For SMBs Adopting ISO 27001, the First Step Isn’t Buying Security Tools — It’s Identifying the Risks You Can’t Afford to Ignore

Many Companies Get the First Step of ISO 27001 Wrong
When a company decides to implement ISO/IEC 27001 Information Security Management System (ISMS), the first reaction is often to:
Assign someone to take charge of the project
Purchase a new firewall
Deploy EDR
Build a backup system
Look for ISO documentation templates
Ban employees from using ChatGPT
All of these measures are related to information security. However, if a company does not first understand its actual risks, it can easily spend a significant amount of money without addressing the problems that matter most.
In particular, generative AI tools such as ChatGPT, Microsoft Copilot, and Google Gemini have become part of everyday business operations over the past year. Information security risks are no longer limited to viruses and cyberattacks. Companies also need to consider the possibility that employees may unintentionally send sensitive information to places where it does not belong.
For SMBs starting their ISO 27001 journey, the first step is therefore not buying security tools or immediately writing policies.
It is answering one fundamental question:
If an important piece of information were leaked today, what could the company least afford to lose?
Why Do Many SMBs Start with a Full-Scale Implementation — Only to Give Up Halfway?
Many companies want to get everything done at once. They may start by:
Conducting a company-wide inventory of information assets, defining what counts as confidential information, and continuing to expand the scope after multiple rounds of meetings
Asking each department to create dozens of policies and procedures
Purchasing multiple security solutions at the same time
Requiring every department to implement the system simultaneously, even though only one IT or administrative employee is coordinating the entire project
The result is often predictable:
The documentation gets completed, but no one actually follows it because it does not fit the company's real-world processes.
The security tools are all in place, but the most critical risks have not actually been reduced.
The project keeps growing in scope and eventually starts interfering with day-to-day operations.
The reason is simple.
ISO 27001 manages risk — not security tools or documentation.
If a company has not first identified its most important information assets, even a well-designed set of security controls can end up being applied in the wrong places.
The Real Starting Point of ISO 27001: Identify the Risks You Cannot Afford to Ignore
ISO 27001 follows a risk-based approach.
It requires organizations to first understand:
Which information is most important?
What risks could affect it?
Which risks are unacceptable to the organization?
In other words, a company does not necessarily need to protect every piece of information in exactly the same way.
The priority should be information that, if exposed, lost, or altered, could have a significant impact on business operations, customer trust, or competitive advantage.
Four Steps SMBs Can Take to Get Started
If you are implementing ISO 27001 for the first time, I recommend starting with the following four steps rather than rushing to create a large number of policies and procedures.
Step 1: Identify the Four Most Important Information Assets
You do not need to inventory the entire company at once.
Start by identifying the core information and systems that have the greatest impact on your business, such as:
Customer information and important contracts
Product designs, R&D documents, or source code
ERP, CRM, or other core business systems
Important information accessible through cloud collaboration platforms such as Microsoft 365 or Google Workspace, as well as AI tools
The purpose of this step is not to create a complete inventory.
It is to establish a common understanding among management:
Which information absolutely cannot be compromised?
For some companies, the answer may be very straightforward: if something goes wrong, the production line stops or the business itself could be seriously disrupted.
That is the kind of risk that should receive attention first.
Step 2: Determine Who Has Access
Next, review:
Who has access?
Which devices can access the information?
Are any shared accounts being used?
Are accounts belonging to former employees still active?
Can AI tools access important information stored in SharePoint, OneDrive, or Google Drive?
Many companies discover risks they had not previously noticed at this stage.
For example:
Former employees can still log in to company systems.
A single administrator account is shared across the organization.
Everyone has permission to download customer data.
An AI assistant has access to the company's document repository without appropriate permission controls.
These may not look like major problems at first, but they can become significant security risks when combined with other weaknesses in the organization's processes.
Step 3: Define the Scenario You Most Need to Prevent
Ask yourself:
If a data breach occurred today, which scenario would have the most serious impact?
For example:
Customer design files are obtained by a competitor
Source code is leaked
Confidential information is inadvertently submitted to an AI tool
A customer list is taken by an employee
The ERP system is unavailable for three days
The answers to these questions help determine the priorities for subsequent risk assessments and security investments.
Step 4: Determine Which Risks Need to Be Addressed First
Once the first three steps are complete, start asking:
Which risks are acceptable?
Which risks must be addressed?
ISO/IEC 27001:2022 organizes its controls into 93 controls under Annex A. However, this does not mean that every organization must implement all 93 controls.
Instead, organizations should select the controls that are appropriate to their circumstances based on the results of their risk assessment.
Practical Example: Narrowing the Scope Can Actually Speed Up Implementation
A small-to-medium-sized manufacturing company was preparing to implement ISO 27001. Initially, the company planned to inventory more than 800 information assets across the entire organization.
After reviewing the project scope, the implementation team decided to focus first on four high-risk information assets:
Customer drawings
ERP system
Design documents
Microsoft 365 cloud collaboration platform
The company completed its first round of risk assessment in less than two weeks. This also gave the team a clearer direction for subsequent policy development, employee training, and security investments.
This "focus first, expand gradually" approach can make ISO 27001 implementation much more manageable for SMBs.
Why Does This Approach Align with the Spirit of ISO 27001?
The four steps above correspond closely to the core requirements of ISO 27001:
Establish an information asset inventory
Identify information security risks
Conduct a risk assessment
Determine appropriate controls based on risk
The important point is that an SMB does not need to achieve 100% coverage on day one.
Instead, it can focus first on the most important 20%, establish the right direction, and gradually improve the overall ISMS.
More importantly, there is no single standard answer or one-size-fits-all approach to these four questions.
As long as a company can identify its own risks and develop reasonable management measures to address them, that solution can be appropriate for its own organization.
FAQ
Can an SMB Implement ISO 27001 Without Dedicated Information Security Staff?
Yes.
Many SMBs form an implementation team consisting of MIS personnel, IT staff, and representatives from different departments, and seek assistance from external consultants when necessary.
Having representatives from each department involved has an important advantage: it helps the organization build cross-functional consensus more quickly, identify gaps in how different departments understand their processes, and develop a management approach that actually fits the way the company operates.
In the past, some companies simply assigned one person to coordinate with all departments. Each department then treated ISO 27001 as something it only needed to "support" rather than actively participate in.
This can easily lead to departments working independently, while the person in charge has no real authority to make changes.
Eventually, that person becomes little more than a document writer.
The time and resources spent on the project are then largely wasted.
Do We Need to Purchase a Large Number of Security Tools at the Beginning?
No.
The focus of ISO 27001 is risk management, not security tool procurement.
It is better to complete the risk assessment first and then determine whether controls such as firewalls, file encryption, USB control, or other technical measures are necessary.
This approach allows the company to spend its budget where it matters most. It also prevents employees from becoming overwhelmed by the simultaneous introduction of multiple new systems, which can require extensive training and even force them to change the way they work.
How Long Does the First Step Usually Take?
If the scope of the organization is clearly defined, many SMBs can complete the initial information asset identification, risk identification, and scope planning within one to two weeks.
If the organization later determines that a broader scope should be included, it can simply expand the scope at that point.
A narrower initial scope does not mean the company will be "penalized" or that its certification will be revoked simply because certain areas were not included from the beginning.
Should AI Tools Be Included in ISO 27001 Management?
Yes.
ISO 27001 does not prohibit the use of generative AI. However, organizations should include the new risks introduced by AI in their risk assessment.
These may include:
Rules governing what information employees may enter into AI tools
Access controls
Third-party service management
Employee security awareness and training
Conclusion: A Good Start Is More Important Than Trying to Do Everything at Once
Many companies assume that implementing ISO 27001 means creating a large collection of policies and procedures or investing heavily in security tools.
In reality, successful implementation often begins with two fundamental questions:
Which information is most important? Which risks are unacceptable?
Once a company establishes a clear direction for risk management, it can gradually improve its policies, employee training, and technical controls—such as file encryption, USB control, AI tool upload control, and activity auditing.
This allows ISO 27001 to become a practical tool for strengthening information security and business governance, rather than becoming another administrative burden.




Comments