
ISO 27001
Case Study
Find out how AKRUP worked with Orbus Software to implement an Information Security Management System aligned with ISO 27001, helping the team put the right processes, policies and controls in place and prepare for certification.
Project Overview
Orbus Software engaged AKRUP to support the implementation of an Information Security Management System (ISMS) aligned with ISO 27001.
We worked closely with the Orbus team throughout the project, helping them understand the requirements of the standard and turn those requirements into practical processes that worked within the business.
Our role covered the key areas needed to build the ISMS, including information security risk management, policies and procedures, security controls, roles and responsibilities, and preparation for the certification process.
The project ran between 2023 and 2024, with AKRUP supporting Orbus through the implementation of ISO 27001 and helping the organisation get ready for certification.

Project Duration: 2023-2024
Industry: Technology/Software
Framework: ISO 27001
Outcome: Successful ISO 27001 implementation and preparation for certification.
The Challenge
For a software company, information security is closely connected to everyday operations. Customer information, cloud environments, internal systems, suppliers and employees all need to be considered as part of the ISMS.
The challenge was therefore not simply to create the documents required by ISO 27001, but to make sure the requirements of the standard were properly understood and built into the way the business operated.
Orbus needed a structured approach for identifying and managing information security risks, clear policies and responsibilities, appropriate security controls and the evidence needed to demonstrate that these arrangements were working in practice.
AKRUP worked alongside the Orbus team to bring these different areas together into one structured ISMS and help prepare the organisation for certification.
Our Approach
We worked directly with the Orbus team throughout the implementation rather than simply handing over a set of ISO 27001 templates.
We started by looking at the organisation's existing security arrangements and identifying what was already working well and where additional processes, documentation or controls were needed.
From there, we worked through the requirements of ISO 27001 with the relevant teams, helping establish the ISMS, develop the required documentation, assess information security risks and make sure appropriate controls were in place.
A big part of our approach was keeping things practical. The aim was to build an ISMS that met ISO 27001 requirements without creating unnecessary processes that didn't make sense for the business.
As the project progressed, we also helped the team review the implementation, close remaining gaps and prepare the documentation and evidence required for the certification process.
What we delivered
ISMS Implementation
Worked with the Orbus team to build and implement an Information Security Management System aligned with ISO 27001 and suited to the way the organisation operated.
Risk Assessment
Helped identify and assess information security risks across the organisation and establish a structured process for managing those risks.
Security Controls
Reviewed existing security arrangements and worked with relevant teams to implement and improve the controls required to address identified risks and ISO 27001 requirements.
Policies & Documentation
Developed and reviewed the policies, procedures and supporting documentation required for the ISMS, making sure they reflected how Orbus actually worked rather than relying on generic templates.
Risk Treatment
Worked with the team to decide how identified risks should be treated and helped develop the Risk Treatment Plan and associated security controls.
Roles & Responsibilities
Helped establish clear information security responsibilities so that the people involved in operating the ISMS understood their role and what was expected of them.
ISMS Governance
Helped put the management and governance processes around the ISMS in place so information security risks, controls and actions could be reviewed and managed in a consistent way.
Gap Closure
Reviewed progress throughout the implementation and helped identify and address outstanding gaps before the organisation moved towards certification.
Implementation Support
Provided practical support throughout the project, working through questions and issues with the Orbus team as different parts of the ISMS were implemented.
External Audit Support
Supported the Orbus team throughout their ISO 27001 audits, helping with auditor questions, evidence requests and any issues that came up during the assessment.
Certification Preparation
Helped Orbus prepare for the ISO 27001 certification process by reviewing the ISMS, supporting the collection of evidence and making sure the organisation was ready to demonstrate how its information security processes worked in practice.
Project Outcome
Working with AKRUP, Orbus Software successfully implemented an Information Security Management System aligned with ISO 27001.
Rather than treating ISO 27001 as a documentation exercise, we worked with the Orbus team to put the processes behind the standard into practice and build an ISMS around the way the organisation actually operated.
By the end of the project, Orbus had:
-
An established Information Security Management System
-
A structured process for identifying and managing information security risks
-
Clearly defined information security policies and procedures
-
A Risk Treatment Plan for managing identified risks
-
Security controls aligned with the organisation's risks and ISO 27001 requirements
-
Clear information security roles and responsibilities
-
A more consistent approach to managing information security across the business
-
The documentation and evidence required to support ISO 27001 certification
The project ran from 2023 to 2024 and gave Orbus a structured information security framework that could continue to be managed and developed internally after the implementation was complete.

Why AKRUP?
AKRUP has built a proven track record of helping organisations achieve successful compliance outcomes across recognised security and assurance standards. With experience supporting clients worldwide, we understand what it takes to move from uncertainty to audit-ready confidence.
Our 100% project success rate reflects the quality of our delivery, the strength of our expertise and our commitment to getting results right the first time. Businesses choose AKRUP because we provide clear direction, practical guidance and reliable support that helps turn compliance into a competitive advantage.
What our clients say

Speak With Our Experts
Discuss your ISO 27001 requirements with one of our specialists. Complete the form below and we'll help you plan your route to successful ISO 27001 implementation.
Looking to achieve ISO 27001? Complete the form and one of our consultants will contact you to discuss your requirements and next steps.

