The Founding Five
Five startups. No fee. Your story is the price.
This quarter I'm taking five startups through their compliance journey — ISO 27001, SOC 2 or Cyber Essentials — at no cost, over twelve weeks. In return I want permission to write up how it went and use it in our marketing. That is the entire arrangement.
Or apply in writing →I have existing clients who come first, so I run this at the edges of the day:
Tuesday & Thursday 7:30–9:00am
Wednesday 5:00–6:30pm
0161 327 5077Or book a slot yourself →The situation this is for
If none of this sounds familiar, you probably don't need it.
The deal is stuck behind a security review
An enterprise customer has sent a 200-line questionnaire, or asked for your ISO 27001 certificate. Procurement won't move until it's answered.
Nobody in the building has done this before
There's no ISMS, no risk register, no Statement of Applicability, and no obvious person to own any of it.
The quotes came back at £20k and six months
Which is real money at your stage, for something you can't yet tell is being done well or badly.
You bought a tool and it didn't help
A dashboard turned green and you still couldn't answer the auditor's third question. The tool was never the hard part.
What the five places include
Twelve weeks, working directly with me, not an account manager.
Gap analysis
Where you actually stand against the standard, in plain English, with the awkward findings included.
A real roadmap
Sequenced to your certification date, not a generic 12-month template.
The ISMS, built
Policies, risk register, Statement of Applicability, evidence — built with you inside the platform, not emailed as templates.
Audit run-up
Readiness review and a rehearsal of the questions the auditor will actually ask.
What it costs
No fee. Not a discount, not a trial that converts, not a rate held back for later. The price is that you let me write up how it went.
- ✓A short written case study — what the problem was, what we did, what changed
- ✓Your logo and a quote from you
- ✓You approve every word before it is published. If you'd rather stay unnamed, we publish it anonymised — I'd still rather work with the right company than the right logo.
- ✕Certification body audit fees are yours — those are paid direct to your auditor and I can't waive them
- ✕No obligation to become a paying customer afterwards, and no auto-renewal into one
Who I'm looking for
Five places, and I'd rather turn people away now than three weeks in.
A good fit
- ✓Pre-Series B, UK or EU
- ✓A real certification deadline in the next six months — usually a customer's
- ✓A founder or senior person who can make decisions in the room
- ✓Able to give a couple of hours a week, early or late
- ✓Willing to be written about
Not a fit
- ✕Exploring compliance with no deadline and no driver
- ✕Needing a certificate in under eight weeks — that isn't a thing I can honestly promise
- ✕Unable to be named or written about even anonymously
- ✕Looking for someone to do it entirely for you with no internal owner
How it works
No form, no discovery call with a rep, no sequence of nurture emails.
- 1
You ring me
0161 327 5077, in one of the windows. Forty-five minutes, and we work out whether this is a fit. If it isn't, I'll tell you on the call and point you somewhere better. Prefer to book a slot? Pick one here.
- 2
Scoping session
We agree the standard, the deadline and the scope, and I write it down so we both know what we've committed to.
- 3
Twelve weeks of work
Fortnightly working sessions, early morning or evening, with the platform carrying everything in between.
- 4
The write-up
We do the case study together at the end, you approve it, and then it goes out.
Who you'd be working with

I'm Simon Green, founder of Sentinel42. Sixteen years in governance, risk and information security — most of it spent getting organisations through the exact process I'm offering here.
I've taken a UK SaaS provider to ISO 27001 certification and SOC 2 Type 2 attestation as its Head of Information Security, and worked across the NHS, financial services and energy. I sit on the other side of the table too, as a qualified lead auditor — which is the main reason I know which parts of this genuinely matter and which parts are theatre.
- ISO 27001 Lead Auditor & Implementer
- ISO 42001 Lead Auditor & Implementer
- Cyber Essentials Assessor
- CISM
- CCSK
- SC Cleared
Straight answers
Actually free. No fee for my time or for the platform during the twelve weeks, and no obligation afterwards. The only money you'll spend is the certification body's audit fee, which is paid direct to them.
Apply for one of the five
Two minutes. I read every one myself and reply within two working days — including the ones I turn down.
Ring me. You'll get me.
Not a switchboard, not an SDR, not a form that generates an email in four working days.
0161 327 5077Tuesday & Thursday 7:30–9:00am · Wednesday 5:00–6:30pm — outside those hours, leave a message and I'll ring you back the same day.