ISO27001 Made Simple

Everything you needed to know about ISO27001 explained in plain English

We know you have questions, and we have answers (well, some of them anyway!)

Building an Information Security Management System (ISMS) which is aligned to ISO27001 is a little like winning in a Formula One driving competition.  Now, I’m no ‘petrol head’, but even I know that to be successful requires a mix of skills and capabilities in the area of technical, people and process.  That’s what ISO27001 is all about – People, Process and Technology.  

In the links below you will find answers to questions you may have had, but if we’ve missed something please let us know.

 

ISO27001 ISMS Pitstop

What is ISO 27001?

ISO 27001 is an internationally recognised standard for managing information security. In simple terms, it helps businesses protect information properly whether that’s client data, financial records, employee information, intellectual property or internal systems.

Keep in mind that ISO 27001 is NOT just about IT… It’s about people, processes, systems (IT) and providers.  So please don’t think you can give this to your IT lead and think this is something that will be ‘done’.

But for most SMEs, ISO 27001 isn’t about paperwork or ticking boxes.

It’s about proving:

  • you take security seriously
  • you manage risk properly
  • your business can be trusted

That matters more than ever because clients, suppliers, and procurement teams increasingly expect businesses to show evidence of good security practices before they’ll work with them.  So if you want to win more clients, ISO 27001 might actually help you do just that!

However, the problem is that many business owners hear “ISO 27001” and immediately picture:

  • endless documentation
  • technical jargon
  • expensive consultants
  • months of disruption

In reality, good ISO 27001 implementation should bring clarity and structure – not chaos. Of course there will be a cost, no matter which approach you take (Just like building an extension on your house… YOU can do it yourself, but if you need help then of course there will be a cost…. but remember that the greatest price we ever pay is time(!))

But remember that the goal isn’t perfection, and that’s important (especially for SME’s)
It’s about building sensible, practical systems that reduce risk, improve credibility, and help the business grow with confidence.

There are several benefits to achieving ISO27001, and you can read these here.

At its core, ISO 27001 simply means:

Understanding your risks, protecting important information, and having clear processes in place so nothing critical gets missed

What is ISO27002?

Great question… There are a number of guidance documents within the ISO27000 ‘family’.  ISO27002 is just one of them.  It provides detailed explanations on what you should consider when implementing the 93 controls of Annex A (contained within ISO27001).

The important thing to remember is that ISO27001 talks about what you shall put in place, and ISO27002 talks about what you should put in place.  It is guidance. It is not a standard and therefore you cannot be certified against ISO27002.

 

Who needs ISO27001?

No matter if you’re handling personal information, financial data, or commercial data, it’s clearly important and valuable to you (and your clients).  Understanding how to protect it is therefore critical to you and your organisation, and ISO27001 is your best approach to implementing a system that helps you protect it.

Consultants Like Us would of course recommend that every organisation has implemented this standard, and it’s not just because we help people achieve it. It’s because we believe in what it is there to do – make us all safer and more secure.

In truth however it is NOT mandatory, and is is therefore completely discretionary.  So the real question is do YOU need ISO27001?

​​Ask yourself these questions;

  • Are clients asking for it?
  • Are you spending money on security without knowing why?
  • Are you looking to scale your business?

If your answer to any of the above is YES, then you need it.

ISO27001 offers a road map to a more trusted and secure business. This is why we all need it.

How much does ISO27001 cost?

As a wise man once said to me; If you measure everything by cost, you won’t see the value in anything.

​​But lets get serious; The answer is always “it depends” right? Well, sort of. But let me try and break it down for you, and show you some typical, tangible costs;​

  • Do it yourself – Using ChatGPT – £0
  • Do it yourself – Using templates – £100 – £800
  • Do it WITH you (Using Consultants Like Us) – £2,500 – £15,000
  • Certification Body (stage 1 and stage 2) – £4,000 – £7,000

So you can see there is a big leap from doing it yourself and bringing in a professional. Just remember that the Certification Body costs are non-negotiable – no matter which approach you take, you have that cost to bare.

But that’s true of anything, right?

Want to fit a new kitchen? Sure… Do it yourself and costs are low.  Bring in an expert and suddenly it’s a lot more expensive.

The questions you have to ask yourself are;

  • What value do you place on your time?
  • How quickly do you want this done?
  • What assurances do you need that you will be certified AND more secure?

Do your research, but make sure you factor in the cost of your time and what your true goal is.

How long does ISO 27001 take?

For most SMEs, ISO 27001 typically takes anywhere from 3 to 12 months depending on:

  • the size of the business
  • how much is already in place
  • internal availability
  • client requirements
  • the complexity of your systems and processes

Businesses that already have:

  • documented processes
  • good operational structure
  • clear leadership
  • basic security controls

…usually move much faster, but the biggest delays rarely come from the standard itself.

They usually come from:

  • lack of time (probably the BIGGEST reason)
  • unclear ownership
  • trying to figure everything out internally
  • overcomplicating the process

That’s why many SME owners feel stuck before they even begin, but the good news is ISO 27001 doesn’t need to take over the business!

With the right structure and guidance, most businesses can make steady progress without overwhelming the team or stopping day-to-day operations.

A practical approach usually works best:

  • identify the gaps
  • identify your critical assets
  • prioritise the important areas
  • build manageable processes
  • improve things step-by-step

The businesses that succeed fastest are rarely the “most technical.” They’re usually the ones with:

  • clear leadership
  • a realistic plan
  • consistent implementation

Do SMEs really need ISO 27001?

No… Not every SME needs ISO 27001.

But many businesses are increasingly finding they need it sooner than they expected.

Common reasons include:

  • clients asking security questions during tenders
  • supplier requirements
  • handling sensitive information
  • growing cybersecurity concerns
  • needing to stay competitive
  • preparing for larger contracts

For some businesses, ISO 27001 becomes essential because clients simply won’t move forward without evidence of proper information security controls.

For others, it’s about reducing risk and building stronger internal processes before problems appear.

One of the biggest misconceptions is:

“ISO 27001 is only for large enterprises.”

That’s no longer true.

More SMEs are now being asked to demonstrate:

  • data protection
  • security controls
  • risk management
  • operational resilience

Especially in sectors like:

  • manufacturing
  • finance
  • SaaS
  • professional services
  • supply chain businesses
  • technology providers

The important thing is approaching ISO 27001 in a way that fits the size and reality of the business.

A small business doesn’t need enterprise-level bureaucracy. It needs practical, manageable processes that reduce risk without creating unnecessary complexity.

Of course there are lots of benefits to implementing ISO 27001. We even wrote a blog to outline some of the key benefits, which you can find here.

Is ISO 27001 difficult for small businesses?

ISO 27001 can feel overwhelming at first for small businesses, especially if no one internally has experience with compliance or information security.

The challenge is rarely intelligence or capability.

It’s usually:

  • lack of time (notice this comes up a LOT)
  • uncertainty about where to start
  • technical jargon
  • fear of getting something wrong
  • trying to interpret complex requirements alone

That’s why many SMEs delay it for months or even years.

The standard itself is manageable, but what makes it difficult is:

  • overcomplication
  • poor guidance
  • unrealistic expectations
  • trying to copy enterprise-level approaches

Small businesses do not need massive corporate systems to become compliant.

They need:

  • practical processes
  • sensible controls
  • clear priorities
  • realistic implementation

The businesses that struggle most are often the ones trying to “figure it all out” internally without a clear roadmap.

The businesses that succeed usually approach ISO 27001 step-by-step, focusing on steady progress rather than perfection.

Done properly, ISO 27001 should ultimately make you and the business feel:

  • more organised
  • more secure
  • more credible
  • less reactive

Not more stressed! 

Can we pass ISO 27001 without an internal compliance team?

Yes, many SMEs achieve ISO 27001 without having a dedicated internal compliance team.

In fact, that’s one of the most common situations for growing businesses.

Most SME owners are already juggling:

  • operations
  • sales
  • staffing
  • client delivery
  • finance
  • day-to-day problem solving

They don’t have spare departments sitting around waiting to manage compliance projects.

The key is not having a huge team. It’s having:

  • clear guidance
  • practical processes
  • sensible documentation
  • accountability
  • ongoing support

A good ISO 27001 approach should simplify the process, not bury the business in unnecessary admin.

Many businesses successfully achieve certification by:

  • assigning internal responsibility clearly
  • getting external guidance where needed
  • implementing practical controls gradually
  • building systems around the way the business already operates

The goal isn’t to become a compliance company.
It’s to build a secure, trustworthy business without losing focus on the work that actually pays the bills.

How do I become ISO27001 certified?

If you decide to take the plunge and want to go through the process, then follow these steps are you’ll be well on your way to achieve certification.

  • ​​Buy the ISO27001 standard
  • Buy the ISO27002 guidance
  • Read them (both)
  • Complete a gap analysis between where you are, and what is required in ISO27001
  • Create a ‘to do’ list
  • Identify your most important assets (physical and virtual)
  • Identify the risks to these assets
  • Action your ‘To Do’ list (to protect these assets)
  • Sign-up a Certification body (someone like Approachable Certification) for your Stage 1 and 2 audits
  • Agree dates for Stage 1
  • Agree dates for Stage 2
  • Run your external audits
  • Celebrate with a big mug of Yorkshire tea (there is no other tea available).

Of course there are tasks you need to complete, like conducting audits, running managerment reviews, testing of BC plans and training.

If all that sounds like too much, Consultants Like us have a simple four step process that takes all the above into account;

  • Discover – Where we learn all about you and your business
  • Design – Where we design the ISMS around you
  • Develop – We develop the ISMS so it firs you perfectly.
  • Deploy – We implement the standard so it works FOR you, not against you.

Remember that we provide ‘Compliance without Complexity’ (anyone can make something complicated). We want to make security easy for you and your business.

What happens during an ISO audit?

An ISO 27001 audit is essentially a review of how your business manages information security in practice.

The auditor is not expecting perfection.

They’re looking for evidence that:

  • your processes exist
  • people understand them
  • risks are being managed properly
  • controls are being followed consistently

For many SME owners, the word “audit” creates instant anxiety.

They imagine:

  • aggressive questioning
  • technical interrogation
  • being caught out publicly

In reality, a well-prepared audit should feel structured and manageable.

A typical audit may include:

  • reviewing policies and documentation
  • discussing security processes
  • checking risk management activities
  • looking at staff awareness
  • reviewing evidence of implementation
  • identifying areas for improvement

There are two main stages:

  • Stage 1: reviewing readiness and documentation
  • Stage 2: assessing how processes work in practice

Auditors understand that SMEs operate differently from large corporations, so what matters most is whether your approach is:

  • sensible
  • consistent
  • documented
  • actively maintained

Good preparation removes most of the stress. That’s why businesses often benefit from guidance before the audit begins so there are no unpleasant surprises later.