We help companies in León implement an information security management system under ISO/IEC 27001:2022, with risk assessment, statement of applicability, staff awareness and internal audit.

León's workforce comes from footwear and leather-goods factories, retail, services, and automotive suppliers, with high seasonal turnover and supervisors trained on the production floor. Our team adapts the scope to their size and sector, works on-site when needed and online the rest of the time, and measures results from the first month.
Since we have a team in León, the risk assessment workshops with each area, the review of the statement of applicability and the internal audit happen at your company. We support service companies, footwear and leather businesses with online sales channels and automotive suppliers that need to demonstrate information security. Awareness runs on the platform, with the cybersecurity awareness course and a certificate for each person, and we review risk follow-up with you every quarter so the ISMS keeps up with changes in systems, vendors and staff.
We serve organizations in León, Silao, San Francisco del Rincón, Purísima del Rincón, and the corridor toward Guanajuato city. We have a team in León and cover the Bajío from Querétaro; in the other locations we combine visits with online work. See also iso 27001 consulting in Guanajuato, ISO 45001 consulting in León, AI agents for business in León. The full detail of the service is at iso 27001 consulting.
The documents you need, controls in place and people who know what to do when something fails.
We compare your current situation with every requirement of the standard and prioritize what is missing by risk and effort.
A clear methodology to identify assets, threats and vulnerabilities, rate the risk and decide how to treat it.
The applicable Annex A controls, the excluded ones and the justification for each, ready for the auditor.
Short policies and procedures written for your real operation, not generic templates that nobody ever reads.
A cybersecurity awareness course with assessment, phishing simulations and a certificate recorded on the platform.
We audit the full ISMS before the certification body does and deliver findings and corrective actions.
The same stages of the method, with on-site visits when the project requires them.
We review processes, systems and existing documentation, and define with management which areas, sites and services the ISMS covers and what each client expects.
Gap and scope reportWe inventory information assets, assess threats and vulnerabilities with each area and agree on the treatment plan with owners and dates.
Risk matrix and treatment planWe implement the applicable Annex A controls and write short policies and the statement of applicability with the justification for each control.
Statement of applicabilityWe train all staff with the cybersecurity course, put the controls into operation and generate the evidence the standard requires.
Competence and operation recordsWe perform the internal audit, close the management review and support you during the stage 1 and stage 2 audits of the certification body.
Internal audit reportMessage us on WhatsApp, request a proposal or open the chat; we reply the same day with three scope options.
Certification is granted by an accredited certification body; we get you ready to receive it with organized evidence.

Both routes reach the standard; the difference is time and what is left running.
| With Geedle | On your own | |
|---|---|---|
| Starting point | Gap analysis against every requirement | Reading the standard and downloaded templates |
| Risk assessment | Proven methodology and workshops with each area | Spreadsheets that get abandoned |
| Statement of applicability | Controls justified for your operation | A list copied from Annex A |
| Awareness | Course with assessment and certificate on the platform | One yearly talk with no records |
| Internal audit | Auditors experienced in management systems | Review by the same team that implemented |
| Maintenance | Review calendar and continual improvement | The ISMS freezes after the certificate |
The same method and the same team, adapted to each location.
Tell us about your case by WhatsApp, form or chat. We reply the same day, free and with no commitment.