Information Security Best Practice: what to look for when choosing a consultancy partner
Information Security Best Practice: what to look for when choosing a consultancy partner
Your business takes its cyber and information security obligations seriously. But can the same be said of your partners? When appraising potential consultants and service providers, these are the trust indicators to look for.
Avoiding exposure: What makes a technology consultancy a potential infosec weak point?
What attributes do you look for when choosing a consultant to work with? Inside-out knowledge is a must-have. So, too, is responsiveness; you need a partner who ‘gets’ what you need and will work with you to deliver it. And especially when it comes to digital transformation, most decision-makers also want to see clear evidence of program success: “This is a significant move for our company, so can this consultancy actually deliver what we are aiming to achieve?”.
Alongside this, information security is a further area you need to look closely at. With any technological consultancy arrangement, there is an element of handing over the keys to the kingdom or, at the very least, a back-and-forth flow of some sensitive information. Depending on the project, your partner will need detailed information about – and often, direct access to – critical systems, processes, and data.
Threat actors are all too aware of this. They know that when they successfully infiltrate a professional services provider, IT consultancy, or software implementation partner, it potentially opens a rich treasure trove, exposing sensitive data relating to each and every one of their target’s clients.
According to Security Magazine, third-party attack vectors are responsible for 29% of all breaches. Three quarters of these third-party breaches are linked to software products and technological services.
An estimated 60% of organisations use cyber security risk as a key factor when determining transactions and business engagements with third parties, which suggests that a significant minority may be failing to give it proper thought. When it comes to technology projects and process transformation, this risk needs to be on the radar of every business.
So how can you tell if a particular consultancy takes cyber risks and information security seriously? Here are the areas to focus on…
They Have the Right Accreditations
To understand your business, your consultant will need to see items such as your business process maps, details of internal procedures, information on existing system priorities and vulnerabilities, and more general information linked to your future and growth strategies. Once the project is underway, they may need to move or process segments of your data across multiple locations or export it for analysis or testing. Obviously, you do not want this to fall into the wrong hands.
Look for consultancies that have been independently verified as having what it takes to keep your information safe. Probably the single most valuable trust indicator here is ISO 27001. If your consultant has an up-to-date ISO 27001 certification, it shows they have an effective ISMS (information security management system) in place. This means the following:
- The consultancy has identified the risks to which its information assets – and clients – are exposed.
- It has appropriate measures (i.e., controls) to protect those assets.
- It has a clear action plan in case of an information security breach.
- It adheres to clear accountability and auditability principles: i.e. you know exactly who the individuals responsible are for each step of the information security process.
They Embrace Security by Design
Security by Design (SbD) means that security is considered an integral part of a project at the beginning rather than being layered in later as an afterthought. It means that appropriate security measures are hardwired into new systems or processes at the outset, helping you avoid costly-post-deployment security fixes.
You can learn a lot about whether a particular consultancy takes SbD seriously by the questions they ask you as part of any initial needs appraisal process. The main point of this is to establish how you operate, what you want to achieve, and what needs to be done to help you reach your goals. At the same time, however, an SbD-focused consultant should also explore areas such as the nature and sensitivity of the data you hold, who need access to it, and details of any specific regulatory frameworks that apply to your business. Right from this early encounter, a consultant should consider the information security risks your business faces and factor them into their proposals and recommendations.
They Maintain Appropriate Safeguards
It’s easy for a business to claim that they prioritise information security. The proof is in the action they take. If a consultancy takes its responsibilities seriously, you should expect to see the following types of safeguards in place:
- The consultancy has an information security policy in place
- Regular security audits and risk assessments are carried out
- They follow a recognised information security framework (e.g. ISO 27001). They have up-to-date accreditation to demonstrate this
- There are clear measures in place to protect client data, including encryption for data at rest and in transit, access controls, and secure storage
- Special care is taken with personally identifiable information (PII) and other categories of sensitive data. This includes GDPR compliance
- If they need to do system or application testing using PII, this is anonymized or pseudonymized beforehand
- Access to client systems and data is closely managed. This includes the application of the principle of least privilege (PoLP)
- Auditability is taken seriously: they can track and log consultant access to client environments
- Care is taken to revoke access after project completion
- Appropriate DevSecOps practices are followed for software implementations
- Incident response and disaster recovery plans are both in place and verifiable. This includes clear procedures for notifying clients in the event of an information security breach
Millennium Consulting: De-Risking Your Business Transformation Journey
Reputation counts for a lot when it comes to information security. The same goes for longevity.
In its 30-plus years of operating, Millennium Consulting has delivered significant business transformation projects for hundreds of organisations, including businesses in some of the most tightly regulated sectors out there.
Our approach to information security is a big part of our success and longevity. Far from being an afterthought, cyber and infosec best practices are hardwired into everything we do.
To discover more about de-risking and successfully transforming your business, speak to us today.
Millennium Consulting Awarded ISO27001 & ISO9001 Certification
January 2025
Updating and re-validation of our ISO 9001 & 27001 certification to the globally recognised UK Government UKAS standard. The ISO 27001 certification now aligns with the latest ISO 27001:2022 standard.


Financials Focus: Year End Process Recording
Millennium Consulting Webinar Series
Financials Focus: Year End Process
Recording from Thursday 30th January 2025
This session covered:
- What is a year end process in Unit4 Financials by Coda
- Pre-requisites to a year end
- Provisional year end
- Undo year end
Phil Leaf
Principal Unit4 Functional Consultant at Millennium Consulting
Phil is one of the world’s leading experts in the use of Unit4 Financials, with over 25 years of experience providing strategic advice, project management, implementation, and migration services for clients across the globe.

Xledger Partnership Announcement
February 2025
Millennium Consulting is delighted to announce it has signed a Partnership Agreement with accounting and financial management software company Xledger.
Xledger is a cloud-based finance software designed to automate financial processes, provide real-time insights, and scale with growing businesses.
“We are excited to announce the Millennium and Xledger alliance, a partnership that combines the strength of our companies. This collaboration will leverage Millennium’s expertise and customer-centric capabilities to expand our customer portfolio while sharing 30 years of industry best practices with a broader client base. Together, we are poised to deliver innovative solutions that drive success for our clients.”
— Jeremy Lucas, COO, Millennium Consulting
Xledger offers a comprehensive cloud-based ERP solution that streamlines financial management, automating key accounting, budgeting, and reporting processes. Its multi-entity, multi-currency, and real-time capabilities empower businesses to enhance efficiency, gain valuable insights, and drive growth.
“We are thrilled to be working with Millennium Consulting, our accounting software and their expertise in the market will support so many businesses going through finance transformation. Alongside our company cultures naturally aligning, our joint passion for innovative technology, expert advice and supporting businesses to thrive is the making for a great partnership.”
— Phil Chalmers, Strategic Partner Manager, Xledger UK
About Xledger
Xledger is one of the most automated and unified ERP systems on the market, designed to streamline financial management and enhance business performance. With five offices globally, Xledger empowers tens of thousands of customers worldwide, delivering real-time reporting, automation, and seamless multi-entity, multi-currency capabilities across industries.
About Millennium Consulting
Millennium Consulting is a trusted partner in delivering tailored technology solutions to businesses, backed by 30 years of finance and ERP implementation expertise. With a focus on customer-centric service and industry best practices, Millennium empowers clients to optimise operations and achieve long-term success.
Millennium Consulting Awarded ISO27001 & ISO9001 Certification
January 2025
Updating and re-validation of our ISO 9001 & 27001 certification to the globally recognised UK Government UKAS standard. The ISO 27001 certification now aligns with the latest ISO 27001:2022 standard.


Updated and re-validation in January 2024
Updating and re-validation of our ISO 9001 & 27001 certification to the globally recognised UK Government UKAS standard.
Updated and re-validation in January 2023
Updating and re-validation of our ISO 9001 & 27001 certification to the globally recognised UK Government UKAS standard.
December 2021
Millennium Consulting passed another ISO 27001 & 9001 audit with flying colours!
In December 2021 the highly successful recertification process was completed with no nonconformities identified in the audit. With special thanks to Mike Deal and Andre Peter for ensuring that we continue to conform to ISO standards internally and externally.
February 2021
Millennium is proud to announce that during December 2020 we obtained ISO27001 & ISO9001 certification.
While adhering to ISO guidelines in recent years, in 2020 the decision was made to formalise this via accreditation. After an intensive 9 month period, we are delighted to announce that this goal has been accomplished.
By gaining ISO 27001 & 9001 certification, we continue to demonstrate our commitment to providing quality service, effective cost management and timely delivery to our customers while at the same time anticipating their demands. In future we will continue to review our management systems, policies and information security management processes to achieve our ongoing objective of providing the highest quality service to our clients. Finally, to maintain our ISO status, we will continue to invest in technology, development and processes so we can best serve you, our customers.
Millennium Consulting Named Sales Growth Partner of the Year by Unit4
January 2025
We are thrilled to announce that Millennium Consulting has been awarded ‘Sales Growth Partner of the Year' by Unit4

This recognition, presented at the Unit4 SKO conference in Amsterdam, celebrates our exceptional growth and the strength of our long-standing partnership with Unit4.
"We are delighted to be named Sales Growth Partner of the Year by Unit4. This award is a testament to our strong collaboration with Unit4 and our shared commitment to delivering exceptional ROI to our customers.”
— Jeremy Lucas, COO

This achievement reflects our teams’ dedication, expertise, and collaborative efforts. It also reinforces our unwavering commitment to fostering innovation and delivering outstanding results for our clients.
Why choose Millennium for Unit4?
We are an Elite Unit4 Partner with over a decade of experience working with Unit4 systems. That means we have the knowledge and expertise to design, implement and support the right Unit4 solution for your business. We also make it easy to extend your system, providing additional applications that allow you to augment and tailor your solution to meet your needs.
Millennium Consulting awarded four Unit4 Partner Awards
January 2025
Millennium Consulting awarded four Unit4 Partner Awards




We are pleased to share that Unit4 has awarded Millennium Consulting four partner awards: Elite Commercial Partner, Elite Financials Services Partner, Select ERP Services Partner, and Select FP&A Services Partner.
Millennium Consulting has proudly upheld its Elite Partner status with Unit4 since the launch of the global partner program in 2020. The program is structured across three levels, emphasising capabilities, contributions, and customer satisfaction. Elite Partners represent the highest tier, awarded to those who consistently demonstrate exceptional success with Unit4 and deliver outstanding results for shared customers.
“Our long-standing Elite Partner status with Unit4 is a testament to the dedication and expertise of our team across all regions we operate in. This recognition reflects our unwavering commitment to fostering a strong, collaborative relationship with Unit4 while consistently delivering exceptional results for our clients. We are proud to maintain this standard of excellence and look forward to continuing our successful partnership with Unit4.”
— Jeremy Lucas, Chief Operating Officer at Millennium Consulting
Why choose Millennium Consulting?
We are an Elite Unit4 Partner with over a decade of experience working with Unit4 systems. That means we have the knowledge and expertise to design, implement and support the right Unit4 solution for your business. We also make it easy to extend your system, providing additional applications that allow you to augment and tailor your solution to meet your needs.
Events
Millennium's 30th Celebration
Millennium celebrates 30 years
Join us as we celebrate three incredible decades of innovation, partnerships, and success at Millennium Consulting. This milestone is a testament to the trust our clients, partners, and team members have placed in us over the years.
Date: Thursday 1st May 2025Time: 17:00 to 20:00
Venue: Moët & Chandon Bar, Hythe Imperial Hotel, Princes Parade, Hythe, Kent, CT21 6AE
RSVP
We would be delighted to have you join us for this special occasion. Please RSVP by 15th April 2025 to secure your place at the celebration.
Email us at events@millenniumconsulting.com or click the button below.
A look back at 30 years
Since our founding in 1995, Millennium Consulting has led in Finance Transformation, delivering transformative solutions that empower organisations worldwide. Over the past 30 years, we’ve worked alongside our clients to achieve remarkable milestones and look forward to the future with the same passion and dedication.
This anniversary marks an opportunity to reflect on the journey, celebrate our shared successes, and thank the people who have been instrumental in our success.
The venue
Moët & Chandon Bar, Hythe Imperial Hotel


Millennium+ for Unit4 ERP and ERPx
for Unit4 ERP and ERPx
Achieving long-term success with your Unit4 system requires more than generic support. In this blog post, Chris Peall, Director of Professional Services at Millennium Consulting explains how Millennium+ is a flexible, cost-effective framework that allows you to access precisely what your business needs to gain maximum advantage from your Unit4 solution.

Most business software calls for at least some expert input for ongoing support and optimisation. Unit4 ERP is a case in point. The solution equips you to integrate key business functions, eliminate data silos, and automate many of your most resource-hungry data processing and reporting tasks while delivering a rich seam of insights to support data-driven decision-making. It’s a lot. And to get the most out of this type of feature-rich application, it demands more than just the occasional walkthrough and a series of templates.
Bridging specific knowledge gaps
Businesses differ widely when it comes to the level and nature of support they require. Many of the organisations we work with benefit from frequent on-demand support and troubleshooting. Others already have significant internal Unit4 experience to draw on. However, especially with new and evolved functions arriving via Unit4’s continuous release process, they still need help getting the most out of new additions.
Every business is different, and when it comes to ERP support, you shouldn’t be pigeonholed into a package that either fails to bridge your gaps or is irrelevant to your business needs.
What is Millennium+?
Our Millennium+ framework provides Unit4 ERP and Unit4 ERPx customers with fully tailored support packages. As a result, you get the level and type of input you need, when you need it, and with the cost-efficiency and certainty that comes with a package approach.
What does Millennium+ consist of?
First and foremost, your Millennium+ package is tailored to meet your business needs. Depending on your circumstances, key elements of your package can include the following:
- On-demand day-to-day support for all modules and areas of the product
- Disaster recovery
- Personalised knowledge transfer
- Systems health check/ecosystem optimisation
- Implementation of new modules
- Integrations
Is Millennium+ a help desk?
Millennium+ is similar to a traditional help desk in some respects. However, it is much broader in scope – as well as being more proactive – than a traditional help desk setup.
Who provides the support?
Our team comprises a group of highly experienced individuals – both in our office and associate consultants – who constantly monitor inbound support requests via a portal.
Many routine support requests tend to be resolvable at this first point of contact. Where there is a need to escalate, there are always Unit4 ERP experts within easy reach across the organisation (one of the main benefits of being a Unit4 ERP Services Partner!).
What type of requests does the support cover?
The traditional help desk model tends to be confined to a relatively narrow range of technical issues and user queries (i.e. day-to-day troubleshooting). We certainly cover all of that. But alongside this, it also covers things like optimisation, integration, assistance with migration projects, and user training. Accounted for in 15-minute increments, it can all be part of your package.
For example, a user may have an urgent data issue. They submit a request, and we can jump right in and provide immediate assistance. At the same time, you realise that users will benefit from training relating to the issue raised in that request. We can plan this out and deliver it for you. And it’s all included in the same package.
What is Millennium+ personalised knowledge transfer?
Millennium Consulting can deliver whatever knowledge, guidance, or training you need in whatever method works best for your organisation.
Training can be conducted on-site or through our ever-popular remote sessions. We have a training manager who works across all our business units. So, whether it’s a one-on-one best practice update, an onboarding session for some of your new starters, a Microsoft Teams classroom with an entire team of your colleagues logged in, or an on-site workshop, we can provide it. All delivered within your Millennium+ subscription, with no uplifts for different delivery methods or caps on the number of attendees.
What is Millennium+ systems health check/ecosystem optimisation?
When you first implemented your Unit4 system, it closely aligned with your organisation’s expectations. Over time, your version of the system has evolved; you’ve implemented some (but not all) upgrades, various add-ons have arrived at different points, and some features you used to rely on have somehow fallen out of favour. And, of course, your business has changed, too. What you expect from planning, reporting, and strategic management software may have diverged significantly from when you first implemented your system.
Our systems health check speaks to this reality.
A useful starting point involves us going in and speaking to the teams who use the solution daily and senior stakeholders. Through consultation, we address the following types of questions:
- What specific questions do you want your ERP system to answer?
- How well does your existing system meet your needs, and what’s missing?
- What pain points are users experiencing?
- How can existing processes be made more efficient?
- What other systems / digital transformation initiatives do you have in play, and how successfully does Unit4 ERP integrate with these other elements?
Cataloguing our findings, we can then analyse your setup and processes and produce a white paper detailing a prioritised matrix of recommendations, from the low-hanging fruit changes you can make right now at little or no cost to more significant changes to consider in the future.
How does Millennium+ deliver full transparency?
Have you ever had a service agreement where you constantly wondered whether it’s all worth it? At Millennium Consulting, we take a very different approach.
Transparency is fundamental for any successful long-term relationship. A big part of this should mean complete openness to how your package is being put to work (in other words, that all-important question of where, precisely, your money is going).
Using Power BI, we give you a near real-time multidimensional reporting suite, giving you full visibility of progress and budget across all work streams. You can see how your requests are managed, their breakdown, how long they take, who’s submitting them, who’s dealing with them, and related comments.
Our Packages
Tiers can be frustrating, especially when you’ve signed up only to realise later that the input you need is several notches up from the level you’ve agreed to and budgeted for.
Millennium+ is different. Every package opens every avenue of our expertise right across our business. So even if you buy the minimum amount of time from us (eight hours in a 12-month rolling period), you can access our entire professional service team.
This includes:
- The core central support team
- Input as and when required from project managers, solution architects, enterprise architects, test managers, and developers across multiple disciplines
- Input beyond the ERP realm, including building up your capabilities across advanced planning and analytics, evolving compliance reporting needs, big data, AI, and advanced automation
For example, for a general appraisal of your needs, one of our business analysts can join you for a call, capture some requirements, deliver detailed recommendations, and it can all be billed against your time.
With Millennium+, no area of digital transformation is out-of-bounds. Whatever blend of expertise you will benefit from most – from routine troubleshooting and report optimisation to hands-on input on your next major data-driven project – it’s all at your fingertips.
Find out more
Get in touch to learn more about Millennium+ and explore putting together a cost-effective package that is fully aligned with your needs.
(Article written and published January 2025)
Financials Focus: VAT & Making Tax Digital
Millennium Consulting Webinar Series
Financials Focus: VAT & Making Tax Digital
Thursday 6th November 2025 at 14.00 p.m. UK
Duration: 30 minutes
Join Millennium Consulting’s Webinar Series, Financials Focus event on VAT & Making Tax Digital in Unit4 Financials by Coda.
Thursday 6th November 2025 at 14.00 p.m. UK for 30 minutes
Discover how to optimise VAT processes and ensure compliance with Making Tax Digital (MTD) in Unit4 Financials by Coda. This session includes a live demonstration of MVAT, Millennium’s HMRC-recognised Making Tax Digital software. MVAT ensures compliance with mandatory MTD requirements and is seamlessly integrated into Unit4 Financials by Coda.
Agenda:
- Introduction to VAT accounting in Unit4 Financials by Coda
- Making Tax Digital
- Set up of MVAT
- Mapping Table
- MVAT Report
- Users
- Demo of MVAT
N.B. You will receive a link to the session after registering.
Presented by
Phil Leaf
Principal Unit4 Functional Consultant at Millennium Consulting
Phil is one of the world’s leading experts in the use of Unit4 Financials by Coda, with over 25 years of experience providing strategic advice, project management, implementation, and migration services for clients across the globe.

Ben Hart
Application and Information Security Consultant at Millennium Consulting
Ben is the Principal Information Security Consultant at Millennium Consulting, bringing a wealth of Cyber Security Auditing and Policy experience. Before joining Millennium, Ben spent 15 years in a high-risk and highly regulated industry.

Did you know...
We are an Elite Unit4 Partner
We are an Elite Unit4 partner and a leading reseller around the world. That means we have the knowledge and experience to design, implement and support the right Unit4 Financials solution for your business. We also make it easy to extend your system, providing additional applications that allow you to augment and tailor your solution to more closely meet your needs.
Financials Focus: VAT & Making Tax Digital
Millennium Consulting Webinar Series
Financials Focus: VAT & Making Tax Digital
Wednesday 5th March 2025 at 14.00 p.m. UK
Duration: 30 minutes
Join Millennium Consulting’s Webinar Series, Financials Focus event on VAT & Making Tax Digital in Unit4 Financials by Coda.
Wednesday 5th March 2025 at 14.00 p.m. UK for 30 minutes
Discover how to optimise VAT processes and ensure compliance with Making Tax Digital (MTD) in Unit4 Financials by Coda. This session includes a live demonstration of MVAT, Millennium’s HMRC-recognised Making Tax Digital software. MVAT ensures compliance with mandatory MTD requirements and is seamlessly integrated into Unit4 Financials by Coda.
Agenda:
- Introduction to VAT accounting in Unit4 Financials by Coda
- Making Tax Digital
- Set up of MVAT
- Mapping Table
- MVAT Report
- Users
- Demo of MVAT
N.B. You will receive a link to the session after registering.
Presented by
Phil Leaf
Principal Unit4 Functional Consultant at Millennium Consulting
Phil is one of the world’s leading experts in the use of Unit4 Financials by Coda, with over 25 years of experience providing strategic advice, project management, implementation, and migration services for clients across the globe.

Ben Hart
Application and Information Security Consultant at Millennium Consulting
Ben supported MVAT during development and recognition with HMRC as a hybrid consultant for Application and InfoSec. Before joining Millennium, Ben spent 15 years in the high-risk and highly regulated industry.

Did you know...
We are an Elite Unit4 Partner
We are an Elite Unit4 partner and a leading reseller around the world. That means we have the knowledge and experience to design, implement and support the right Unit4 Financials solution for your business. We also make it easy to extend your system, providing additional applications that allow you to augment and tailor your solution to more closely meet your needs.