Information Security & Governance Consulting

Cyber Governance.
Risk Clarity.
Compliance Confidence.

SMUP helps regulated, growing and high-trust organisations design, implement and improve information security governance, ISO 27001 programmes, risk frameworks, data protection controls and business continuity capability.

For businesses that need security to be credible, auditable and commercially useful.

ISO 27001:2022 · IRCA Lead Auditor · GDPR Practitioner
ISO 27001
GRC
GDPR
Risk Management
Business Continuity
FCA-Regulated
Third-Party Risk

Security governance built for organisations that cannot afford uncertainty.

SMUP provides senior-led information security, governance, risk and compliance advisory for organisations that need more than box-ticking. We help leadership teams create practical, auditable and commercially aligned security programmes that stand up to client scrutiny, regulatory pressure and board-level expectations.

10+ Years Experience
ISO 27001:2022
IRCA Certified
GDPR Practitioner

Built for organisations
where trust matters.

Regulated Environments

Deep experience within FCA-regulated, NHS, central government and professional services environments where information security obligations carry real consequence.

Board Scrutiny

We communicate at board level. Security governance that speaks the language of leadership — risk, accountability, commercial impact and strategic resilience.

Audit Readiness

Every deliverable is designed for scrutiny. Certification body, client, regulator or internal audit — SMUP builds programmes that hold up under examination.

Operational Resilience

Business continuity, disaster recovery and resilience frameworks that move beyond documentation to build genuine organisational capability.

Governance Maturity

From first-time certification to mature programme optimisation — SMUP meets organisations at their level and builds towards genuinely sustainable governance.

"We combine technical understanding with strategic advisory — helping clients move from fragmented controls and audit pressure to structured, confident and resilient security governance."
Speak to SMUP

A complete advisory capability,
from governance to assurance.

ISO 27001 Internal Audits

Independent internal audit support to verify conformity, identify gaps and maintain your ISMS between certification cycles.

Enquire

Virtual CISO

Fractional CISO services for boards, executives and regulated businesses that need strategic oversight without the overhead.

Enquire

GRC Transformation

Strategic governance, risk and compliance transformation aligning security practice to business objectives and regulatory expectation.

Enquire

Cybersecurity Governance

Board-level governance frameworks that give clarity to risk decisions, oversight and accountability across your organisation.

Enquire

Risk Management

Structured risk assessment, treatment planning and risk registers designed for practical use, not just compliance documentation.

Enquire

Third-Party Risk Management

Supplier due diligence, vendor risk assessments and third-party assurance frameworks meeting client and certification requirements.

Enquire

GDPR & Data Protection

Practical UK GDPR compliance — privacy notices, ROPAs, DPIAs, data subject rights processes and breach response frameworks.

Enquire

Business Continuity & DR

Business impact analysis, continuity planning and disaster recovery frameworks aligned to ISO 22301 principles.

Enquire

Security Policies & Frameworks

Complete information security policy suites written in plain language and aligned to international standards.

Enquire

Regulatory Readiness

Pre-assessment readiness reviews and remediation for FCA, NIS2, DORA and evolving regulatory frameworks.

Enquire

Audit Support

Stage 1 and 2 audit support, evidence preparation, management review facilitation and post-audit remediation planning.

Enquire

Built for
high-trust environments.

SMUP works alongside organisations where security credibility, regulatory compliance and audit readiness are not optional.

Hedge Funds

Discreet, board-level advisory for alternative investment managers navigating FCA obligations and investor due diligence.

Financial Services

ISO 27001 and GRC programmes aligned to FCA expectations, PRA requirements and operational resilience obligations.

FCA-Regulated Firms

Security governance frameworks purpose-built for firms operating under FCA authorisation and regulatory scrutiny.

Professional Services

Law firms, accountancies and advisory businesses where client data protection and certification credibility are essential.

SMEs

Proportionate security governance for growing businesses needing certification to win clients and enter new markets.

Enterprise Organisations

Complex, multi-entity governance programmes for large organisations with demanding compliance portfolios.

India-Based Corporates

UK and international ISO 27001 implementation for Indian corporates establishing governance for global expansion.

GCC / UAE Markets

Advisory for organisations navigating NESA, PDPL, DIFC and international standards requirements.

Calm expertise.
Practical governance.
Audit-ready outcomes.

We believe security governance should be clear, structured and commercially useful — not alarming, not technical theatre. Just reliable, evidence-based practice that gives your organisation genuine confidence.

Book a Consultation
Senior-led advisory

Every engagement is led by experienced, certified professionals.

Board-ready communication

Security translated into clear, confident language for leadership teams.

Clear documentation

Policies and evidence that are readable, usable and audit-ready from day one.

Practical implementation

Trusted implementation partners working alongside your team.

Audit-focused evidence

Deliverables designed to stand up to scrutiny from certification bodies and clients.

Risk-based decision making

Security decisions anchored to real organisational risk, not generic checklists.

Commercially aligned controls

Controls proportionate to your risk profile.

Human, approachable delivery

We build relationships, not just documents.

A clear path from uncertainty
to assurance.

Assess

Comprehensive gap analysis identifying where you are and what is needed to reach your target.

Design

Structured project plan with clear milestones, ownership and timelines designed around your business.

Implement

Building, documenting and embedding controls and policies that are practical and usable.

Evidence

Organising documentary evidence to demonstrate conformity and effectiveness to any auditor.

Assure

Internal audit and certification support giving leadership genuine confidence.

Improve

Post-certification continual improvement maintaining the value of your programme long-term.

IRCA Lead Auditor
ISO 27001:2022
GDPR Certified

Advisory with purpose,
built on principle.

SMUP was created to make information security, governance and compliance clearer, calmer and more valuable for modern organisations. We combine technical understanding with strategic advisory, helping clients move from fragmented controls and audit pressure to structured, confident and resilient security governance.

After more than a decade working across multinational enterprises and industry, our founder recognised a gap between compliance theatre and genuine security value. SMUP exists to close that gap — delivering advisory that is practical, human and commercially grounded.

Our name carries meaning. SMUP was inspired by our founder's daughter — whose innocent determination became the foundation of the values that guide everything we do: humility, fairness, honesty, care and hard work.

Organisations we have had the privilege of working with

Thought leadership for
security-conscious organisations.

ISO 27001

What Boards Really Need From ISO 27001

Certification is not the goal — confidence is. How forward-thinking boards are using ISO 27001 to create genuine competitive and commercial advantage.

Read More
GRC

Why GRC Fails When It Becomes Too Technical

Most GRC programmes stall not because of a lack of effort, but because they become divorced from business reality. How to keep governance grounded.

Read More
Audit Readiness

How To Prepare For A Client Security Review

Security questionnaires and client due diligence reviews are now routine. How to prepare your evidence, documentation and responses with confidence.

Read More

Build confidence before the next audit, client review or regulatory challenge.

Speak to SMUP about strengthening your security governance, ISO 27001 readiness, risk management and resilience programme.

07902 296 888 SMUP Ltd on LinkedIn
London, England, United Kingdom