In this case study:
Meet the client
This client is a group of three affiliated companies in the investment and property services sector. Each company operates its own business model, customer base, and regulatory obligations, spanning institutional funds, freehold services, and aspirational living, but the group shares a common commitment to protecting customer data and demonstrating best practice.
The challenge: aligning security across three distinct businesses

The group set out to strengthen its information security group-wide. With three companies operating under different teams, cultures, and regulatory pressures, building a shared framework meant careful coordination and strong leadership.
Coordinating a group-wide information security framework across businesses with different focuses, teams, and regulatory obligations was a central challenge, alongside reviewing supplier risk end to end, from onboarding to offboarding, including vendor selection standards and contractual protections. The group also needed to formalise secure software development practices for the tools it builds in-house.
What we did: unified framework, certified individually
With a strong internal culture of governance already in place, the group partnered with Reflective IT to launch a group-wide project aligning information security policies and processes. Despite differences between the businesses, Reflective IT helped create a unified framework that allowed flexibility where needed, with each company certified individually to reflect its own risk profile.
The solution: strengthening security at every stage
Multi-company coordination sat at the heart of the project, aligning policies and processes across three businesses with different focuses while allowing flexibility for each company’s risk profile. Supplier risk management was a major area of focus, with the entire supplier lifecycle reviewed, from vendor selection standards to contractual protections, from onboarding to offboarding.
The group had already built some of its own tools in-house, and the ISO process encouraged it to formalise its approach: structured testing was introduced at every stage of development to ensure software was secure and reliable before deployment.

The impact: certification, confidence and continuous improvement
All three companies passed their ISO 27001 audits on the first attempt. Supplier contracts became more robust, software development more secure, and internal teams more confident. The ISO 27001 logo now appears in email signatures and customer communications as a visible mark of quality, and the project has improved security posture while building trust with investors, customers, and staff, demonstrating the group’s commitment to doing things right.
| 3 | 100% | 1 |
| companies certified | first-time audit pass rate | unified security framework |

“Looking back, since we originally achieved ISO 27001 certification for all three businesses, it has been a contributing factor to building confidence with new investors and existing customers.”
Group Director of Technology & Data
Want to strengthen your own security posture?
From policy alignment to first-attempt audit success, discover how we support ISO 27001 certification and compliance-led security.


