Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



ISO 27001 has become a default solution when it comes to demonstrating that an organisation takes information security seriously. An increasing number of organisations, clients and partners are requesting certification to strengthen supply chains and gain assurance that the businesses they work with are managing information security properly. It’s easy to see how this can start to look like something all organisations should have.
But, the common misconception is that every organisation needs—or should be working towards—ISO 27001 certification. Others believe that it automatically means their business is secure. In reality, it’s about building effective governance and risk management through a strong Information Security Management System (ISMS) and continually improving security over the long-term. The certificate is the evidence that this is all happening, not that it’s a problem solved.
This all might sound counter-intuitive coming from a consultancy that frequently does this kind of work, but we believe there’s more value in honest support that aligns with an organisation’s current maturity rather than defaulting to ISO 27001 because it's a widely known standard.
If you’re considering ISO 27001, read this article to make sure it’s the right fit for your business.
ISO 27001 delivers the most value when there is a clear and direct business need, such as:
Ultimately, the organisations that get the most out of ISO 27001 are the ones that see certification as an outcome, not the objective. The aim should always be to improve your organisation's actual security posture, with the certificate following as a result.
ISO 27001 isn't always the right place to begin, especially for small to medium-sized businesses who are early in their cyber security maturity. We believe that choosing the appropriate framework for where your organisation actually is today, rather than the one with the most name recognition, often produces a better security outcome and a better return on investment.
Alternatives to ISO 27001:
We always recommend taking a deep dive into why certification is being considered in the first place.
If you're expecting ISO 27001 to:
...then certification is likely not going to deliver what you're actually looking for. These are the expectations that tend to lead to disappointment further down the line, because the certificate alone doesn’t actually achieve those goals.
In these cases, working with a Trusted Advisor to guide you and help you understand what your organisation genuinely needs at your current maturity is often more valuable than pursuing a standard for its own sake.
Some useful questions you should ask before investing time, money and resources:

If you answered YES to most of these, ISO 27001 is likely to be the right choice.
If you need further help from an expert to figure out ifISO 27001 is right for your organisation, or would like guidance on the next move in your cyber security journey, get in touch with us.

"We're PCI compliant — our payment provider handles the security"This is a common misconception PGI hears from security and compliance teams, and it's a dangerous assumption in the world of e-commerce.

You have clients approaching you with a brief of what they want. What's the pattern you keep seeing?"Recently I’ve noticed that clients often come in with a clear idea of what they think they need: A specific framework, certification or service they've heard about.

Many organisations invest heavily in ISO 27001 and PCI DSS year after year — but few realise they may be paying for a scope that is larger, more complex, and more expensive than necessary.