Jigsaw Create
ISO/IEC 27001 readiness and penetration testing for a RegTech start-up selling to enterprises
Strongest proof
ISO/IEC 27001 readiness and cyber assurance
- Sector
- Technology / SaaS / RegTech
- Capability
- Cyber Governance & Assurance
- Geography
- United Kingdom
- Engagement model
- Defined-scope assurance
- Evidence
- Named client · Public evidence
At a glance
- Who
- Jigsaw Create · Technology / SaaS / RegTech
- Why it mattered
- Enterprise buyers wanted independent assurance of a RegTech start-up's security before contracting.
- IG-Smart's role
- ISO/IEC 27001 readiness, penetration testing and training
01The exposure
Jigsaw Create is a legal and RegTech start-up whose enterprise customers expect independent evidence of information-security management.
Without recognised security assurance, enterprise procurement stalls — a critical constraint for a growing supplier.
02The mandate
A practical, proportionate ISMS ready for independent ISO/IEC 27001 certification, plus technical testing of its estate.
Commissioned scope
- ISO/IEC 27001 readiness and implementation support
- Penetration testing: networks, web and mobile applications, wireless
- Security awareness training
03Environment
Organisation context
Describes the client organisation — not the size of IG-Smart's work.
- Technology and creative services business
Frameworks in scope
- ISO/IEC 27001
Scope boundary
- Certification was awarded independently by BSI; IG-Smart does not certify
04IG-Smart's approach
- 01
Proportionate ISMS
Guided the company towards BSI certification with a governance operating model tailored to its business, avoiding unnecessary complexity.
- 02
Penetration testing
Tested internal and external networks, web and mobile applications and wireless infrastructure, with remediation insight.
- 03
Awareness training
Delivered security awareness training so security became a shared responsibility.
05Engagement scale
What IG-Smart's work covered
- ISO/IEC 27001 readiness
- Cyber assurance
06What we delivered
- ISMS documentation and governance operating model
- Penetration test reports and remediation recommendations
- Security awareness training
07Outcome
Measured result
Jigsaw Create achieved ISO/IEC 27001 certification through BSI's independent certification process.
Client-reported result
The MD reports that IG-Smart's pragmatic approach sped up the process and saved time and money.
08Client perspective
“IG-Smart took the time to truly understand our business before providing concise, pragmatic and expert-level advice... this approach sped up the whole process, saving us time and money.”
09What this demonstrates
A proportionate ISMS reaches certification faster than an over-engineered one.
10What buyers can verify
Public
- Named client
- Engagement scope
- Named client quotation
- Deliverable types described
Further evidence can be discussed subject to confidentiality and client permissions.
Related services
Related evidence
Charity / Social Enterprise, Cyber Governance & Assurance · NHS & HealthTech
Addvanced Solutions Community Network CIC
Penetration testing and security assurance supporting a community organisation's compliance goals
A community organisation needed its networks, applications and wireless estate tested, with findings mapped to its compliance obligations.
The client's Director reports the assessments helped identify and rectify vulnerabilities.
Read the case studyRetail / Consumer, Cyber Governance & Assurance
The Co-operative Group
Routine penetration testing for a major national retailer and co-operative
A major national organisation needed consistent, routine testing that kept pace with its changing digital estate.
On the Group's preferred supplier list for more than two years.
Read the case study
Facing a comparable requirement?
This case reference is passed to the form so you don't need to re-enter it.
Submit a Requirement