ISO 27001 – Does a small business need it?

Will a small business benefit from ISO 27001?

Imagine you’ve just started your own business. It’s going well and over the last 12 mths more and more customers are coming to you, and you’ve even taken on your first member of staff.

But then disaster strikes… and you’ve been hit with a virus!

  • All your files … gone.
  • All your work… gone.
  • All the trust built up over months… gone.

This happened to a small business owner I met at an event recently.  The business closed shortly after, and they returned to full-time employment.

Running a small business is not easy, there are so many things to think about and possibly the last thing people want to do is implement an ISO standard… but it’s incredibly important, as that business owner discovered.

But is ISO 27001 mandatory?

When people ask me if a small business needs ISO 27001:2022 I reply, “No… not all small businesses need it. But all businesses can benefit from it.”

ISO 27001 is not mandatory, but having it, and building an effective Information Security Management System (ISMS) could be a game changer for a number of reasons. and I think it’s worth exploring these reasons here, so that you can make an informed decision.

ISO 27001 is for SMEs too

The Pros

As a small business you have many hats; You are the finance director, head of operations, sales AND marketing, and IT too! On top of this you need to comply with the law (obviously). This means you need to think about Data Protection, and in particular you need think about the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.

You also need to think about keeping all that precious data secure. Your customer records, your financial data, and orders need to be protected.

Clients love it

Having ISO27001 in place helps you to structure your thinking around data security, which is not only useful for demonstrating compliance to data protection laws, it’s a great indicator to your clients that you take security seriously.

Having invested in ISO 27001 means that you can easily demonstrate that you are a trusted partner which builds customer confidence in you.  They will be happier in the knowledge that should the worse happen, you’ll notify them in timely fashion, thereby building further trust.

But this isn’t the only benefit for clients… it helps with prospective clients too.

Good for business growth

If you want to grow your business then you know you need to differentiate your business from your competitors, and building trust with your clients is a great way to do this.  As you try and win bigger contracts, and collect those ‘big logos’ as customers, you’ll find that they ask more and more questions about your security. 

Supplier Questionnaires will become increasingly difficult to answer if you haven’t thought about data protection and security.  ISO27001 structures your thinking in this area and allows you to either point to your official ISO 27001 certificate, or explain what you do more clearly.

Improved efficiency

As a small business you may find that your business grows up around you. This means that inefficiencies will creep into your business, and this may lead you to be a little less productive than you could be.  ISO 27001 requires that you look at how you process data, and therefore think about who uses it, how and why.

Through this process you may find better ways to run your business and therefore save time and money in the process.

Reduce losses

With improved efficiency, you may also see areas that could result in errors or data breaches, so ISO 27001 could actually save you money (and your reputation).  ISO 27001 is focused on Confidentiality, Integrity and Availability , and you should consider the risks to your business based on these areas.  What could go wrong and could result in negative impact on you? 

Ultimately ISO 27001 is about ‘security’, which means that you’re trying to secure the information that has been entrusted to you.  ISO27001 gives you confidence that you’re less likely to suffer the negative effects of a data breach or cyber attack.

If you are unlucky enough to suffer a breach, as the business owner did at the start of this blog, you’ll be better prepared to respond to the event because ISO 27001 requires that you have developed an incident response plan (A5.24 Information security incident management planning and preparation) and business continuity plans. 

But more importantly, you’ll have processes in place to prevent this kind of event happening in the first place.  As the saying goes; Prevention is better than Cure! And this holds true for Cybersecurity.

The benefits of ISO 27001

The cons

Before you get too excited about the idea of implementing ISO 27001, let’s discuss some of the downsides.

Firstly, there is a cost and that cost is both in financial terms and time.  If you are going for formal certification to ISO27001 the financial costs are not inconsiderable because you need to assign a certification body (CB) that is part of UKAS. 

Not all Certificates are the same.

Don’t waste your money (or time) with a CB that isn’t UKAS accredited. There are a lot of businesses out there that will charge you to do the consultancy and build your ISMS, then they will audit you against that ISMS that they built(?) and (amazingly) you’ll pass!!

This is a little like your driving instructor teaching you to drive, then giving you a test to see if you’ve learnt to drive well, and then giving you your driving licence?!  Would YOU trust that process?  How safe do you think this is? And where’s the impartiality in this?

ISO 27001 for SMEs getting your oil changed is important

 So please do yourself a favour; If you’re investing in getting the certificate you should seek a UKAS certification body.  

For a small business you are looking at around a £4,000 cost, and that is just for the external audits you’ll need to complete.

It takes time and effort

The other cost you need to think about is your time. You have work to do, even if you bring in Consultants Like Us.

This is because the ISMS needs to reflect you and it needs to reflect truth, so we’re going to spend time with you going over everything, and then once we develop all the mandatory documents (policies and procedures), you’ll need to review them and sign them off. 

They are yours, and ultimately you are accountable for security.  

This is where a lot of people come unstuck because they go out on to the Web and download a bunch of policies that aren’t great, or worse still, buy policies that are just full of tools you don’t need.  Don’t get me wrong, there are some fantastic resources out there… but as the saying goes ‘Buyer beware’!

There are some truly awful policy packs that are put together by people whose only interest is to make their policy pack look like it’s worth the ££££ that you’re paying, but you don’t need them (and … they look awful too!).

It’s important to caveat this by saying you also don’t always need Consultants Like Us either.  

We are the experts at this. We know what we’re doing, so we know how to use the tools in an effective way. But of course you can do it yourself, as long as you have the tools and the knowledge then there’s a good chance you’ll build something to be proud of.

All I’m saying is that your choices are pretty simple;

  • DIY – Buying the tools (or getting ChatGPT to create them!)
  • Do it with help – Consultants Like Us will guide you and do the heavy lifting. 

Just keep in mind that it will taketime for you to create the framework, the policies and procedures and all the evidence needed to demonstrate compliance.

The question you have to ask is; Do I want to do it myself? Or should I get expert help? .

Want to get started?

Before answering this question, let’s return to the original question – Does a small business need ISO27001?

The answer is “No because it’s not mandatory”. You don’t need to be certified to the standard, but we would recommend that every business needs to look at ISO27001 carefully and at the very least align to it.

But where do you start? I would suggest if you’re a small business, do away with the first part of ISO27001 (Clauses 4 to 10), and focus on the ISO 27001 Annex A controls at the back.

This may sound controversial but we’ve been where you are, and a lot of what is in the ISMS needs carefully unpacking to understand what’s needed and how to implement it. But Annex A is a little more directional, as it sets out very clear expectations on you.

In the Annex A controls you’ll find 93 controls which need to be considered for your organisation.  This might sound onerous, but note the word considered. You don’t have to apply them all.  What is applicable to you? What is of relevance?

ISO 27001 is like a recipe for good security. It gives you a list of items that you should consider, but it’s up to you if you use them or not.

Once you are comfortable with the controls, return to the first part of the standard and work your way through it. 

When you are happy with the approach you’re taking to the ISMS you can continue in that way until you feel you are ready (or required) to go for formal certification.

If you’re already at that stage, then get in touch and we will help you all we can.  Alternatively you can buy our book, The Real Easy Guide to ISO27001 which should help. 

If you have more questions, then get in touch and we can help with your specific question. No question is too big or small, we’d love to hear from you.

ISO 27001 questions that people often ask

FAQ

What makes ISO 27001 a difficult process?

ISO 27001 can quickly become a beast! Many people make it difficult by over complicating the whole process. We always say you can’t protect what you don’t understand so start with understanding your level of compliance today.  Buy a copy of the standard and read it, and as you read it, simply ask yourself “Do we do these things?” 

From there you can create an action plan to address the gaps and that becomes the basis of your work for the next 6mths.  There are lots of guides out there, and we even created an app ‘Consultants in your pocket’, which is available on both Android and Apple devices.  It’s just £4.99, so there’s really no excuse for not having a copy of the standard in your hand (or in your pocket!

Where do I start?

Start from where you are, and and then find your why… I know that sounds so simple but it’s true.  Review the question above to understand how to get a view of where you are today, but also ask yourself WHY you want to achieve ISO 27001 certification. 

Remember that it’s not mandatory, but neither is staying healthy!  WHY do you want to improve your health/security? Are you being told you must improve it? Are customers demanding it? Are investors interested in buying you but concerned about your data security?

You need a compelling WHY otherwise you’ll lose focus and momentum will quickly follow.

Are SMEs really a target of Cyber attackers?

Unfortunately yes. There are lots of statistics and reports that tell us that cyber attackers are targeting smaller businesses, so the facts are there to be read and understood (if you care to read them).

According to the UK governments reports on Cyber attacks in 2024 

Half of businesses (50%) and around a third of charities (32%) report having experienced some form of cyber security breach or attack in the last 12 months. This is much higher for medium businesses (70%), large businesses (74%) and high-income charities with £500,000 or more in annual income (66%).

But stats aside, the reason that cyber attackers target SMEs is for very simple and obvious reasons; SMEs have less money and time to defend themselves against attack.  It sounds harsh but SMEs are an easy target.  Worse still, if you are a victim of cyber crime the likelihood is that law enforcement won’t investigate the crime too heavily because they know the chances of finding the criminals is low.

To put it simply; Imagine YOU are a criminal… Who would YOU target? Would it be a large financial institution that has invested heavily in technical security and other controls, and are well prepared for an attack. And if they are attacked, will have law enforcement there to assist (due to the size and scale of the institute).

Or would you attack a small business that has neither the resources nor the support of law enforcement should they even discover they have been attacked?

ISO 27001 puts you, the SME in the driving seat and ensures that you are prepared for an attack, and you know how to respond effectively.

ISO 27001 may seem like an uphill struggle

Conclusion

ISO 27001 may feel like an uphill struggle at times. But in an era that relies so heavily on data and technology we can’t afford to leave security to chance. With the right training, the right support and the right knowledge you’ll be better placed to succeed and reach the summit.

SMEs are the life blood of a nation. They are the beating heart of the community and they are also an easy target for attackers.

We can’t leave it to the government to protect us so we need to take actions to protect ourselves.

If you’re an SME and you want to know how to implement ISO 27001 then get in touch for a free online quote and we can help protect you, your reputation and your livelihood.