Our expertise
Our services
Who we serve
Insights
About us
Digital Threat Digest Insights Careers Let's talk

The questions your information security consultant should be asking you

We sat down with one of our Senior Information Security Consultants to talk about why it's valuable to challenge the client brief and what it really means to act as a Trusted Advisor.

SMSSC
Samuel Middleton, Senior Security Consultant
Double circle designs6
You have clients approaching you with a brief of what they want. What's the pattern you keep seeing?

"Recently I’ve noticed that clients often come in with a clear idea of what they think they need: A specific framework, certification or service they've heard about. And as a consultant, it would be easy to just blindly run with that. The brief is already set, the client seems confident and then it’s my job to explain how I can fulfil that need, sometimes with little scope to move outside of what they’ve asked for.

What I've found is that what a client says they want and what they actually need aren't always the same thing. If you don't take the time to probe it and understand the real business context, you risk delivering something that solves the wrong problem, or creates new problems later."

Can you give an example of that in practice?

"I was recently on a client call discussing how we could support them on their ISO 27001 certification journey. During the call, the client asked: “do you think a business like ours actually needs this?”.

This led to a much more valuable conversation that became a feasibility assessment."

What does a feasibility assessment involve?

"The aim was to understand why they thought they needed ISO 27001, identify who was driving that Information Security requirement, any issues they foresee in becoming ISO compliance and what they were trying to achieve. 
This then allowed me to tell them what their scope would actually look like in reality – and to flesh it out, learn about their business; including locations, people, systems, and functions. 

From these conversations, I could then map out what their compliance roadmap should look like."

So, the feasibility assessment becomes the starting point rather than jumping straight into delivery?

"Exactly. And whilst this example still focuses on a specific framework, what I'm actually doing is working with the client as a ‘Trusted Advisor’. I'm putting myself in a position to learn about the business to truly identify gaps and ways I can support them in a cost-effective way.

If I sell someone something they don't need or don't want to follow through on long term, that becomes a blocker to delivery. As an advisor, I can identify solutions based on what they actually need. This could be simplifying scope, identifying issues they didn't know they had or flagging services they'd never considered.

Most clients appreciate someone who pushes back thoughtfully rather than just saying yes straight away. It builds trust quickly and it usually results in a more honest and realistic conversation about what they're actually trying to achieve."

What's your advice for clients when choosing a security partner?

"Don't just look for a partner who is capable. Look for someone who:

  • Asks probing questions upfront
  • Challenges your assumptions about what you need
  • Takes the time to understand your business before they start pitching solutions


This is where the role of a Trusted Advisor really becomes valuable. Taking that time upfront leads to better decisions, a clearer scope and outcomes that are far more likely to stick long term. And it means the work we do together is shaped into a realistic and deliverable solution."

Samuel Middleton is a Senior Security Consultant at PGI, specialising in compliance and information security advisory. To find out how PGI can support your organisation with your objectives, get in touch with us.