About
Kellwick is an independent advisory practice focused on ISO 27001 readiness, ISMS maintenance and product-led security governance for regulated technology companies - SaaS, fintech, payments, FX, iGaming and credit platforms.
Most companies do not fail ISO 27001 because they lack policies. They fail because the ISMS is not operated: risks go stale, evidence is scattered, ownership is unclear, and the system only looks compliant on paper. That is the problem we work on.
Why Kellwick exists
Too much ISO 27001 work is sold as a documentation exercise: buy a template pack or a compliance platform, generate policies, and hope. It produces a certificate and a false sense of safety, then falls apart at the surveillance audit or the first serious enterprise security review.
Kellwick exists for exactly that gap. Too much readiness work is product-blind: controls treated as documents rather than as things that must operate in how a product is built, shipped and run. We bring that operating mindset to readiness and maintenance, so an ISMS holds up when an auditor, or your next customer, actually looks.
Policies do not prove control operation. Evidence does. We look at what your ISMS actually produces - access reviews, incident records, supplier assessments, management decisions - not just what it promises.
Controls fail when nobody owns them. We map every control to a real owner in product, engineering or operations, so the system keeps running after we leave.
For SaaS and fintech companies, ISO 27001 touches release governance, QA evidence, access control and supplier risk. We connect the ISMS to how your product is actually built and shipped.
If you are not ready, we say so - and show exactly what to fix first. If a readiness review is not the right first step, we tell you that too.
Methodology
Our methodology maps to established security frameworks rather than to a single template. ISO/IEC 27001 remains the certification standard we prepare you for, and we align the way we structure a security programme to NIST CSF 2.0 - using its Govern, Identify, Protect, Detect, Respond and Recover functions as a common language for organising controls, ownership and risk.
This is a framing for how we think, not a product or a certification. We do not certify against NIST CSF, and mapping to it does not replace an accredited ISO 27001 audit - it simply helps us structure a programme that holds up under scrutiny.
Kellwick is an independent advisory practice. We are not a certification body and do not issue ISO certifications. Certification decisions are made only by accredited certification bodies.
We do not sell template packs, we do not guarantee audit outcomes, and we do not replace your accredited certification body. We prepare you to face them with confidence.
We do not lead with client logos. We lead with knowing exactly what an auditor will look for - and where regulated operations actually break.
Confidentiality-first engagement. We can work under your NDA and use your approved document-sharing process. A readiness review does not require production access unless explicitly agreed, and we never ask for sensitive documents before an agreement is in place.