01
Human context
A growing biotechnology company needs to move quickly while protecting sensitive data, keeping ownership clear and making every important control auditable.
02
Scope of responsibility
Operational ISMS implementation across infrastructure, cloud services, access control, secure development, continuity and governance.
03
Decisions
- Make ownership, access and risk decisions visible and understandable.
- Design controls around real workflows so security becomes part of how the company works.
- Build evidence and auditability into operations from the beginning.
04
Collaboration
Worked across management, science, product, operations, engineering and legal counsel to turn requirements into a usable and auditable system.
05
Implementation
Led the operational implementation and audit readiness of the ISO/IEC 27001:2022 certification process. Translated security, infrastructure, access control, secure development and governance into a practical ISMS connected to daily work.
06
Who it serves
Scientific, product, operations and engineering teams as well as the people who trust the organisation with health data.
07
Publicly describable outcome
Established transparent responsibilities, auditable processes and a shared security practice that supports reliable product delivery instead of slowing it down.
Good security is clear enough to use every day and strong enough to stand up to an audit.
