The need for Information Security has only increased as we become more dependent on technology to keep things running smoothly. Even in industries such as construction, which many may have assumed were largely exempt.
While not common, there are a few within the construction space that have taken the initiative to implement best practice information security Standards, such as todays’ guest, AmcoGiffen.
In this episode, Ian Battersby is joined by James Butler, IT Director at AmcoGiffen, to dive into why they chose to implement ISO 27001, what they learned during the process and the benefits felt following certification.
You’ll learn
- Who is James Butler?
- Who are AmcoGiffen?
- What was the main driver for ISO 27001 Implementation?
- What was the biggest gap identified during the Gap Anaylsis?
- What did AmcoGiffen learn from the Implementation journey?
- What are the main benefits of ISO 27001 Implementation?
- James’ Top Tip
Resources
In this episode, we talk about:
[02:35] Episode Summary – Ian Battersby is joined by James Butler from AmcoGiffen to discuss their journey towards ISO 27001 certification, including the challenges faced and resulting benefits following certification.
[03:00] Who is James Butler? James Butler is the IT Director at AmcoGiffen.
One thing many may not know about him is that he’s recently started taking swimming lessons aside his kids. Growing up, there weren’t many opportunities to learn, so he’s taking the time now to both set a good example for his children and to ensure he can keep them safe when in bodies of water in the future.
[05:40] Who are AmcoGiffen?: AmcoGiffen are a national contractor for construction and engineering throughout the UK. They are owned by the group company Renew Holdings.
Their projects range from rail, infrastructure, highways, environmental sectors to aviation.
[07:10] What was the main driver behind ISO 27001 Implementation? They had a couple of reasons:
- They wanted to ensure that clients, stakeholders and shareholders had confidence in their ability to secure their data and information along with their employees data.
- When you work in the public sector, ISO 27001 is becoming a necessary certification to have. James expects that within the next 5 years, it will be just as mandated as Cyber Essentials currently is.
AmcoGiffen already proudly hold Cyber Essentials Plus, and saw ISO 27001 certification as the next natural step to provide that extra level of assurance.
[08:35] How long did it take to achieve ISO 27001? It was discussed for a while before committing, but the whole process took around 12 months from start to certification.
At first, they did want to challenge themselves with a shorter timeframe, but after starting the process they realised that a shorter time restraint was adding unnecessary pressure and wouldn’t have resulted in a good Management System that could be used.
So, they took a step back and allowed more time for the system to be properly integrated into the business, which was that part that took the longest, as documentation is the easier part to deal with.
[10:55] What was the biggest gap identified during the Gap Analysis? – For AmcoGiffen, the biggest gap was documentation.
They already had a lot in place where controls were concerned thanks to their existing Cyber Essentials Plus certification, but the actual documentation of processes, objectives and risks were lacking.
ISO 27001 allowed them to put the structure in place to manage this. Their key message throughout the implementation process was: ‘we need documentation for the right purpose’.
[09:55] What did AmcoGiffen learn from the Implementation journey? ISO 27001helped to create a priority list, while also allowing them reflect and realise they should be documenting a lot more, not just to meet Standard requirements but because it’s the right and responsible thing to do.
One such example is making sure that there’s enough information to allow someone to pick up a task if it’s passed to them.
They went to great pains to ensure the whole implementation wasn’t forced, and as a result they passed both their Stage 1 and Stage 2 Assessments with no non-conformities or observations!
AmcoGiffen also had the benefit of strong leadership commitment and involvement throughout the Implementation. James stresses the need to have Leadership buy-in from day one, otherwise you have to fight an uphill battle of making cases for the changes that you need to make as a result of implementing a Management System.
He also make a point of ensuring you understand your stakeholders requirements, as ISO 27001 is not just an IT Standard, it touches on aspects like HR and physical security, aspects they may actively be involved with. If possible, it’s best to bring them in and involve them in the initial planning so you’re all on the same page of why you want to achieve Certification.
[15:20] When did AmcoGiffen achieve Certification? – They completed they Stage 2 Assessment in July of 2026 and received the certificate in September of 2026.
[15:50] What are the benefits of ISO 27001 Certification? – James states that the benefits started from day 1 of the implementation process.
The initial Gap Analysis allowed them to really look at how they currently operated, what were their strengths and weaknesses, where potential opportunities were.
It gave them the chance to gather people from all corner of the business to come together and discuss their current processes, get feedback on how they could be improved, and ensure the updated processes would fit in with how they actually worked.
James states that IT professionals can have a tendency to over complicate things, so he ensured that the system remained something that could be easily understood and integrated into the business.
One other thing they implemented early was a mature Risk Register, this was so they could be driven by the actual risks facing the business and not just by who was shouting the loudest.
Ultimately, ISO 27001 has provided a lot more organisational structure and more direction on priorities.
[18:55] James’ Top Tips – Do it for the right reason, don’t do it as just a tick box exercise. If you’re simply doing it for a badge on the website, then it’s unlikely it will be providing any real benefit as it requires effort to keep the momentum of continual improvement going.
Secondly, get Leadership buy-in before committing to certification. The process will be difficult without that endorsement from the top down.
Lastly, challenge yourself to remove friction. The system has to work for the business, not just the auditors of the system. The key is to make the right information available to the right people at the right time. Don’t just bog them down with endless processes and manuals, keep it simple and easy to understand as that’s how a system gets integrated successfully.
[21:50] James’ book recommendation – The subtle art of not giving a f*ck – Mark Manson
[23:45] James’ favourite quote – ‘Keep it simple’
If you’d like to learn more about AmcoGiffen, check out their website.
If you’d like help with ISO 27001 Implementation or on-going support, feel free to reach out to us, we’d be happy to help.
We’d love to hear your views and comments about the ISO Show, here’s how:
- Share the ISO Show on Twitter or Linkedin
- Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.
Subscribe to keep up-to-date with our latest episodes:
Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List
Download the ISO Standards Blueprint
A step-by-step checklist for getting ISO certified
Resources
Subscribe to keep up-to-date with our latest episodes:
SoundCloud Spotify iTunes
Stitcher
YouTube
Amazon Music