
A firm that has operated for more than a century accumulates systems, habits, and institutional knowledge that no startup ISMS template fits. Gordon Brothers needed an Information Security Management System that matched how the firm actually runs: deal teams handling confidential financials, a global footprint, and long-standing client relationships where a security failure would cost more than any single engagement. The certification also had to survive an accredited registrar's audit, not just look complete internally.
BD Emerson built the ISMS with the firm rather than handing over documents. The work ran from scope definition and risk assessment through the Statement of Applicability, control implementation, and the internal audit ISO 27001 requires, with BD Emerson walking Gordon Brothers staff through each stage: what Stage 1 tests, what Stage 2 tests, and what evidence answers each clause. When the accredited certification body arrived, the firm was presenting a system it understood and operated, not one it had been handed.
The certification audit closed with zero nonconformities, a result most first certifications do not achieve. Gordon Brothers now answers client and counterparty security diligence with a certificate backed by an operating management system, and the same control base is positioned to carry the firm's next assurance milestones without starting over.