost always regret picking the fully in-house model, because things are never quiet for long enough.
The Independence Rule: Your Consultant Cannot Be Your Certification Body
Here is the single most important compliance fact in this entire article, and it's one I see even experienced compliance leads get tripped up on: whoever helps you build your ISMS — writes your policies, designs your risk methodology, drafts your Statement of Applicability, or otherwise consults on the substance of your system — cannot also be the certification body that audits and certifies that same ISMS. This isn't a minor procurement preference. It's a foundational independence requirement that sits underneath the entire accredited certification ecosystem, and reputable certification bodies will not — and structurally cannot, if they want to keep their own accreditation — certify work they had a hand in consulting on.
The logic is straightforward once you see it: certification exists to give a third party — a customer, a regulator, a board, an insurer — confidence that an independent assessor looked at your ISMS and found it conformant. If the assessor also built the thing being assessed, that independence evaporates, and the certificate becomes worthless as an external signal. This is exactly why accredited certification bodies maintain strict boundaries between any advisory or implementation services they might separately offer (some larger firms do have consulting arms) and their certification/auditing arms — usually via separate legal entities, conflict-of-interest screening, and rules against a CB auditing an organization it consulted for within a defined look-back period.
What this means practically for your resourcing decision:
Your consultant helps you build the ISMS. A separate, accredited certification body audits and certifies it. These must be two different organizations (or, at minimum, fully firewalled divisions with no involvement by the same individuals).
Vet your certification body independently of your consultant's recommendation. A good consultant will often suggest a shortlist of CBs they've seen do solid, professional audits — that's fine and normal — but the final selection and contract should be yours, made with the same diligence you'd apply to any vendor. See how to choose an ISO 27001 certification body for the criteria that actually matter (accreditation, sector experience, auditor day rates, and reputation for consistency).
Ask any consultant directly whether they also offer certification services, and how they firewall the two. A reputable independent consultant will answer this without hesitation, because they already know the rule and structure their business around it. Hesitation or a vague answer is a warning sign, not a technicality.
This applies to internal implementations too, just differently expressed: if you build your ISMS in-house, the person leading internal audit still needs to be independent of the process being audited (Clause 9.2 requires this), and the certification body auditing you is, by definition, always a separate organization from your own staff.
I've seen organizations try to shortcut this — usually because a single vendor pitched a bundled "we'll build it and certify it, one convenient invoice" offer that sounded efficient. It is not efficient; it is a certificate that a sophisticated customer, auditor, or insurer can challenge, and one that a genuinely accredited body would refuse to issue under that arrangement in the first place. If you ever encounter a firm offering to do both for the same engagement, treat it as a disqualifying red flag and walk away, regardless of price.
"I turn away at least one prospective client a year who wants me to both build their ISMS and rubber-stamp the certificate. I tell them the same thing every time: if I did that, the certificate wouldn't mean anything, and neither would my accreditation." — Owen Marsh, Lead Auditor, Northfield Certification Body
How to Choose a Consultant (If You Go That Route)
Assuming you've decided a consultant-led, hybrid, or managed-service model fits your situation, the next decision — who you actually hire — matters as much as the model itself. I've seen excellent hybrid engagements and I've seen Brindlewood-style disasters, and the difference almost never comes down to the framework chosen. It comes down to who was in the room and what the contract actually asked them to deliver.
Selection Criteria That Actually Predict a Good Engagement
Credentials matter less than most buyers assume. A consultant with an impressive certificate wall who has never actually run a Stage 2 audit alongside a client is a worse bet than a less-decorated practitioner with ten completed certifications under their belt. Ask for references from organizations similar in size and industry to yours, and actually call them — ask specifically what happened at the first surveillance audit, not just at initial certification, since that's where knowledge-transfer failures like Brindlewood's show up.
Table 3: Consultant Selection Criteria
Criterion | What to Ask | Why It Matters |
|---|---|---|
Track record | How many ISO 27001 certifications have you led to completion, and in what industries? | Direct experience predicts fewer costly missteps |
Post-certification references | Can I speak to a client from at least 18 months ago, after their first surveillance audit? | Reveals whether their engagements survive past the certificate |
Independence from certification bodies | Do you offer certification services, or have a financial relationship with a CB? | Confirms compliance with the independence rule above |
Knowledge-transfer philosophy | How do you measure whether my team can run this without you? | Distinguishes builders who teach from builders who just build |
Scope clarity | Will you provide a written statement of work with named deliverables and hours? | Vague engagements are where scope creep and disappointment start |
Tooling neutrality | Are you tied to a specific GRC platform or vendor, and do you get a referral fee? | Undisclosed incentives distort tooling recommendations |
Communication cadence | What does a typical week of this engagement look like for my team? | Sets realistic expectations for internal time commitment |
Fee structure | Fixed fee, time-and-materials, or milestone-based? | Fixed/milestone fees align incentives better for defined-scope work |
Scoping the Engagement So Everyone Knows What "Done" Means
The single biggest source of consultant disputes I mediate isn't price — it's scope ambiguity. "Help us get certified" is not a scope; it's a wish. A well-scoped statement of work names the specific deliverables, who owns each one, and what "complete" looks like for each.
Table 4: Sample Engagement Scope Template
Workstream | Consultant Deliverable | Internal Team Deliverable | Joint Deliverable |
|---|---|---|---|
Scoping & context | Facilitates scoping workshop | Defines boundaries, provides org chart, business context | ISMS scope statement |
Gap analysis | Runs and documents the gap assessment | Provides access to existing controls/evidence, or runs a first pass using PentesterWorld's ISO 27001 Gap Analysis Tool before the consultant even starts | Prioritized gap report |
Risk assessment | Trains team on methodology, facilitates first cycle | Identifies assets, participates in workshops, owns risk register after handover | Risk register v1 |
Policies & procedures | Provides templates, reviews drafts | Writes first drafts using templates, owns final approval | Policy set aligned to ISO 27001 mandatory documents checklist |
Statement of Applicability | Advises on control applicability rationale | Makes final inclusion/exclusion decisions, documents justification | Completed SoA |
Internal audit | Trains internal auditor or performs first cycle | Nominates and trains an independent internal auditor for future cycles | Internal audit program |
Stage 1 & 2 audit prep | Mock audit, readiness review | Owns evidence organization, works through PentesterWorld's Certification Readiness Checklist independently, attends live audits | Audit-ready ISMS |
Knowledge transfer | Delivers structured handover sessions with sign-off | Assigns named ISMS owner(s), confirms understanding | Signed knowledge-transfer checklist |
Notice the pattern in the "Internal Team Deliverable" column: even in a heavily consultant-led engagement, your people should be doing something real in every single workstream, not just attending meetings. That's the difference between a hybrid engagement that builds capability and one that just outsources thinking with an internal audience.
Building Knowledge Transfer Into the Contract, Not Just the Intentions
Good intentions about knowledge transfer evaporate under deadline pressure unless they're written into the contract as deliverables with sign-off, the same way any other milestone would be. I now require this on every engagement I run, and I'd encourage you to require it of anyone you hire.
Table 5: Knowledge-Transfer Checklist to Put in the Contract
Item | Format | Owner After Handover |
|---|---|---|
Risk assessment methodology walkthrough | Live working session, recorded | Internal risk owner(s) |
Risk register maintenance training | Hands-on session updating a live entry | Internal ISMS manager |
SoA update process | Documented procedure + one supervised update cycle | Internal ISMS manager |
Internal audit training | Internal auditor shadows or co-leads one full audit cycle | Named internal auditor |
Document control process | Written procedure, access handover to document repository | Internal document controller |
Management review preparation | Template + one supervised prep cycle | Internal ISMS manager / leadership |
Surveillance audit prep | Written runbook for the next surveillance cycle | Internal ISMS manager |
Named points of contact for each control area | RACI matrix delivered as a final artifact | Department heads / control owners |
If a prospective consultant balks at putting any of this in writing, that tells you something important before you've paid a dollar. For a broader view of who inside your organization should be holding these roles regardless of resourcing model, see building an ISO 27001 project team.
Red Flags When Vetting a Consultant
Beyond the selection criteria above, certain behaviors during the sales process itself tell you a great deal about how the engagement will actually run. I've learned to treat these as near-disqualifying, regardless of how polished the proposal deck looks.
Table 5b: Consultant Red Flags
Red Flag | What It Usually Means |
|---|---|
Offers to "build and certify" you under one roof | Violates the independence rule; not a legitimate accredited pathway |
Can't name a single reference from 18+ months post-certification | Likely hasn't tracked (or doesn't want you to see) long-term outcomes |
Pushes a specific GRC platform hard, with no disclosed financial relationship | Possible undisclosed referral incentive distorting the recommendation |
Resists putting knowledge-transfer deliverables in the contract | Signals the engagement plan is "certificate first, capability optional" |
Quotes a price dramatically lower than every other bidder with no scope explanation | Often means far less hands-on work, or corners cut on documentation quality |
Can't clearly explain how they'd firewall consulting from certification if they offer both | Doesn't understand, or is minimizing, a foundational compliance requirement |
Proposes a single generic policy set with no tailoring workshop | Templates without context rarely survive contact with an actual auditor's questions |
Unwilling to name specific hours/deliverables per milestone | Scope will likely creep, and you'll have no contractual basis to push back |
Contractual Safeguards Worth Insisting On
A statement of work is not the same as a contract, and a surprising number of ISO 27001 consulting engagements run on the former without ever nailing down the latter's protections. Beyond price and deliverables, a handful of contractual terms consistently save clients real pain later: a defined knowledge-transfer milestone with a sign-off requirement (covered above), a data and documentation ownership clause confirming that all policies, registers, and records belong to your organization outright — not licensed from the consultant — even after the engagement ends, a termination-for-convenience clause with reasonable notice so you're not locked into an underperforming relationship, and, for managed-service or vCISO arrangements specifically, the exit-and-transition clause described in the Fenwick Cloud Storage case study, which turned what could have been a crisis into a routine vendor switch. None of these are exotic asks. Any consultant or managed-service provider operating professionally in this space will have handled these requests before and shouldn't need convincing.
Managing the Consultant Relationship Day to Day
Signing a good contract is necessary but not sufficient. The engagements that go well share a few operating habits that have nothing to do with the paperwork.
Assign a genuine internal owner from day one — not a passive point of contact who forwards emails, but someone with the authority to make scope decisions and the time to actually participate in workshops, review drafts, and push back when something doesn't fit the business. In every failed engagement I've reviewed after the fact, there was no such person, or the person nominally in that role was too junior or too busy to actually engage.
Hold a standing weekly or biweekly checkpoint for the life of the engagement, not just ad hoc calls when something's on fire. Use it to track a simple RAID log (risks, actions, issues, decisions) rather than a vague status update — it forces concreteness and creates a paper trail that's useful later if a dispute arises about what was agreed.
Insist on reviewing, not just receiving, every deliverable. If a consultant hands you a 60-page information security policy and nobody on your side reads it critically before it's adopted, you've just outsourced governance, not implementation support. Build in a real review cycle, even if it slows things down by a few days.
Track scope changes explicitly. Consulting engagements almost always expand in scope — a new business unit gets added, a client contract adds new requirements, someone discovers a control gap nobody anticipated. That's normal, but it should trigger an explicit conversation about fee and timeline impact, not silent absorption by either side (which breeds resentment and rushed work).
Keep a shared, living document of decisions and rationale — not just deliverables. Six months after a risk acceptance decision is made, nobody remembers the reasoning behind it unless it was written down at the time, and an auditor will ask "why" as often as "what." A simple decision log, updated at every checkpoint, becomes one of the most valuable artifacts of the entire engagement — arguably more valuable long-term than any individual policy document, because it's what lets your team defend decisions confidently at surveillance without the consultant in the room.
Table 6: Engagement Health Checkpoints
Checkpoint | Frequency | What "Healthy" Looks Like |
|---|---|---|
Scope vs. actual progress review | Biweekly | Deliverables tracking to the agreed statement of work |
Internal team engagement level | Biweekly | Named internal owners are producing drafts, not just attending |
Knowledge-transfer milestone check | Monthly | Contracted transfer sessions are happening on schedule, not deferred to "later" |
Budget/hours burn | Monthly | Spend tracking to plan; overruns flagged early, not discovered at invoice time |
Executive sponsor briefing | Monthly | Leadership sees real progress evidence, not just a green status light |
Avoiding Over-Reliance: Building Internal Capability Alongside Outside Help
The single biggest lesson from Brindlewood — and from every similar case I've seen since — is that outsourcing the implementation of an ISMS is entirely reasonable, but outsourcing the operation of it indefinitely, without a deliberate plan to build internal capability, is how certificates quietly rot between audits. An ISMS is not a one-time deliverable like a website redesign; it's a management system that has to run continuously — risk reviews, management reviews, internal audits, incident response, supplier reassessments — for as long as you hold the certificate, which for most organizations means indefinitely, through 3-year recertification cycles punctuated by annual surveillance audits.
Whatever resourcing model you choose, name a real internal ISMS owner before the project even starts, not after the consultant leaves. This doesn't need to be a full-time hire at a small organization — it's often a compliance-minded ops or IT manager who takes this on as 20-40% of their role — but it needs to be a named person with calendar time protected for it, not an unstaffed responsibility that theoretically belongs to "the IT department."
Build a simple internal capability roadmap that runs in parallel with the implementation project, so that by the time the consultant's engagement ends (or the managed-service contract renews for the first time), your own people have actually done — not just watched — each of the core recurring ISMS activities at least once.
Table 7: Internal Capability Roadmap
Recurring ISMS Activity | Month 1–3 | Month 4–8 | Month 9+ |
|---|---|---|---|
Risk assessment cycle | Internal staff observe/assist | Internal staff co-lead with consultant oversight | Internal staff lead independently |
Internal audit | Consultant or subcontractor leads | Internal auditor shadows and co-signs findings | Internal auditor leads, consultant reviews only if retained |
Statement of Applicability updates | Consultant drafts with rationale | Internal team proposes updates for review | Internal team owns updates end-to-end |
Management review | Consultant preps materials | Internal team preps with template, consultant reviews | Internal team runs independently |
Incident response tabletop | Consultant facilitates | Internal team co-facilitates | Internal team facilitates, consultant optional observer |
Supplier security reviews | Consultant provides methodology | Internal team applies it to existing suppliers | Internal team applies it to all new suppliers |
Even organizations that choose an ongoing managed-service or vCISO model should insist on some version of this roadmap — not because you plan to fire the vendor, but because a company that could run its own ISMS if it had to negotiates from a position of strength, and recovers faster if the vendor relationship ever ends unexpectedly (acquisition, rate hikes, an account manager departure, or a service-quality decline).
"I tell every client the same thing on day one: my job is to make myself unnecessary, not indispensable. If you still need me for the same things in year three that you needed me for in month three, I haven't done my job." — Devika Ranganathan, Founder, Meridian ISMS Advisory
Cost Considerations Across the Three Models
Cost comparisons for ISO 27001 resourcing are notoriously apples-to-oranges, because "fully in-house" costs show up as internal salary time rather than an invoice, which makes it look artificially cheap until you actually total the hours. The figures below are illustrative planning ranges drawn from typical mid-market engagement patterns, not a quote — your actual cost depends heavily on organization size, number of locations, cloud footprint, and how mature your existing documentation and controls already are. For a full breakdown of every cost category — certification body fees, internal labor, tooling, training, and gap remediation — see the realistic ISO 27001 implementation cost breakdown.
Table 8: Illustrative Total Cost of Ownership, First 18 Months
Cost Category | Fully In-House | Consultant-Led Hybrid | Managed Service / vCISO |
|---|---|---|---|
Direct consulting/advisory fees | $0–$5,000 (occasional advisory hours) | $25,000–$90,000+ | $10,000–$25,000 setup + ongoing retainer |
Internal labor (est. hours, blended cost) | 800–1,500 hours | 250–500 hours | 150–350 hours |
Training/certification courses for staff | $2,000–$8,000 | $1,000–$4,000 | $500–$2,000 |
GRC tooling/templates | $0–$6,000/year | $0–$6,000/year | Often bundled into retainer |
Certification body audit fees (Stage 1 + 2) | Same across all models — set by the CB, not the resourcing choice | Same | Same |
Ongoing annual cost (post-certification) | Lowest direct spend, but highest internal time draw | Low unless retainer renewed | Recurring retainer, typically $24,000–$96,000+/year |
The line worth internalizing: certification body audit fees don't change based on how you got there. A CB charges based on scope, headcount, and site count — not on whether a consultant helped you prepare. So the resourcing decision is really about how you pay (fees now vs. staff time vs. an ongoing subscription), not whether you pay for the audit itself.
The Hidden Costs Nobody Budgets For
Every resourcing model has a set of costs that don't show up on the initial proposal or budget line, and I've watched otherwise well-planned projects run over specifically because these were left out of the first conversation. Gap remediation is the biggest one: almost every organization's internal audit or Stage 1 audit surfaces at least a few control gaps nobody anticipated — a supplier contract missing a security clause, an access review that was never actually happening despite the policy saying it should — and closing those gaps takes real budget and time regardless of resourcing model. Tooling migration costs show up when an organization outgrows spreadsheets partway through the project and has to migrate a half-built risk register into a GRC platform. Staff backfill costs are real but almost never budgeted: if your named internal ISMS owner is spending 30% of their time on this project, someone is picking up the other work they used to do, and that has a cost even if it doesn't appear on the consulting invoice. And re-work costs from a rushed first attempt — a risk methodology so complex nobody can maintain it, a policy set copied from a template with no organizational tailoring — often cost more to fix than they would have cost to do properly the first time. Building a 10–15% contingency into whatever budget you set, across any of the three models, is not pessimism; it's just accounting for the version of this project that actually happens rather than the version on the proposal slide.
Timeline Comparison: What Each Model Looks Like Month by Month
Abstract cost and control comparisons are useful, but what most first-time buyers actually want to know is: what does my calendar look like under each option? The table below sketches a realistic month-by-month shape for a mid-market organization (roughly 100-150 employees, single primary location, moderate cloud footprint) under each model. Treat it as a planning template to adapt, not a guarantee — your scope, industry, and existing documentation maturity will shift these numbers in either direction.
Table 6b: Illustrative Month-by-Month Shape by Model
Phase | Fully In-House | Consultant-Led Hybrid | Managed Service / vCISO |
|---|---|---|---|
Months 1–2 | Scoping, initial training, template gathering | Scoping workshop, gap analysis, kickoff | Onboarding, scope agreement, initial gap analysis |
Months 3–5 | Policy drafting begins, risk methodology built (often revised once) | Risk assessment cycle, policy drafts reviewed jointly | Vendor builds core documentation with light internal review |
Months 6–9 | Risk assessment completed, first internal audit prep | Internal audit, Stage 1 audit, remediation | Internal audit and Stage 1 audit run by vendor with named internal sign-off |
Months 10–14 | Stage 1 audit, remediation, Stage 2 prep | Stage 2 audit, certification achieved | Stage 2 audit, certification achieved |
Months 15–18 | Stage 2 audit, certification achieved | Knowledge-transfer sessions, first surveillance prep | Ongoing management under retainer; first surveillance handled largely by vendor with internal co-sign |
Ongoing | Internal team runs all recurring activity | Internal team increasingly independent per capability roadmap | Vendor sustains operations under contract; internal capability roadmap runs in parallel if planned |
Note the shape difference: in-house and hybrid models converge on the same destination — a team capable of running the ISMS alone — just on different timelines, while the managed-service model deliberately keeps the vendor in the loop indefinitely unless you've built an internal capability roadmap alongside it, as recommended earlier in this article.
Industry Considerations That Shift the Calculus
The three-model framework holds across industries, but certain sectors tilt the decision in predictable ways worth naming explicitly.
Table 6c: Industry-Specific Resourcing Patterns
Industry Context | Common Pattern | Why |
|---|---|---|
Regulated financial services / fintech | Hybrid or managed service, with heavy compliance/legal involvement | Overlapping regulatory obligations (e.g., data protection, financial services rules) mean internal legal and compliance teams need deep involvement regardless of model; many of these firms are separately weighing PCI DSS QSA versus in-house assessment resourcing for the same reasons discussed here |
Healthcare and health tech | Hybrid, often with a specialist consultant familiar with health data handling | Domain-specific risk scenarios benefit from sector experience, though ISO 27001 itself is industry-agnostic |
SaaS / software vendors | Hybrid or managed service, frequently pursuing ISO 27001 and SOC 2 together | Overlapping evidence requirements make combined consultant expertise valuable; see ISO 27001 vs SOC 2 vs NIST CSF compared |
Manufacturing and industrial | Fully in-house more common | Often has existing quality-management (e.g., ISO 9001) culture and documentation discipline that transfers well |
Managed service providers / IT service providers | Managed service or hybrid, sometimes bundled with the provider's own client-facing security offering | MSPs frequently certify partly to strengthen their own market position, a nuance specific enough to warrant its own dedicated article (logged as a backlog topic above) |
Professional services (legal, consulting, accounting) | Hybrid, moderate scope | Typically simpler technical environments but high client-confidentiality expectations driving the initial demand |
None of these are hard rules — I've run successful fully in-house engagements in fintech and successful managed-service engagements in manufacturing — but they reflect where the internal capacity and existing documentation culture most often land by sector.
Governance: Who Signs Off, Regardless of Resourcing Model
One thing every one of the three models has in common: certain governance responsibilities cannot be delegated to an outside party no matter how the engagement is structured. Clause 5 of the standard places leadership commitment and accountability squarely with top management, and no consulting arrangement changes that. Mapping out who signs off on what — before the engagement starts — avoids the ambiguity that let Brindlewood's risk register drift unnoticed for ten months.
Table 6d: Governance Sign-Off Matrix (Illustrative)
Decision or Artifact | Consultant/Vendor Role | Internal Role (Cannot Be Delegated) |
|---|---|---|
ISMS scope statement | Advises | Top management approves |
Risk acceptance decisions | Recommends treatment options | Risk owner and top management accept residual risk |
Statement of Applicability | Drafts rationale | Top management (or delegate) formally approves |
Policy adoption | Drafts content | Top management signs and communicates |
Internal audit findings | May facilitate or execute | Management review process owns response and closure |
Corrective action closure | May recommend fixes | Named internal owner verifies and closes |
Management review | May prepare materials | Top management attends and makes decisions |
Final certification decision liaison | Advises on readiness | Organization's leadership authorizes proceeding to audit |
This table is worth pinning up next to whichever resourcing decision you make. It's also a useful gut-check during consultant vetting: if a proposal implies the consultant would be making risk acceptance or policy-approval decisions rather than just informing them, that's a scope problem worth raising before signing.
Common Mistakes Organizations Make With This Decision
Most of the mistakes below aren't exotic — they're the same handful of patterns showing up again and again across very different organizations, which is exactly why they're worth naming plainly rather than leaving to be rediscovered the hard way.
Table 9: Common Resourcing Mistakes and How to Avoid Them
Mistake | Why It Happens | How to Avoid It |
|---|---|---|
Hiring the cheapest consultant without checking post-certification outcomes | Price is easy to compare, sustainability isn't | Always call a reference from 18+ months post-certification |
Letting the consultant do 100% of the thinking | Feels faster in the short term | Contractually require internal participation in every workstream |
No named internal ISMS owner during the engagement | Assumed to be "IT's job" generally, owned by no one specifically | Name a person, protect their calendar time, put it in the project charter |
Choosing a managed service with no exit plan | Focus is on solving today's problem, not tomorrow's dependency | Ask the vendor directly: "if we left tomorrow, what would we need to take over?" |
Assuming a consultant can also certify you | Sounds convenient; misunderstands the independence requirement | Always contract certification separately with an accredited CB |
Under-scoping the statement of work ("just help us get certified") | Feels efficient to skip detailed scoping upfront | Use a deliverable-and-owner scope table before signing |
No budget held back for gap remediation after the first internal audit | Budgets are set assuming everything goes to plan | Reserve 10–15% contingency for the inevitable surprises |
Treating the ISMS as a project with an end date rather than an ongoing system | Certification feels like the finish line | Build the recurring-activity roadmap into the plan from day one |
Picking a resourcing model based on what a peer company did, not your own capacity | Social proof feels safer than an honest capacity assessment | Run the "who has protected hours each week" test before choosing |
A Decision Flow for Picking Your Resourcing Model
The diagram below lays out the decision path I actually walk clients through — starting with internal capacity and expertise, since that's the variable that predicts success or failure more reliably than budget alone.
flowchart TD
A[Start: Need ISO 27001 certification] --> B{Do you have staff with real<br/>GRC/security expertise and<br/>protected weekly time?}
B -- Yes, plenty of capacity --> C{Is speed to certification<br/>a hard deadline driver?}
C -- No, timeline is flexible --> D[Fully In-House]
C -- Yes, urgent deadline --> E[Hybrid: Consultant Advisory Only]
B -- Some capacity, but limited experience --> F{Do you want to build<br/>lasting internal capability?}
F -- Yes --> G[Consultant-Led Hybrid<br/>with contracted knowledge transfer]
F -- Not a priority right now --> H{Do you have budget for<br/>an ongoing retainer?}
H -- Yes --> I[Managed Service / vCISO]
H -- No --> G
B -- Little to no internal capacity --> H
D --> J[Certify with an independent,<br/>accredited certification body]
E --> J
G --> J
I --> J
J --> K[Sustain via internal capability<br/>roadmap regardless of model]Whichever branch you land on, notice the flow always ends at the same two steps: certify through an independent accredited body, and sustain the ISMS through a deliberate internal capability plan. The resourcing model changes the path, not the destination.
Building a Business Case for Whichever Model You Choose
Whatever model you land on, you'll likely need to justify the spend to a budget-holder who isn't as close to the day-to-day trade-offs as you are. The strongest business cases I've seen frame the decision in terms leadership already cares about — revenue enablement, deal-cycle speed, and risk exposure — rather than compliance mechanics.
Tie the ask to a concrete business driver wherever one exists: a specific customer contract or RFP requirement, a target market where certification is table stakes, an insurance premium consideration, or a competitive gap versus certified rivals. Quantify the cost of not certifying, or of certifying too slowly, alongside the cost of the resourcing model itself — a stalled enterprise deal worth six or seven figures makes a $60,000 consulting engagement look like the obviously cheaper option, but that comparison only lands if you make it explicitly rather than assuming leadership will infer it.
Table 6e: Framing the Ask by Audience
Audience | What They Care About | How to Frame the Resourcing Decision |
|---|---|---|
CEO / Board | Revenue impact, risk exposure, competitive position | "This unlocks/protects $X in contract value; here's the fastest responsible path" |
CFO | Total cost, budget predictability, ROI timeline | Side-by-side of one-time fee vs. ongoing retainer vs. internal labor cost (Table 8) |
Sales / Customer Success leadership | Deal-cycle speed, ability to answer security questionnaires | Timeline comparison (Table 6b) and what "certified" unlocks in active deals |
Engineering / Operations leadership | Disruption to existing workload, realistic time ask | Internal capability roadmap (Table 7) showing exactly what's asked of their team and when |
Existing IT/security staff | Whether this becomes "their job" indefinitely, career growth | Clarity on named ownership and long-term role, not just project-phase tasks |
A business case that only talks about audit fees and consulting rates tends to get bounced back with budget objections. A business case that ties the resourcing decision to a specific revenue or risk outcome, with the model comparison as supporting detail, tends to get approved on the first pass — because the resourcing question stops looking like a compliance line item and starts looking like the strategic lever it actually is.
Case Studies: Three Companies, Three Models, Three Outcomes
Case Study 1: The Hybrid Done Right — Corvane Analytics
Corvane Analytics, a 90-person data analytics vendor, needed ISO 27001 to win a $1.4 million enterprise contract with a healthcare client. Rather than repeating Brindlewood's mistake, its VP of Engineering insisted on the deliverable-and-owner scope table approach with its chosen consultant, and made knowledge transfer a contracted milestone with sign-off, not a verbal promise. The consultant led the first risk assessment cycle but had two internal engineers co-facilitate it; by the second cycle, six months later, the internal engineers ran it themselves with the consultant only reviewing outputs. Corvane reached Stage 2 certification in six months at a consulting cost of roughly $52,000. Eighteen months later, at its first surveillance audit, the same internal team that had built the risk register defended it without the consultant present, closed one minor nonconformity within two weeks, and renewed the enterprise contract on schedule. Total incremental cost of building internal capability during the engagement: roughly $6,000 in extra consulting hours for co-facilitation. Total cost avoided by not needing a Brindlewood-style rescue: unquantifiable, but comfortably in six figures based on comparable remediation cases.
Case Study 2: The Managed Service That Worked — Fenwick Cloud Storage
Fenwick Cloud Storage, a 35-person SaaS startup with no dedicated security hire, chose a managed-service/vCISO arrangement rather than a one-time consultant engagement, reasoning correctly that it had neither the headcount nor the near-term intention to build an internal compliance function. The vendor built the ISMS, provided a named vCISO for board and audit purposes, and — critically, because Fenwick's leadership had read enough horror stories to ask the right question upfront — contracted an explicit "exit runbook" clause: if Fenwick ever terminated the retainer, the vendor was obligated to deliver a full documentation handover and a two-week transition-training period at no extra cost. Fenwick certified in five months, paid roughly $14,000 in setup fees plus a $3,200/month retainer, and two years later, when the vendor was acquired by a larger firm and account management quality dipped, Fenwick invoked the exit clause, brought on a part-time internal compliance contractor, and transitioned with minimal disruption — a foreseeable event they'd priced into the original contract rather than discovering the hard way.
Case Study 3: The In-House Slog That Still Paid Off — Halloway Precision Manufacturing
Halloway Precision Manufacturing, a 210-person industrial parts manufacturer, decided against outside help entirely, partly on principle and partly because its newly hired IT security manager, hired six months earlier from a larger regulated manufacturer, had prior hands-on ISO 27001 experience from a previous employer. The implementation took fourteen months — longer than a hybrid engagement would have taken — and included several detours, including a risk methodology rewrite three months in after the first version proved too cumbersome for department heads to use. But because every document, every risk entry, and every control decision was made by people still employed at Halloway a year later, the first surveillance audit surfaced zero major nonconformities and only one minor observation about evidence retention timing. Total direct cost: roughly $9,000 in training and tooling, against an estimated 1,100 internal hours — expensive in time, cheap in dollars, and durable in outcome.
Table 10: Case Study Outcomes at a Glance
Company | Model | Time to Certification | Direct Cost (Illustrative) | First Surveillance Outcome |
|---|---|---|---|---|
Brindlewood Logistics | Consultant-led (no transfer plan) | 5 months | ~$40,000 initial + ~$68,000 remediation | 2 major nonconformities, near-loss of $2.3M contract |
Corvane Analytics | Hybrid with contracted knowledge transfer | 6 months | ~$52,000 + ~$6,000 transfer premium | Clean, 1 minor nonconformity, self-defended |
Fenwick Cloud Storage | Managed service / vCISO with exit clause | 5 months | ~$14,000 setup + $3,200/month | Clean; later transitioned vendors smoothly |
Halloway Precision Manufacturing | Fully in-house (experienced hire) | 14 months | ~$9,000 + ~1,100 internal hours | Clean, zero major nonconformities |
The throughline across all four companies — including Brindlewood's cautionary tale — isn't which model they picked. It's whether they planned, from day one, for who would run the ISMS after the initial push to certification ended. The three that planned for it succeeded regardless of model. The one that didn't paid for it at the worst possible moment: the first time an independent auditor came back to check.
"Certification day is not the finish line — it's the day the real test starts. Anyone can pass a Stage 2 audit with enough consulting help. Passing your third surveillance audit with the same people who were there on day one is the actual proof the system works." — Callum Ebersole, Head of Information Security, Fenwick Cloud Storage
Signs You Need Outside Help (and Signs You Probably Don't)
Not every organization needs the same answer, and I'd rather talk a prospective client out of hiring me than watch them overpay for expertise they don't need — or, worse, under-resource a project that was always going to need outside help.
You probably need a consultant or managed service if: nobody on staff has ever seen an ISO 27001 risk register or Statement of Applicability before; you have a hard external deadline (a customer contract, an investor requirement, a regulatory expectation) inside twelve months; your team is already at capacity on its existing workload with no slack for a multi-month side project; or you've tried a self-led gap analysis already and found the exercise more confusing than clarifying.
You can probably go fully in-house if: someone on staff has led an ISO 27001, SOC 2, or comparable management-system implementation before, even at a different employer; your timeline has real flexibility (12+ months); your organization is small and simple enough in scope that the standard's requirements map cleanly onto what you already do; and leadership is willing to protect real weekly hours for the effort rather than treating it as an unstaffed background task.
Table 11: Quick Self-Assessment
Question | If Mostly "Yes" | If Mostly "No" |
|---|---|---|
Does anyone in-house have hands-on ISO 27001 experience? | Lean in-house or light advisory | Lean hybrid or managed service |
Is there a hard deadline under 9 months? | Lean hybrid (speed) | In-house is more viable |
Is there protected weekly capacity for months, not just "when things are quiet"? | In-house or hybrid can work | Managed service reduces the capacity burden |
Does leadership want to build a long-term internal security function? | Any model works if capability-building is planned in | Managed service may fit better long-term |
Is budget for a one-time fee more available than ongoing subscription budget? | Hybrid (one-time fee) fits better | Managed service (retainer) fits better |
Running through PentesterWorld's "Is Your Organization ISO 27001 Ready?" quiz alongside this table is a useful gut-check before you commit budget in either direction — it takes ten minutes and often surfaces a gap in the self-assessment above that's easy to miss when you're close to the project.
The Strategic Opportunity Hiding Inside This Decision
It's easy to treat the "how do we resource this" question as a pure cost-and-logistics problem to get out of the way before the "real" work of implementation starts. I'd push back on that framing. How you resource ISO 27001 shapes what the certificate actually represents to your customers, your board, and your own team for years afterward. A certificate backed by genuine internal capability is a durable competitive asset — it lets you answer a prospect's security questionnaire with confidence instead of panic, walk into a surveillance audit without dread, and expand your ISMS scope to new products or subsidiaries without starting from zero. A certificate backed only by an outside consultant's memory is a liability wearing a compliance badge, and it tends to get discovered at the worst possible moment, the way Brindlewood discovered it — in front of an auditor, with a major customer contract on the line.
The good news is that none of the three models is inherently the "risky" one. Fully in-house, hybrid, and managed-service engagements have all produced both durable, well-run ISMSs and Brindlewood-style near-misses in my experience. What separates the good outcomes from the bad ones isn't the org chart of who did the work — it's whether the organization treated knowledge retention and sustainability as a first-class requirement from the day the project started, not an afterthought to be figured out once the certificate was already framed on the wall. Build that requirement into your model selection, your contract, and your internal accountability from week one, and the resourcing question stops being a risk and starts being a genuine strategic lever — one that compresses your sales cycles, opens doors to enterprise and regulated customers, and gives your security program a seat at the table that outlasts any single vendor relationship.
If you're still weighing which of these three paths fits your organization, PentesterWorld's Implementation Roadmap walks through the milestones any of the three models needs to hit, and our team can help you scope a gap analysis, vet consultant proposals, or sanity-check a managed-service contract before you sign — whatever stage of this decision you're at, reach out and let's talk through it before you commit a budget line to a model that doesn't fit your actual capacity.
