Our expertise
Our services
Who we serve
Insights
About us
Digital Threat Digest Insights Careers Let's talk

Is ISO 27001 what your organisation actually needs?

ISO 27001 is a well known standard, but before you invest significant time and money, read our article to confirm if it's the right next step in your cyber security journey. 

Yomi Ogundairo, Information Security Consultant's photo
Yomi Ogundairo, Information Security Consultant
Double circle designs part43

ISO 27001 has become a default solution when it comes to demonstrating that an organisation takes information security seriously. An increasing number of organisations, clients and partners are requesting certification to strengthen supply chains and gain assurance that the businesses they work with are managing information security properly. It’s easy to see how this can start to look like something all organisations should have.

But, the common misconception is that every organisation needs—or should be working towards—ISO 27001 certification. Others believe that it automatically means their business is secure. In reality, it’s about building effective governance and risk management through a strong Information Security Management System (ISMS) and continually improving security over the long-term. The certificate is the evidence that this is all happening, not that it’s a problem solved.

This all might sound counter-intuitive coming from a consultancy that frequently does this kind of work, but we believe there’s more value in honest support that aligns with an organisation’s current maturity rather than defaulting to ISO 27001 because it's a widely known standard.

If you’re considering ISO 27001, read this article to make sure it’s the right fit for your business. 

When ISO 27001 is the right fit

ISO 27001 delivers the most value when there is a clear and direct business need, such as:

  • Meeting customer or contractual requirements
  • Protecting highly sensitive information
  • Operating in a regulated industry
  • Introducing a more structured and mature approach to cyber security governance

Ultimately, the organisations that get the most out of ISO 27001 are the ones that see certification as an outcome, not the objective. The aim should always be to improve your organisation's actual security posture, with the certificate following as a result.

When another framework is a better starting point

ISO 27001 isn't always the right place to begin, especially for small to medium-sized businesses who are early in their cyber security maturity. We believe that choosing the appropriate framework for where your organisation actually is today, rather than the one with the most name recognition, often produces a better security outcome and a better return on investment.

Alternatives to ISO 27001:

  • Cyber Essentials certification is often a better fit for organisations as a starting point. It’s cheaper, lower effort and is a great way to demonstrate your organisation has the government’s recommended fundamental cyber security measures in place.
  • NIST CSF works well for businesses looking to improve their overall cyber maturity, without necessarily pursuing formal certification.
  • SOC 2 tends to be the more relevant choice for SaaS organisations, where customer assurance around how data is handled is the primary driver.
When you might need guidance rather than a formal standard

We always recommend taking a deep dive into why certification is being considered in the first place. 

If you're expecting ISO 27001 to:

  • Automatically make your business secure
  • Provide you with ready-made policies and procedures that fit your business 
  • Automatically help you win new clients
  • Be a quick, easy win
  • Be a one-off tick box exercise 
  • Remove the need to complete supplier questionnaires (without confirmation from the requesting entity that this is acceptable)

...then certification is likely not going to deliver what you're actually looking for. These are the expectations that tend to lead to disappointment further down the line, because the certificate alone doesn’t actually achieve those goals.

In these cases, working with a Trusted Advisor to guide you and help you understand what your organisation genuinely needs at your current maturity is often more valuable than pursuing a standard for its own sake.
 

Simple ISO 27001 decision checklist

Some useful questions you should ask before investing time, money and resources:

  • Who is asking for ISO 27001 and why are they asking for it?
  • Is there a regulatory or contractual obligation driving this?
  • Will certification help us win or retain business?
  • Do we handle highly sensitive or confidential information?
  • Do we have foundational cyber security controls and policies in place?
  • Do we have the commitment and resources to maintain certification over the long-term?

If you answered YES to most of these, ISO 27001 is likely to be the right choice.

If you need further help from an expert to figure out ifISO 27001 is right for your organisation, or would like guidance on the next move in your cyber security journey, get in touch with us.