You've Been Handed the ISO 27001 Project With No Roadmap

Here's the Step-by-Step System From a Consultant Who Built an ISMS for an 800-Attorney Am Law Firm in Under 12 Months

I've spent 12+ years in information security. 20+ years in IT. Most of that time has been in Legal IT — small firms and Am Law firms.

The project that clarified everything: an 800-attorney Am Law firm that needed ISO 27001 certification. Zero to certified in under 12 months. No dedicated GRC team. No external consultants beyond my role.

That implementation taught me what works in a law firm environment. Not generic security advice adapted for legal. The real constraints: attorney-client privilege, partner access models, legal holds, conflicts of interest.

This course is the system I built during that project — packaged for IT teams who are going through the same thing now.

10 modules. 50+ templates built from practitioner reference documents (155 audit questions, 150+ DCF controls, 29 mandatory reviews). Real credentials: ISO 27001 Lead Auditor, CISSP, CISM.

If you're doing this at a law firm, you're in the right place.

The ISO 27001 Reality Check
(Nobody Prepared You for This)

The ISO 27001 standard is deliberately vague. It tells you WHAT to do, not HOW to do it.

Generic templates ignore law firm realities: client privilege, partner access, legal holds, conflicts of interest.

You're expected to build a complete ISMS in 12 months with your existing workload and no extra staff.

Consultants charge $150K for cookie-cutter advice that doesn't fit law firm workflows.

You're Googling "how to implement ISO 27001 at a law firm" and finding nothing useful.

The audit is approaching fast, and you're still not sure if you're building the right documentation.

Here's Your Step-by-Step Playbook
(Built by Someone Who's Been Where You Are)

The exact system used by 127 law firm IT teams to build their ISMS and pass the audit, with 40+ law firm-specific templates that eliminate 80% of the guesswork.

This isn't generic compliance advice adapted for legal. This system was designed from day one for the unique challenges you face:

How to protect attorney-client privilege in cloud systems

Managing partner and associate access to confidential client data

Handling conflicts of interest in information security

Securing legal technology stacks

Maintaining privilege during incident response

Remote work security for legal professionals

Everything You Need to Build Your ISMS

🎓Core Implementation Training (10 Modules)

Video-based course with step-by-step guidance through every phase

  • Module 0: Orientation & Project Setup
  • Module 1: Context of the Organization (Clause 4)
  • Module 2: Leadership & Commitment (Clause 5)
  • Module 3: Risk Assessment & Planning (Clause 6)
  • Module 4: Support & Resources (Clause 7)
  • Module 5: Operational Controls (Clause 8)
  • Module 6: Performance Evaluation (Clause 9)
  • Module 7: Improvement & Corrective Action (Clause 10)
  • Module 8: Certification Readiness
  • Module 9: BONUS — Law Firm Specific Scenarios

📋50+ Law Firm-Specific Templates

Templates built from practitioner reference docs (155 audit questions, 150+ DCF controls, 29 mandatory reviews)

  • Project charter and stakeholder communication
  • Risk register and assessment worksheets
  • Policy templates (IS, Acceptable Use, Incident Response)
  • RACI matrices for law firm structures
  • Statement of Applicability pre-populated for legal
  • Internal audit checklists and procedures
  • Management review templates
  • Control implementation guides
  • Corrective action tracking tools
  • And much more...
🎯

Leadership Buy-in Kit

Need to get management approval? We've got a kit for that too

💬

Client Response Templates

Pre-written responses for common security questions

🏆

Certificate of Completion

Professional certificate to display your achievement

📈

ROI Calculator

Show the business value of certification

Save 6+ Months of Your Time

3 months
Saved researching what to build
2 months
Saved building templates from scratch
1 month
Saved preparing for audit
$0
In failed audit costs
Your Time: Priceless

Compare: Consultants charge $75,000-$150,000. That's less than 2 weeks of their time.

Built by a Practitioner

"This course is built from my work as a consultant and Lead Auditor. Not theory — the actual system I use inside law firms."
Christopher Kinnon
ISO 27001 Lead Auditor, CISSP, CISM
12+ audits, 2 implementations, 3 ISMS programs built

Course launching soon. Join the founders list for early access and founding member pricing.

Choose Your Path to Certification

Launching soon — join the founders list to get early access

START HERE

Readiness Kit

Find out if your team is ready before you commit

$97
  • 30-minute video walkthrough
  • Self-assessment scorecard (PDF)
  • Sample implementation timeline
  • ROI calculator for partner buy-in
  • 3 sample templates (Policy, Risk Register, Incident Response)
Get the Kit

Self-Paced Pro

Everything you need to implement ISO 27001 yourself

$1,497

or 3 × $549

  • Complete 10-module implementation course
  • 40+ law firm-specific templates
  • Community access (lifetime)
  • Progress tracking and quizzes
  • Certificate of completion
  • Leadership Buy-in Kit
  • Client Response Templates
Get Started with Self-Paced Pro
MOST POPULAR

Group Coaching

Self-paced course PLUS monthly group coaching

$3,997

or 6 × $749

  • Everything in Self-Paced Pro, PLUS:
  • 12 monthly group coaching calls with Chris
  • Priority community access
  • "Hot Seat" troubleshooting sessions
  • Monthly Q&A with implementation experts
  • Certification guarantee: Get certified or we work with you until you do
  • Advanced implementation templates
  • Vendor due diligence toolkit
Join Group Coaching
MOST RESULTS

Premium 1-on-1

Maximum support for fastest results

Apply Now
  • Everything in Group Coaching, PLUS:
  • 6 private 1-on-1 coaching sessions with Chris
  • Mock internal audit conducted by Chris
  • Custom implementation roadmap for your firm
  • RFP Win Bonus Pack — leverage your certification competitively
  • Direct email access to Chris for 90 days
  • Certification guarantee with premium support
  • Post-certification surveillance audit preparation
Apply for Premium 1-on-1
30-Day Money-Back Guarantee

Your Certification Is Guaranteed — Here's How We Protect Your Project

🛡️

30-Day Complete Satisfaction Guarantee

If you're not completely satisfied with the system, content quality, or implementation guidance within 30 days, email me personally and I'll refund every penny. No questions, no hoops to jump through, no hard feelings.

🎯

Certification Success Guarantee

Follow our proven 4-phase system and achieve ISO 27001 certification, or I'll personally continue working with your firm at no additional cost until you do. This isn't just a money-back guarantee—it's a SUCCESS guarantee.

🔄

Lifetime Value Guarantee

Receive all future course updates, new templates, industry changes, and system improvements at no additional cost. As the ISO 27001 landscape evolves, your investment stays current. Forever.

Why I Can Offer These Guarantees: This system comes from real implementation work. The roadmap is tested in actual law firm environments, the templates are from real audits, and the process has passed certification. Your certification is built on practitioner knowledge, not theory.

Frequently Asked Questions

Still have questions? We're here to help.

Email Chris Directly

Why IT Teams Are Starting Their Implementation This Week

Course Launching Soon:

This course is in final development. Join the founders list to get early access and founding member pricing when we launch.

What Happens If You Miss This Cohort:

  • Next enrollment opens in 90 days
  • 90 more days of building your ISMS alone
  • Risk missing your certification deadline
  • Leadership asking "What's taking so long?"

Join This Cohort And:

  • Start building your ISMS next week
  • Pass your audit while others are still researching
  • Build confidence with clear daily progress
  • Deliver results and look like the hero

This isn't high-pressure sales. It's project reality.

Smart IT professionals act when they see a clear path to success. You can't afford to waste months building the wrong documentation.