Project Description
Rockford is a specialist payroll services provider operating in a highly regulated industry where information security and customer trust are critical. As a relatively new business, Rockford needed to build its entire IT and security environment from the ground up while achieving recognised security certifications that would demonstrate its commitment to protecting client data.
Bridgeall partnered with Rockford from the outset to design and implement a secure Microsoft 365 environment, establish the governance and security controls required for compliance, and guide the organisation through achieving both Cyber Essentials and ISO 27001 certification. The result was a secure, scalable technology platform that continues to support Rockford’s growth.
Bridgeall have been instrumental in helping us obtain, and retain, our ISO27001 certification. They have guided us through multiple stages of a complex process, advising where required, recommending approaches and solutions, always happy to share their time and expertise. Working with Bridgeall certainly feels like a partnership rather than a standard client / supplier relationship. We couldn’t recommend them highly enough.” –Stephen Nicholas, CEO and Co-Founder
About Rockford
Rockford is a Professional Engagement and Payroll Services Organisation (PEPSO) providing transparent, compliant payroll solutions for contingent workers, recruitment agencies, and end clients.
Through its innovative Agreed Contract Rate (ACR), Rockford delivers a fairer, clearer alternative to traditional umbrella companies, helping businesses reduce costs while giving workers confidence in exactly what they earn.
Challenges facing Rockford
Launching a new business presented Rockford with the unique challenge of creating an entire IT and security environment from scratch. With no existing users, devices, policies or governance framework in place, the organisation needed to establish secure working practices from day one.
In today’s market, robust cybersecurity is not just about protecting the business, it is also a key factor in winning new customers. Many organisations, particularly larger enterprises, now expect suppliers to demonstrate recognised cybersecurity certifications as part of their procurement and supplier assurance processes.
For Rockford, building a secure, compliant IT environment from the outset was therefore essential to safeguarding the business, meeting customer expectations, and creating a strong foundation for future growth and commercial success.
Alongside building its Microsoft 365 environment, Rockford had ambitious goals to achieve both Cyber Essentials and ISO 27001 certification, providing assurance to customers and stakeholders that security had been embedded throughout the organisation.
Although an Information Security Management System (ISMS) platform was selected to support compliance activities, Rockford understood that software alone would not achieve certification. The organisation required an experienced security partner capable of translating certification requirements into practical technical controls, governance processes and day-to-day operational practices.
The Solution – How Bridgeall Helped
Bridgeall worked alongside Rockford as a trusted security partner from the earliest stages of the business, providing both technical implementation and practical security expertise throughout the certification journey.
The engagement began with the design and deployment of a secure Microsoft 365 environment using Microsoft 365 Business Premium. Bridgeall implemented Microsoft Intune for device management, Microsoft Defender for endpoint protection, Multi-Factor Authentication (MFA), Conditional Access policies, Data Loss Prevention (DLP), Information Protection controls and comprehensive endpoint security to create a robust security foundation.
Beyond the technology implementation, Bridgeall provided hands-on support to prepare Rockford for certification. This included developing security policies, advising on governance and risk management, carrying out gap analysis, supporting business continuity planning, preparing for audits and working closely with both the chosen ISMS provider ISMS Online and certification auditors.
Rather than simply implementing technology, Bridgeall acted as an extension of the Rockford team, helping transform certification requirements into practical security controls and operational processes that could be embedded across the organisation.
Results – Benefits to Rockford
By partnering with Bridgeall, Rockford successfully achieved both Cyber Essentials and ISO 27001 certification while establishing a secure and scalable technology environment capable of supporting future growth.
Key benefits included:
- Successful certification – Achieved both Cyber Essentials and ISO 27001, demonstrating compliance with recognised cybersecurity and information security standards.
- Secure Microsoft 365 environment – A modern, security-first Microsoft 365 platform with robust identity, endpoint and data protection controls built in from the outset.
- Improved governance and risk management – Clear security policies, governance processes and operational controls strengthened compliance and reduced organisational risk.
- Greater customer confidence – Recognised certifications provided assurance to customers and stakeholders that information security is embedded throughout the organisation.
- Long-term security partnership – Ongoing access to Bridgeall’s security expertise ensures Rockford continues to strengthen its security posture and maintain certification standards as the business grows.
Bridgeall have been an invaluable partner to RIG, consistently supporting us across our business needs and providing expert guidance throughout our ISMS and ISO 27001 journey. Their knowledge, responsiveness and practical approach have made what can be a complex process much more straightforward for us.
They have worked closely with our team to understand our requirements, provide the right advice and help us strengthen our overall information security framework. Their support has been instrumental in helping RIG progress towards ISO 27001 certification, while also giving us greater confidence in the robustness and maturity of our ISMS.
We have really valued the partnership with Bridgeall and would have no hesitation in recommending them to other organisations looking to develop and strengthen their information security and governance arrangements. – Francis Osborne, Operations Manager
Looking to achieve Cyber Essentials or ISO 27001?
Achieving recognised security certifications requires far more than implementing software. Success depends on designing the right technical controls, developing effective governance processes, and embedding security into day-to-day operations.
Bridgeall helps organisations prepare for Cyber Essentials and ISO 27001 by combining Microsoft security expertise with practical implementation support, helping businesses build secure, compliant and resilient technology environments.
Talk to Bridgeall today to discover how we can help you achieve certification while creating a secure foundation for future growth.



