top of page
ChatGPT Image Sep 15, 2026, 04_44_31 PM.png

ISO 27001
Case Study

Find out how AKRUP worked with Orbus Software to implement an Information Security Management System aligned with ISO 27001, helping the team put the right processes, policies and controls in place and prepare for certification.

Project Overview

Orbus Software engaged AKRUP to support the implementation of an Information Security Management System (ISMS) aligned with ISO 27001.

We worked closely with the Orbus team throughout the project, helping them understand the requirements of the standard and turn those requirements into practical processes that worked within the business.

Our role covered the key areas needed to build the ISMS, including information security risk management, policies and procedures, security controls, roles and responsibilities, and preparation for the certification process.

The project ran between 2023 and 2024, with AKRUP supporting Orbus through the implementation of ISO 27001 and helping the organisation get ready for certification.

image.png

Project Duration: 2023-2024
Industry: Technology/Software
Framework: ISO 27001
Outcome: Successful ISO 27001 implementation and preparation for certification.

The Challenge

For a software company, information security is closely connected to everyday operations. Customer information, cloud environments, internal systems, suppliers and employees all need to be considered as part of the ISMS.

The challenge was therefore not simply to create the documents required by ISO 27001, but to make sure the requirements of the standard were properly understood and built into the way the business operated.

Orbus needed a structured approach for identifying and managing information security risks, clear policies and responsibilities, appropriate security controls and the evidence needed to demonstrate that these arrangements were working in practice.

AKRUP worked alongside the Orbus team to bring these different areas together into one structured ISMS and help prepare the organisation for certification.

Our Approach

We worked directly with the Orbus team throughout the implementation rather than simply handing over a set of ISO 27001 templates.

We started by looking at the organisation's existing security arrangements and identifying what was already working well and where additional processes, documentation or controls were needed.

From there, we worked through the requirements of ISO 27001 with the relevant teams, helping establish the ISMS, develop the required documentation, assess information security risks and make sure appropriate controls were in place.

A big part of our approach was keeping things practical. The aim was to build an ISMS that met ISO 27001 requirements without creating unnecessary processes that didn't make sense for the business.

As the project progressed, we also helped the team review the implementation, close remaining gaps and prepare the documentation and evidence required for the certification process.

What we delivered

ISMS Implementation

Worked with the Orbus team to build and implement an Information Security Management System aligned with ISO 27001 and suited to the way the organisation operated.

Risk Assessment

Helped identify and assess information security risks across the organisation and establish a structured process for managing those risks.

Security Controls

Reviewed existing security arrangements and worked with relevant teams to implement and improve the controls required to address identified risks and ISO 27001 requirements.

Policies & Documentation

Developed and reviewed the policies, procedures and supporting documentation required for the ISMS, making sure they reflected how Orbus actually worked rather than relying on generic templates.

Risk Treatment

Worked with the team to decide how identified risks should be treated and helped develop the Risk Treatment Plan and associated security controls.

Roles & Responsibilities

Helped establish clear information security responsibilities so that the people involved in operating the ISMS understood their role and what was expected of them.

ISMS Governance

Helped put the management and governance processes around the ISMS in place so information security risks, controls and actions could be reviewed and managed in a consistent way.

Gap Closure

Reviewed progress throughout the implementation and helped identify and address outstanding gaps before the organisation moved towards certification.

Implementation Support

Provided practical support throughout the project, working through questions and issues with the Orbus team as different parts of the ISMS were implemented.

External Audit Support

Supported the Orbus team throughout their ISO 27001 audits, helping with auditor questions, evidence requests and any issues that came up during the assessment.

Certification Preparation

Helped Orbus prepare for the ISO 27001 certification process by reviewing the ISMS, supporting the collection of evidence and making sure the organisation was ready to demonstrate how its information security processes worked in practice.

Project Outcome

Working with AKRUP, Orbus Software successfully implemented an Information Security Management System aligned with ISO 27001.

Rather than treating ISO 27001 as a documentation exercise, we worked with the Orbus team to put the processes behind the standard into practice and build an ISMS around the way the organisation actually operated.

By the end of the project, Orbus had:

  • An established Information Security Management System

  • A structured process for identifying and managing information security risks

  • Clearly defined information security policies and procedures

  • A Risk Treatment Plan for managing identified risks

  • Security controls aligned with the organisation's risks and ISO 27001 requirements

  • Clear information security roles and responsibilities

  • A more consistent approach to managing information security across the business

  • The documentation and evidence required to support ISO 27001 certification

The project ran from 2023 to 2024 and gave Orbus a structured information security framework that could continue to be managed and developed internally after the implementation was complete.

Why AKRUP?

AKRUP has built a proven track record of helping organisations achieve successful compliance outcomes across recognised security and assurance standards. With experience supporting clients worldwide, we understand what it takes to move from uncertainty to audit-ready confidence.

Our 100% project success rate reflects the quality of our delivery, the strength of our expertise and our commitment to getting results right the first time. Businesses choose AKRUP because we provide clear direction, practical guidance and reliable support that helps turn compliance into a competitive advantage.

What our clients say

Trusted by organisations across automotive, manufacturing and technology sectors.

ChatGPT Image Jun 10, 2026, 01_15_31 PM.png
"Very happy with the service recieved and the ongoing support"

Denzil Allen, Head of HSEQT

Rudolph and Hellmann

ChatGPT Image Jun 10, 2026, 01_39_52 PM_edited.png

Speak With Our Experts

Discuss your ISO 27001 requirements with one of our specialists. Complete the form below and we'll help you plan your route to successful ISO 27001 implementation.

Looking to achieve ISO 27001? Complete the form and one of our consultants will contact you to discuss your requirements and next steps.

bottom of page