The illusion of the technical security project
When B2B companies decide to pursue ISO 27001 certification, the focus at the beginning is almost always on technology. Discussions revolve around encryption standards, multi-factor authentication (MFA), vulnerability scanners, and access control lists.
Engineering and security teams are well prepared for these tasks. The technical controls (Annex A of the standard) can be implemented and automated relatively quickly with the right tools.
The real audit risk, however, lies elsewhere: in human behavior and operational processes.
Why ISO 27001 is a culture and process project
ISO 27001 does not require a fixed technical setup, but rather a functioning Management System (ISMS). This means that security must be continuously planned, executed, checked, and adjusted (PDCA cycle).
In practice, three non-technical hurdles typically arise:
1. Leadership responsibility instead of IT delegation (Leadership & Governance)
Chapter 5 of ISO 27001 sets clear requirements for management. An auditor checks not only whether a security policy exists, but whether the management team actively embodies it and provides the necessary resources.
If management does not sign off on risk assessments or lets management reviews slide, even the most modern SIEM tool will not help. Information security must be anchored as a core strategic task of the company's leadership.
2. Verifiability instead of gut feeling (Evidence Management)
One of the most important basic rules in an audit is: If it isn't documented, it didn't happen. The challenge lies in continuously generating evidence in everyday operations without overloading teams with manual work:
- Were access reviews actually conducted quarterly?
- Was the new employee's onboarding completed exactly according to policy?
- Is there a documented change request for the modification to the production environment?
The operational effort required for continuous evidence collection is often massively underestimated at the start of a project.
3. Employee acceptance (change management)
An ISMS only works if the staff understands and supports the security measures. If policies are perceived as mere harassment, shadow IT and everyday risks will inevitably emerge.
A security culture is not created by distributing 50-page PDF documents once. It is built through:
- Pragmatic policies: Rules must fit the company's actual workflow.
- Continuous training: Practical training instead of abstract theory.
- Clear responsibilities: Every team member knows their role in incident management and data protection.
Compliance as infrastructure: Designing pragmatic processes
To prevent ISO 27001 from devolving into rigid paper bureaucracy, the ISMS should be integrated directly into existing workflows:
- Leveraging interfaces: Manage access reviews and change management directly within the systems already in use (e.g., GitHub, Jira, HR tools) instead of maintaining parallel Excel lists.
- Standardization instead of isolated solutions: Structure the established processes so that they can simultaneously be used for other use cases such as GDPR, SOC 2, or NIS2.
- Maintaining process scoping: Define the scope precisely at the beginning, rather than immediately overwhelming the entire company with overly complex requirements.
FAQ
How much time should be planned for change management?
How much time should be planned for change management?
Building awareness and establishing new routines within the team often takes just as much time as closing technical gaps. It is therefore advisable to involve the affected departments, such as HR, Development, and Operations, in defining the new processes at an early stage.
Can compliance automation tools replace cultural change?
Can compliance automation tools replace cultural change?
No. Automation tools can significantly support technical evidence collection and monitoring. However, they cannot compensate for missing approvals, insufficient management involvement, or employees failing to follow defined processes in their day-to-day work.
What happens if an employee violates an ISO 27001 policy?
What happens if an employee violates an ISO 27001 policy?
The ISMS must include mechanisms for handling deviations and non-conformities. A transparent approach to mistakes is essential: the underlying causes should be analysed and processes adjusted where necessary to prevent similar incidents from recurring.








