top of page

For SMBs Adopting ISO 27001, the First Step Isn’t Buying Security Tools — It’s Identifying the Risks You Can’t Afford to Ignore

1 day ago
7 min read


Many Companies Get the First Step of ISO 27001 Wrong

When a company decides to implement ISO/IEC 27001 Information Security Management System (ISMS), the first reaction is often to:

  • Assign someone to take charge of the project

  • Purchase a new firewall

  • Deploy EDR

  • Build a backup system

  • Look for ISO documentation templates

  • Ban employees from using ChatGPT

All of these measures are related to information security. However, if a company does not first understand its actual risks, it can easily spend a significant amount of money without addressing the problems that matter most.

In particular, generative AI tools such as ChatGPT, Microsoft Copilot, and Google Gemini have become part of everyday business operations over the past year. Information security risks are no longer limited to viruses and cyberattacks. Companies also need to consider the possibility that employees may unintentionally send sensitive information to places where it does not belong.

For SMBs starting their ISO 27001 journey, the first step is therefore not buying security tools or immediately writing policies.

It is answering one fundamental question:

If an important piece of information were leaked today, what could the company least afford to lose?

Why Do Many SMBs Start with a Full-Scale Implementation — Only to Give Up Halfway?

Many companies want to get everything done at once. They may start by:

  • Conducting a company-wide inventory of information assets, defining what counts as confidential information, and continuing to expand the scope after multiple rounds of meetings

  • Asking each department to create dozens of policies and procedures

  • Purchasing multiple security solutions at the same time

  • Requiring every department to implement the system simultaneously, even though only one IT or administrative employee is coordinating the entire project

The result is often predictable:

  • The documentation gets completed, but no one actually follows it because it does not fit the company's real-world processes.

  • The security tools are all in place, but the most critical risks have not actually been reduced.

  • The project keeps growing in scope and eventually starts interfering with day-to-day operations.

The reason is simple.

ISO 27001 manages risk — not security tools or documentation.

If a company has not first identified its most important information assets, even a well-designed set of security controls can end up being applied in the wrong places.



The Real Starting Point of ISO 27001: Identify the Risks You Cannot Afford to Ignore

ISO 27001 follows a risk-based approach.

It requires organizations to first understand:

  • Which information is most important?

  • What risks could affect it?

  • Which risks are unacceptable to the organization?

In other words, a company does not necessarily need to protect every piece of information in exactly the same way.

The priority should be information that, if exposed, lost, or altered, could have a significant impact on business operations, customer trust, or competitive advantage.


Four Steps SMBs Can Take to Get Started

If you are implementing ISO 27001 for the first time, I recommend starting with the following four steps rather than rushing to create a large number of policies and procedures.


Step 1: Identify the Four Most Important Information Assets

You do not need to inventory the entire company at once.

Start by identifying the core information and systems that have the greatest impact on your business, such as:

  • Customer information and important contracts

  • Product designs, R&D documents, or source code

  • ERP, CRM, or other core business systems

  • Important information accessible through cloud collaboration platforms such as Microsoft 365 or Google Workspace, as well as AI tools

The purpose of this step is not to create a complete inventory.

It is to establish a common understanding among management:

Which information absolutely cannot be compromised?

For some companies, the answer may be very straightforward: if something goes wrong, the production line stops or the business itself could be seriously disrupted.

That is the kind of risk that should receive attention first.


Step 2: Determine Who Has Access

Next, review:

  • Who has access?

  • Which devices can access the information?

  • Are any shared accounts being used?

  • Are accounts belonging to former employees still active?

  • Can AI tools access important information stored in SharePoint, OneDrive, or Google Drive?

Many companies discover risks they had not previously noticed at this stage.

For example:

  • Former employees can still log in to company systems.

  • A single administrator account is shared across the organization.

  • Everyone has permission to download customer data.

  • An AI assistant has access to the company's document repository without appropriate permission controls.

These may not look like major problems at first, but they can become significant security risks when combined with other weaknesses in the organization's processes.


Step 3: Define the Scenario You Most Need to Prevent

Ask yourself:

If a data breach occurred today, which scenario would have the most serious impact?

For example:

  • Customer design files are obtained by a competitor

  • Source code is leaked

  • Confidential information is inadvertently submitted to an AI tool

  • A customer list is taken by an employee

  • The ERP system is unavailable for three days

The answers to these questions help determine the priorities for subsequent risk assessments and security investments.


Step 4: Determine Which Risks Need to Be Addressed First

Once the first three steps are complete, start asking:

  • Which risks are acceptable?

  • Which risks must be addressed?

ISO/IEC 27001:2022 organizes its controls into 93 controls under Annex A. However, this does not mean that every organization must implement all 93 controls.

Instead, organizations should select the controls that are appropriate to their circumstances based on the results of their risk assessment.


Practical Example: Narrowing the Scope Can Actually Speed Up Implementation

A small-to-medium-sized manufacturing company was preparing to implement ISO 27001. Initially, the company planned to inventory more than 800 information assets across the entire organization.

After reviewing the project scope, the implementation team decided to focus first on four high-risk information assets:

  • Customer drawings

  • ERP system

  • Design documents

  • Microsoft 365 cloud collaboration platform

The company completed its first round of risk assessment in less than two weeks. This also gave the team a clearer direction for subsequent policy development, employee training, and security investments.

This "focus first, expand gradually" approach can make ISO 27001 implementation much more manageable for SMBs.


Why Does This Approach Align with the Spirit of ISO 27001?

The four steps above correspond closely to the core requirements of ISO 27001:

  • Establish an information asset inventory

  • Identify information security risks

  • Conduct a risk assessment

  • Determine appropriate controls based on risk

The important point is that an SMB does not need to achieve 100% coverage on day one.

Instead, it can focus first on the most important 20%, establish the right direction, and gradually improve the overall ISMS.

More importantly, there is no single standard answer or one-size-fits-all approach to these four questions.

As long as a company can identify its own risks and develop reasonable management measures to address them, that solution can be appropriate for its own organization.


FAQ

Can an SMB Implement ISO 27001 Without Dedicated Information Security Staff?

Yes.

Many SMBs form an implementation team consisting of MIS personnel, IT staff, and representatives from different departments, and seek assistance from external consultants when necessary.

Having representatives from each department involved has an important advantage: it helps the organization build cross-functional consensus more quickly, identify gaps in how different departments understand their processes, and develop a management approach that actually fits the way the company operates.

In the past, some companies simply assigned one person to coordinate with all departments. Each department then treated ISO 27001 as something it only needed to "support" rather than actively participate in.

This can easily lead to departments working independently, while the person in charge has no real authority to make changes.

Eventually, that person becomes little more than a document writer.

The time and resources spent on the project are then largely wasted.


Do We Need to Purchase a Large Number of Security Tools at the Beginning?

No.

The focus of ISO 27001 is risk management, not security tool procurement.

It is better to complete the risk assessment first and then determine whether controls such as firewalls, file encryption, USB control, or other technical measures are necessary.

This approach allows the company to spend its budget where it matters most. It also prevents employees from becoming overwhelmed by the simultaneous introduction of multiple new systems, which can require extensive training and even force them to change the way they work.


How Long Does the First Step Usually Take?

If the scope of the organization is clearly defined, many SMBs can complete the initial information asset identification, risk identification, and scope planning within one to two weeks.

If the organization later determines that a broader scope should be included, it can simply expand the scope at that point.

A narrower initial scope does not mean the company will be "penalized" or that its certification will be revoked simply because certain areas were not included from the beginning.


Should AI Tools Be Included in ISO 27001 Management?

Yes.

ISO 27001 does not prohibit the use of generative AI. However, organizations should include the new risks introduced by AI in their risk assessment.

These may include:

  • Rules governing what information employees may enter into AI tools

  • Access controls

  • Third-party service management

  • Employee security awareness and training


Conclusion: A Good Start Is More Important Than Trying to Do Everything at Once

Many companies assume that implementing ISO 27001 means creating a large collection of policies and procedures or investing heavily in security tools.

In reality, successful implementation often begins with two fundamental questions:

Which information is most important? Which risks are unacceptable?

Once a company establishes a clear direction for risk management, it can gradually improve its policies, employee training, and technical controls—such as file encryption, USB control, AI tool upload control, and activity auditing.

This allows ISO 27001 to become a practical tool for strengthening information security and business governance, rather than becoming another administrative burden.

 
 
 

Comments


Headquarter (Taiwan)

Address: 11F, No. 96, Section 3, Zhongxiao East Road, Da'an District, Taipei City 106, Taiwan

Telephone: 02-2731-5860

Fax: 02-2731-7905

Central Taiwan

Address: 11F-1, No. 161, Gongyi Rd., West District, Taichung City 403

Telephone: 04-2305-3366

Southern Taiwan

Address: Room B1402-3, 4th Floor, No. 195, Kunda Rd., Yongkang Dist., Tainan City 710

Telephone: 06-2723-291

Hsinchu 

Address: Room 5, 9th Floor, No. 168, Section 2, Fuxing 3rd Road, Zhubei City, Hsinchu County 302, Taiwan

Hsinchu 

Address: Room 5, 9th Floor, No. 168, Section 2, Fuxing 3rd Road, Zhubei City, Hsinchu County 302, Taiwan

Introduction

Solutions

News

Blog

Follow Us On:

  • Youtube
  • Facebook

© 2035 by Vista.io. Powered and secured by Wix

bottom of page