Main Services
Viritux Limited is a UK-based ISO compliance and digital assurance consultancy, headquartered in Northern Ireland and working with clients across the UK and European Union. We specialise in information security management, AI governance, IT service management, and cyber risk — helping organisations achieve and maintain certification to internationally recognised standards. Our clients range from growing SMEs navigating compliance requirements for the first time to established organisations in financial services and the public sector seeking to strengthen their security posture. We are not a managed services provider, and we do not offer penetration testing. Our work is purely advisory: focused, independent, and aimed at one outcome — getting our clients compliant and keeping them there. The consultancy is led by Bruce Dorrian-Clark, who brings over 20 years of experience in information security and compliance across a range of demanding environments. Bruce’s background includes a senior role as Lead Security Architect with the UK Ministry of Defence, alongside extensive work in financial services, large corporates, and SMEs. That breadth of experience, from central government security architecture to the practical compliance realities facing smaller organisations shapes how Viritux operates. Bruce is a qualified external auditor with direct, hands-on experience conducting ISO 27001 audits and gap assessments, and holds deep practitioner-level expertise across ISO 27001:2022, ISO 42001, ISO 20000-1, ISO 27005, and NIS2/UK Cyber Security & Resilience Bill compliance. He is supported by a small team of experienced external auditors and principals, giving clients access to genuine collective expertise rather than a single-point service. Viritux delivers a focused range of advisory services built around the ISO management system standards most relevant to information security and digital governance. Our core offering centres on ISO 27001:2022 implementation and certification support — from initial gap analysis through to certification readiness — alongside ISO 20000-1 consultancy for organisations seeking to demonstrate maturity in IT service management. We conduct internal audits for both ISO 27001 and ISO 42001, providing clients with qualified, independent audit capability without the need to source it elsewhere. Our risk assessment work draws on ISO 27005 methodology, threat modelling, and cyber risk quantification, giving organisations a structured, defensible basis for their risk management decisions. For organisations that lack in-house security leadership, we provide Virtual CISO (vCISO) services — fractional, senior-level security oversight that covers strategy, governance, and board-level communication. We also support clients in understanding and preparing for obligations under NIS2 and the forthcoming UK Cyber Security & Resilience Bill, which will bring significantly more organisations into scope for regulatory compliance. One area where Viritux is particularly well-positioned is ISO 42001 — the international standard for AI Management Systems. Published in 2023, ISO 42001 provides a structured framework for governing the development, deployment, and use of artificial intelligence within an organisation. Demand for this standard is accelerating, driven by the EU AI Act, growing supply chain requirements, and increasing board-level scrutiny of AI risk. Despite this, very few UK consultancies have developed genuine practitioner-level expertise in ISO 42001 implementation. Viritux has. We support organisations building AI governance frameworks from the ground up, and — crucially — we can deliver integrated implementations that align ISO 42001 with an existing or concurrent ISO 27001 programme. For organisations that need to demonstrate both information security and AI governance maturity, that dual capability in a single consultancy is a meaningful practical advantage. What distinguishes Viritux in the market is straightforward. Most organisations seeking compliance consultancy face an uncomfortable choice: a freelancer with limited capacity and scope, or a large firm with rates that are difficult to justify unless you are already operating at enterprise scale. Viritux occupies the space between those options, delivering genuinely senior advisory work — the kind of expertise that typically sits inside large organisations or commands large-firm day rates — at a scale and cost that works for SMEs and mid-market businesses. Clients engage with experienced principals from the outset and throughout the engagement, not with junior staff working from templates. There is no upsell into software, managed services, or ongoing retainers that serve our interests rather than the client’s. Our advice is conflict-free and scoped to what each organisation actually needs to achieve. Organisations looking to pursue ISO 27001, ISO 42001, or ISO 20000-1 certification — or to strengthen their information security governance, risk management, or regulatory compliance position — are welcome to get in touch via www.viritux.com. We are happy to discuss requirements in a straightforward initial conversation, with no obligation, and provide a clear picture of what achieving your compliance objectives will actually involve.