ISO 27001 EXPLAINED
What is ISO 27001? The information security standard, explained plainly
ISO 27001 is the international standard for an information security management system: a documented, audited way of managing how your organisation protects its data. This page explains what the standard covers, when a business actually needs certification, how it differs from the frameworks and roles it gets confused with, and how to get there without buying a stack of templates you never use.
Book a conversationWhat ISO 27001 actually is
ISO 27001 is a certifiable standard published by the International Organisation for Standardisation that defines the requirements for an information security management system, usually shortened to ISMS. An ISMS is not a piece of software. It is the set of policies, processes, risk decisions and controls your organisation uses to keep information confidential, available and accurate. The standard tells you what good looks like and lets an independent auditor verify that you are doing it. The current version is ISO 27001:2022, and its companion document ISO 27002 describes the controls in detail.
The point of certification is evidence. A certificate from an accredited body says a third party has examined how you manage security and found it sound. That is why buyers, regulators and large procurement teams ask for it: it replaces a leap of faith with an audited fact.
What the standard actually requires
ISO 27001 is built around risk. You define the scope of what you are protecting, identify the risks to that information, decide how to treat each one, and then run the whole thing as a continuous cycle rather than a one-off project. The standard sets out management clauses covering leadership, planning, support, operation, performance evaluation and improvement. Alongside these sits Annex A, a catalogue of controls spanning organisational, people, physical and technological measures.
Crucially, you are not required to apply every control. You select the ones your risk assessment justifies and record your reasoning in a Statement of Applicability. That document, your risk treatment plan and evidence that the system is genuinely operating are what the auditor scrutinises. This is the same risk-led discipline that good cyber security consulting brings to any security programme, certified or not.
When a business actually needs ISO 27001
Most organisations pursue ISO 27001 for a commercial reason rather than a regulatory one. The usual trigger is a customer or partner who will not sign without it, a tender that lists it as a requirement, or a sales cycle that keeps stalling on security questionnaires. SaaS companies, managed service providers, and any firm handling sensitive client data tend to reach this point as they move up market.
There are also strategic triggers. Investors conducting technology due diligence view certification as a sign of operational maturity. Boards weighing cyber governance use it to demonstrate that security is managed, not improvised. And firms in regulated sectors, including those building toward NIS2 compliance or operating in financial services, often find an ISMS gives them a coherent structure to satisfy several obligations at once. If certification is not yet justified for you, the underlying discipline still pays off: a documented risk picture is the foundation of a credible incident response plan.
How ISO 27001 differs from the things it gets confused with
ISO 27001 is regularly mixed up with Cyber Essentials, SOC 2 and GDPR, and the differences matter. Cyber Essentials is a UK government-backed baseline of five technical controls: practical, affordable and quick, but narrow. ISO 27001 is broader, risk-led and internationally recognised. Many organisations start with Cyber Essentials and grow into ISO 27001 as their customers demand more.
SOC 2 is an American attestation framework popular with US buyers; it overlaps heavily with ISO 27001 but is a report rather than a certificate. GDPR and the UK Data Protection Act are laws about personal data, not security standards: ISO 27001 helps you meet them but does not replace them. The ICO fined British Airways twenty million pounds in 2020 and Interserve four point four million pounds in 2022, a reminder that a certificate is a means of managing risk, not a shield against accountability.
One more distinction: ISO 27001 is a standard, not a person. People searching for it sometimes want a leader who can run security rather than a framework. That role is a CISO, available as a virtual CISO or through CISO as a service. If you want a fuller explanation of the leadership side, see what is a vCISO.
What certification actually costs you
The real cost of ISO 27001 is rarely the audit fee. It is the time spent designing controls, writing policies people will follow, and gathering evidence that the system works in practice. Buying a certificate without embedding the behaviour behind it produces a document that fails its first surveillance audit and impresses no serious buyer. The IBM Cost of a Data Breach Report 2025 puts the global average breach at 4.44 million US dollars, which frames the investment: an ISMS is cheaper than the event it helps you avoid.
The work splits into a gap assessment, a remediation phase, an internal audit, then a two-stage external certification audit followed by annual surveillance. The heaviest lift is usually the controls you do not yet have, which is why honest scoping at the start saves months later. Our pricing page explains how we structure that engagement.
How Starkhorn helps you get and keep certification
Starkhorn treats ISO 27001 as a leadership problem, not a paperwork exercise. As a fractional CIO and CISO, the work begins with a clear-eyed gap assessment, then a risk-led plan that prioritises the controls your business genuinely needs. We can run the programme end to end or work alongside your team, building the ISMS so it survives audits and reflects how you actually operate. This sits naturally alongside broader IT strategy consulting and modern concerns such as AI governance, where the same risk discipline now applies to shadow AI as it does to data.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Running technology and security across a private equity-backed group and a national motor retailer means Daniel has built and defended the kind of information security management system ISO 27001 asks for, under real audit and real commercial pressure, rather than describing one from the outside.
Frequently asked questions
Is ISO 27001 a legal requirement in the UK?
No. ISO 27001 is a voluntary standard, not a law. Businesses pursue it because customers, tenders or investors ask for it, or because they want a structured way to manage security. Laws such as UK GDPR apply regardless of whether you are certified.
What is the difference between ISO 27001 and Cyber Essentials?
Cyber Essentials is a UK baseline of five technical controls, quick and affordable to achieve. ISO 27001 is broader, risk-led and internationally recognised, covering how the whole organisation manages information security. Many firms start with Cyber Essentials and progress to ISO 27001 as buyers demand more.
How long does ISO 27001 certification take?
It depends on how mature your security is at the start. A business with documented controls may certify within a few months, while one starting from scratch needs longer to build and embed the management system before an auditor will pass it. Honest scoping early on is what prevents delays later.
Do I need a CISO to get ISO 27001?
You need someone who owns the information security management system, but not necessarily a full-time hire. A fractional or virtual CISO can design the ISMS, run the certification programme and stay on for surveillance audits, which is often more practical for mid-market firms than a permanent appointment.
Does ISO 27001 cover AI and cloud risks?
Yes, when you scope it that way. The standard is risk-led, so it adapts to whatever you are protecting, including cloud services and AI tools. Treating AI governance as part of your ISMS is increasingly expected by auditors and buyers alike.
START HERE
See where your security stands before you commit to certification
If buyers are asking about your security and you are weighing whether ISO 27001 is the right move, start with the basics. Our free Cyber Essentials Readiness check shows where your technical controls stand today, the natural first step before a full ISMS. When you are ready to plan the path to certification, book a conversation and we will scope it honestly.
Cyber Essentials Readiness check Book a conversation