We are a small consultancy focused on supporting businesses in the South West to help them improve their information security practices and comply with contractual or regulatory (e.g. GDPR) requirements.
We typically use ISO 27001:2013 as a framework to support changes to policy and process as it makes it more likely that the changes will be maintained and sustained.