Excellence Gateways Consulting & Development
Consulting, Audit, Risk & Training
Who we work with
Meridian Advisory Group
A demonstration partner record. Joint delivery of management system implementation across the region.
Visit websiteCedar & Vale Consulting
A demonstration partner record. Quality and service management delivery.
Visit website
The people behind the progress
Good strategy starts with your reality.
Every organisation has its own pressures, people and priorities. We work alongside your team to make standards useful in the decisions you make and the work you do every day.
Get to know EGFind your starting point
What do you need help with?
Start with your goal and explore the services that can support it.
01 / Your goal
Choose your goal and starting point. See a recommendation without sharing contact details.
Browse all servicesEngagement walkthrough
Preparing for ISO/IEC 27001
Information security management system implementation support, from gap assessment to certification readiness.
The starting point
Understand how your current information security practices compare with the standard.
The work
Build an information security management system with implementation support from EG.
The objective
Reach certification readiness.
Explore the approach
An engagement starts with a gap assessment. The findings establish the work needed to build the management system and prepare for certification. Discuss your current position with EG to agree the scope.
What we do
Three practices, one method: internationally recognised standards applied to the risks a business actually carries.
ISO/IEC 27001:2022
ISO/IEC 27001 Implementation
An information security management system built around the risks your organisation actually carries, taken from gap assessment to certification readiness.
ISO 22301:2019
Business Continuity Management
Impact analysis, recovery strategies and exercises that establish what the organisation can keep running, and for how long.
ISO 9001:2015
Quality Management Systems
Process mapping, documentation and internal audit for a quality system that reflects how the work is actually done.
COBIT 2019 · ISO/IEC 20000-1
IT Governance & Service Management
Governance structures, decision rights and service management processes that connect IT spending to business outcomes.
ISO 19011
Internal Audit Programmes
An audit programme with a schedule, competent auditors, and findings tracked to closure rather than filed.
Regulatory
Compliance & Regulatory Review
An independent read of where you stand against the regulations that apply to you, and what closing each gap involves.
Sectors we work in
The same standards, read against what each sector is actually accountable for.
Banking & Financial Services
Regulated institutions carrying both a supervisor's expectations and a customer's money.
Government & Public Sector
Ministries, agencies and semi-government entities with public accountability for the data they hold.
Telecommunications & Technology
Operators and technology companies whose service availability is the product.
Oil, Gas & Energy
Operations where an information security failure and a safety failure are not separate categories.
Healthcare
Providers holding patient records, where confidentiality and availability pull in opposite directions.
Education
Universities and training providers running open networks with sensitive records behind them.
EG in figures
- 15+
- Years in practice
- 40+
- Organisations advised
- 600+
- Professionals trained
- 9
- Standards and frameworks
Upcoming training
Certification courses delivered in English, Arabic and bilingually, on site and online.
ISO/IEC 27001:2022 Lead Implementer
Five days on building an information security management system that survives its first certification audit and the year after it.
ISO/IEC 27001:2022 Lead Auditor
Five days of audit technique against ISO 19011: planning, sampling, evidence and findings that hold up.
Information Security Manager — Examination Preparation
Four days working through the four domains, with practice questions and the reasoning behind each answer.
Recent insights
24 August 2026
The 2022 Annex A is shorter. That is not the same as easier
Ninety-three controls instead of a hundred and fourteen, reorganised into four themes — and a Statement of Applicability that has to be rewritten rather than renumbered.
29 June 2026
Awareness training that changes something
An annual slide deck satisfies a clause. Measuring reporting rates rather than completion rates is what tells you whether anything changed.
A management system that contradicts daily practice is a system people work around.
Frequently asked
How long does an ISO/IEC 27001 implementation take?
Between four and nine months for most organisations, and the range is mostly about how much documentation already exists and how quickly risk owners can be got into a room.
Does EG issue the certificate?
No, and no consultancy can. Certification is issued by an accredited certification body, which must be independent of the people who built the system. EG prepares you for that audit and supports you through it.
Can a course be delivered in-house for one organisation?
Yes. In-house delivery works from six delegates upward and the material is adjusted to the organisation's own systems, which is usually what makes it worth doing.
Which languages are courses delivered in?
English, Arabic, or bilingual — the calendar says which for every date. Course material and the examination are usually in English even when delivery is in Arabic.
Tell us what you are trying to achieve
A consultation is a conversation about the standard that applies to you and what meeting it would take.
Request a consultation
