ISO 27001: Your Biggest Cybersecurity Risk Might Not Be Your Technology

Your business may have strong security tools and still leave important gaps in the way people work. Learn how ISO 27001 helps you look beyond technology, improve everyday processes and give your team the support they need to protect information.

ISO 27001: Your Biggest Cybersecurity Risk Might Not Be Your Technology

Your business has invested in security software. Your computers receive updates. You have an IT provider and a backup service.

Then an urgent email arrives.

It appears to come from a director. A payment needs making before the end of the day. The person handling it is busy, the request looks familiar, and asking questions feels like causing a delay.

The payment goes through.

The bank details belong to a criminal.

There may be nothing wrong with the computer used to make that payment. The gap could sit in the approval process, the pressure to act quickly or the lack of a clear way to check the request.

Technology matters. So do the decisions and habits around it.

When reviewing ISO 27001 cybersecurity risks, businesses need to look at how information is handled across daily work.

ISO/IEC 27001 takes a broad approach to information security, covering people, policies and technology through a risk management system. Information security management systems

The question is therefore wider than “Are our systems protected?”

You also need to ask: does the way we work help people protect information, or make it harder?

The risk may sit in the process

A business can have good tools and still use a weak process.

A customer file is sent to the wrong person because nobody checks the recipient. A former employee keeps access because their departure was not passed to IT. A supplier’s bank details are changed without independent confirmation.

Each event involves technology, but the weakness may begin elsewhere.

Perhaps responsibility was unclear. Perhaps staff followed the usual method, and that method left a gap.

This is why blaming the last person involved can miss the wider problem.

Ask what made the event possible.

What information did the person have? What checks were expected? Could they follow those checks during a normal working day?

A useful security review follows the task from start to finish.

It looks at the tools, the instructions and the decisions together, then identifies where protection needs to improve.

Information security is wider than stopping hackers

Cybersecurity often brings to mind stolen passwords, harmful software and attacks on computer systems.

Information security also includes less dramatic events.

A lost paper file can expose private details. An incorrect change to a spreadsheet can affect a business decision. Information that cannot be accessed when needed can stop work.

ISO 27001 addresses protecting information from unauthorised disclosure, improper changes and loss of availability. In plain terms, the right people should be able to access trustworthy information when they need it. iso.org

That makes information security relevant across the business.

Finance handles payment details. HR holds staff information. Sales manages customer records. Managers approve access and decide how work is organised.

IT provides vital support, but it cannot make every decision for those teams.

Start by understanding which information your business depends on and how people use it. That gives you a clearer view of what needs protecting.

Avoid treating staff as the problem

It is easy to say that people are the weakest link.

That phrase offers little help to someone trying to work safely.

Employees may face unclear instructions, difficult systems and heavy workloads. They may be expected to respond quickly to requests that deserve careful checking.

Attackers can take advantage of those conditions.

A stronger approach asks how the business can support people and limit the effect of mistakes.

The NCSC warns against relying too heavily on staff spotting every phishing message. Its guidance recommends several layers of protection, with education forming one part of the approach. National Cyber Security Centre

People still need clear expectations.

However, a sensible system should allow for a suspicious message reaching an inbox or someone making an error.

Good protection combines suitable technical measures, workable processes and a team that knows how to seek help.

That gives the business more chances to detect a problem before it causes harm.

Rushed decisions deserve closer attention

Think about the tasks your team completes under pressure.

An urgent payment. A customer asking for immediate access. A manager requesting a file just before a meeting.

These situations can make checks feel inconvenient.

If staff are praised for speed but criticised for pausing, they learn which behaviour the business values.

Review whether your expectations support safe decisions.

For sensitive tasks, define which checks remain necessary even when a request is urgent.

Give people a clear route to resolve uncertainty. They should know who can approve an exception and when they should stop and ask.

Managers need to follow the same arrangements.

If senior staff routinely bypass checks, written instructions lose their value.

A useful question for your next review is:

“Where does pressure to finish quickly make it harder to follow our security process?”

The answer may reveal a practical weakness that another software purchase would not solve.

Make payment checks reliable

A request to change bank details deserves attention.

It may arrive through a genuine-looking email, including one sent from an account that has been taken over.

A familiar name or writing style is not enough to establish that the request is genuine.

Your payment process should include a suitable independent check before sensitive changes are made.

For example, staff can contact the supplier using details already held in a trusted record, rather than a number supplied in the change request.

Define who performs the check and how it is recorded.

Also make clear that urgency does not remove the need for verification.

Consider a fictional case where an employee receives a bank-detail change late on Friday. Their manager is unavailable, and payment is due.

If the process gives no guidance for that situation, the employee may feel forced to choose.

Design the process so they have a safe, clear next step.

Access should follow the job

People need access to do their work.

Problems arise when that access becomes wider than their role requires or remains after the need has ended.

An employee moves departments but keeps access to old files. A contractor finishes a project but retains an account. Temporary access becomes permanent because nobody remembers to review it.

These gaps can build quietly.

Agree who approves access, who puts it in place and who reviews it.

Include changes of role and departures, not just new starters.

Managers need to explain what their staff require. IT or the relevant service owner needs reliable notice when those needs change.

Review important accounts and shared folders against current responsibilities.

The aim is to provide appropriate access while reducing unnecessary exposure.

The UK Government’s access-control guidance highlights the importance of defining and managing who can use systems and what permissions they hold. Security

Strong sign-in protection still needs good management

Passwords alone can leave accounts vulnerable.

Additional sign-in protection can make unauthorised access harder. Multi-factor authentication, often called MFA, asks for more than one form of evidence when someone signs in.

However, different methods provide different levels of protection.

The NCSC’s guidance recommends stronger approaches and explains pitfalls that organisations should consider when choosing and managing them. National Cyber Security Centre

Work with suitable technical support to protect important accounts, including email and administration services.

Then explain the process to users.

What should they do if they receive an unexpected approval request? How do they report a lost device used for signing in? What is the approved recovery route?

These questions matter because sign-in protection forms part of a wider process.

If recovery is handled carelessly, or people approve requests they did not start, useful protection can be weakened.

The tool and the way it is managed need to work together.

Check how files are shared

A file can leave the business in seconds.

That makes sharing worth reviewing, especially where information is sensitive.

Staff may use email attachments, shared links, messaging tools or personal accounts. Different methods can give very different levels of control.

Make the approved options clear.

Explain how people should check recipients, set access and review whether the information needs to be shared at all.

A link intended for one person should not accidentally allow wider access.

Also consider what happens when a customer or supplier cannot use your normal method. Staff need an approved alternative rather than having to invent one.

Watch for repeated workarounds.

If people regularly send files through personal accounts, ask why. The business tool may be difficult to use, or its limits may not have been explained.

Solve the practical difficulty while maintaining appropriate protection.

A rule that people cannot follow reliably deserves attention.

Training should relate to real tasks

General awareness training can introduce important ideas.

It becomes more useful when people can connect those ideas to their work.

Finance staff need to understand payment scams. HR teams need guidance on handling staff records. Managers need to know their part in access decisions and incident reporting.

Use realistic examples.

Ask how an employee would respond to an unusual request, a misdirected file or a lost work device.

Check whether they can find the relevant guidance.

A completed training record does not prove someone knows what to do during a busy afternoon.

Short discussions and practical exercises can reveal confusion before an actual event does.

Keep the wording clear and give people space to ask questions.

If a rule changes, explain the change and its purpose.

Training should help people make sound decisions, while the business continues to provide the tools and processes needed to support them.

Make reporting quick and safe

Someone notices they sent a file to the wrong address.

Their first thought should be to report it promptly.

If they expect anger or embarrassment, they may delay. That can leave the response team with less time to act.

Make the reporting route clear, simple and easy to find.

Staff should know who to contact, what details to provide and how to raise an urgent concern outside normal hours where needed.

Managers also need to respond constructively.

The NCSC advises against a blame-focused approach to phishing and encourages organisations to make reporting straightforward. National Cyber Security Centre

Once a concern is reported, focus first on understanding and managing it.

Questions about conduct or repeated failures can be addressed through appropriate processes later.

Prompt reporting gives the business information it can use. Silence leaves a gap.

A person who says “I think something went wrong” may be helping prevent a much larger problem.

Suppliers belong in the review

Your information may pass through organisations outside your own team.

An IT provider, payroll service, cloud platform or specialist contractor could hold it or have access to your systems.

That creates responsibilities your business needs to understand.

Before using a service, consider what information it will handle, what access it requires and how problems will be reported.

Agree relevant expectations rather than assuming the supplier manages everything.

Ask who approves access and how it ends. Understand the arrangements for returning or deleting information when the service finishes.

Review important services when circumstances change.

A supplier may introduce a new platform or use another provider. Your own business may begin sharing more sensitive information.

The level of review should suit the risk.

A supplier relationship should give your team a clear understanding of the protection provided and the tasks that remain your responsibility.

Security needs leadership decisions

Some weaknesses need action from senior leaders.

Staff cannot solve every problem through care alone.

They may need better systems, clearer priorities or resources to carry out essential checks. A known issue may remain open because nobody has authority to make the decision.

Leaders should review information security alongside other business risks.

Ask which information and services matter most, what could disrupt them and where current protection falls short.

Name the person responsible for each important action.

Agree when it should be completed and what evidence will show progress.

The UK Government’s Cyber Governance Code of Practice places attention on leadership oversight, risk management, people and incident planning. GOV.UK

A meeting that notes the same weakness repeatedly without a decision offers little protection.

Leadership needs to turn concerns into action and make expectations clear across the business.

Prepare for the day something goes wrong

Good prevention matters, but the business also needs a response plan.

If an account is taken over or important files become unavailable, people should know what happens next.

Define how concerns are assessed, who leads the response and which contacts may be needed.

Include practical communication arrangements.

If the usual email service is unavailable or untrusted, how will the team coordinate safely?

Consider the information required to make decisions about customer, supplier and regulatory notifications. Reporting duties depend on the event and the rules that apply.

Test the plan with a realistic discussion.

For example, work through a suspected account takeover. Ask who staff contact, who can restrict access and how essential work continues.

Any technical action should be handled through the agreed response process and appropriate expertise.

An exercise gives you a chance to find unclear roles before pressure makes them harder to resolve.

Backups need a recovery check

A backup service can provide reassurance.

The more useful question is whether the business can recover the information and services it needs.

Find out which information is covered, how backups are protected and who manages recovery.

Arrange suitable tests with the people responsible.

A successful backup message does not answer every recovery question. The business may still need to establish how long restoration takes and whether essential information is complete.

Think about priorities.

Which services must return first? What work can continue while systems are unavailable? Where are the instructions and contact details needed for recovery?

The NCSC’s small organisations guidance includes backups among practical measures for improving protection. National Cyber Security Centre

Keep recovery arrangements aligned with the way the business now works.

A plan created before a major system change may no longer provide a dependable route back to normal operations.

Use ISO 27001 to connect the pieces

ISO 27001 provides a structured way to manage information security risks.

It helps the business establish what sits within its system, assess risks, decide how to address them and review whether those arrangements remain effective.

The choices should reflect the organisation and its needs. Information security management systems

In practical terms, this connects work that might otherwise sit in separate places.

Access reviews, staff guidance, supplier decisions and incident planning become parts of a managed approach.

A risk list has limited value if nobody acts on it. A policy needs to match real work. A completed action needs checking to see whether it helped.

Internal reviews can test those links using actual examples.

Follow a recent starter, a supplier change or a sensitive file transfer.

Look for evidence that the agreed arrangements were used and that they provided the intended protection.

The benefits of an ISO consultant’s support

One of the benefits of an ISO consultant’s support is an outside view of how security is managed across the business.

A consultant can help identify gaps between written rules and daily practice, explain ISO 27001 clearly and support a practical risk review.

They can also help improve internal audits, define responsibilities and organise actions so managers can track progress.

For example, they may find that departure records reach HR promptly but arrive late with the people managing accounts.

Useful support builds the team’s understanding.

Technical weaknesses still need suitable technical expertise. Specialist legal or regulatory questions need the right advice.

The business remains responsible for its decisions and actions.

Certification and consultancy cannot guarantee that an attack will never happen. Their value lies in supporting a clearer, more consistent approach to managing risk and learning from results.

Follow one sensitive task this week

Choose one task involving important information or money.

It might be approving a payment, sharing a customer file or removing access when someone leaves.

Follow a recent example from start to finish.

Ask the people involved to show you the process, the checks and the route they would use if something looked wrong.

Look for places where the work relies on memory, urgency or an assumption that someone else has checked.

Then select one practical improvement.

Give it an owner, explain it to the team and review whether it works.

At your next management meeting, ask:

Where are we relying on someone being careful because our process leaves them without enough support?

Use that answer to guide your next risk review.

Your technology may be strong. The way your business uses it deserves the same careful attention.

Get Started

There has never been a better time to invest in ISO certification. Show your commitment to quality management, the environment or occupational health & safety performance with a UKAS certified ISO certification from Compliant.
Get in Touch

Free Download

Download our free “The ISO process and ongoing Support pdf”