Business Idea - Sanity check

Faust Security

Free Member
Jan 12, 2023
6
0
Hi all,

So I finally, after months of deliberation and research, got my business registered as a limited company.

I wanted to do a sanity check with those who own businesses outside of my own field in regards to my idea.

My research, plus 4 years experience working in small organisations wanting to get ISO certified, is that a lot of companies, especially smaller companies, struggle to get compliant with ISO27001, in that it takes them a long time to get all the nessecary documents/procedures written and then onto the certification audit due to either resource constraints or time constraints.

My idea is to, in effect, introduce "ISO in a box", which contains all the required (and relevant) documents plus a detailed description on how best to implement them, and offer it for sale as my main product, so an organisation can buy it, modify the policies and procedures to best fit their organisation and then go onto certification (with required evidence) and thus save them time in having to write everything from scratch.

As well as this, the ISO27001 standard has now changed from 2013 to 2022, with that it introduces a raft of new controls which have never been seen before. So my secondary idea was also to sell documents individually for those organisations who are transitioning from the 2013 to 2022 standard.

In short;

1. "ISO in a box" for organisations who are completely new and need a hand getting started

2. Individual documents for sale to help companies who are transitioning from the 2013 to 2022 standard.

I know there are other companies which sell documents directly, but I feel as though my unique aspect is that the documents I've written also come with detailed guides on best implementation rather than "This is what the control needs".

Apologies for the long post, I wanted to make sure I had everything in one post.
 

Faust Security

Free Member
Jan 12, 2023
6
0
Hi @Faust Security

How is your "ISO in a box" different from organisations using consultants to get certified?

The price firstly. Consultants can charge anywhere from £500 a day up to £1,000 a day (As experienced first hand recently),

I aim to price the main product in the region of £450 and the documents they keep will mean they save money on getting consultants in at much higher prices, as the documents will come with a detailed "How to" guide on implementing it themselves.
 
Upvote 0

Faust Security

Free Member
Jan 12, 2023
6
0
Here are some things you need to know (in broad terms)

- How many businesses want/need your brand of ISO?
- how happy/unhappy are they with the current form of delivery?
- how easy is it for a current provider to copy and undercut you?
- how do how plan to reach your target audience?
All good points, on which I'll be spending time going through on a detailed plan.

For now, I wanted to get a sanity check on the product itself. The challenge around the current form of delivery is extortionate pricing, the security industry has a significantly bad reputation for it and it leaves smaller organisations in the lurch.
 
Upvote 0
Iso in a box is trademarked by a company called Equas


The offer iso 27001 and others

There is this as well


£595

I googled "Iso 27001 in a box", these are all on the first page.

This is all good news as what you're offering exists and seems to sell.

The question is what are you going to do differently and how are you going to market/sell it?
 
Upvote 0

Faust Security

Free Member
Jan 12, 2023
6
0
Iso in a box is trademarked by a company called Equas



The offer iso 27001 and others

There is this as well



£595

I googled "Iso 27001 in a box", these are all on the first page.

This is all good news as what you're offering exists and seems to sell.

The question is what are you going to do differently and how are you going to market/sell it?
So,

my main selling point is that instead of "just selling documents" like ITGovernance does (funnily enough that's who I'm directly aiming at), my documents are going to come with detailed guides on how to implement them, on top of that, the Policies themselves have already been written, all the purchaser has to do is input some information, modify it to best fit their organisation and that's.. that!

My product, in essence, is taking the heavy lifting out for them, instead of spending 6-12 months writing policies & procedures from scratch, I'm doing the heavy work for them and they can focus on filling it out and implementing those policies and procedures and gathering evidence for the audit.

Edit; In regards to the use of "ISO in a Box", it was more a quotation rather than that's what the product will be called. So far I need to complete ALL the documentation before I give the entire product a name and trademark it.
 
Upvote 0

Latest Articles