Having an ISO 27001 Certificate Doesn’t Mean Your ISMS Is Working

Having an ISO 27001 Certificate Doesn’t Mean Your ISMS Is Working

The M&S story has been running for over a year now. The attack happened at Easter 2025, and this week the full-year figures landed: profits down 24%, with the cyber attack costing the business somewhere in the region of £300 million in lost operating profit. That’s before you factor in the stock market hit, the reputational damage, or the customers who quietly migrated to competitors while the website was dark

It’s also emerged that M&S apparently held no cybersecurity certification at the time. No ISO 27001. No Cyber Essentials. And they weren’t alone — Co-op and Harrods, also caught up in the same wave of attacks, appear to have been in the same position. For organisations handling the volumes of personal data that major retailers do — staff records, loyalty schemes, payment information — that’s perhaps a conversation for another day. Or possibly a reason to pause and reflect on what the sector’s appetite for formal certification actually looks like.

But here’s the question I keep coming back to — not about M&S, but about the organisations that are certified. Because in my experience, a certificate on the wall and a genuinely functioning ISMS are not always the same thing. And the gap between them is where the real risk lives.

It cuts both ways. There’s the organisation that achieves certification and breathes a sigh of relief — job done, we’re safe now. And there’s the uncomfortable moment when an ISO 27001 certified organisation does suffer a breach or an outage, and the reaction is disbelief: how did that happen? They’re certified.

Certification matters. It demonstrates commitment, it provides a framework, and it absolutely raises the bar. But it doesn’t make your people do the right thing on a Tuesday afternoon when something just needs to get done. And that’s where most of the problems I’ve seen actually start.

The supplier problem

ISO 27001 has always required organisations to think about their supply chain. The 2022 version of the standard sharpened that focus considerably — Annex A now includes specific controls around information security in supplier relationships and managing information security in the ICT supply chain. The intent is clear: you are responsible for the risks that come through your suppliers’ doors, not just your own.

In theory, most organisations with a mature ISMS know this. In practice, I’ve seen it go wrong in almost every way imaginable.

One of my favourites — and I use that word loosely — involved a client who had an impressively thorough supplier questionnaire. Pages of it. Detailed questions covering data handling, access controls, incident response, business continuity. Exactly the kind of rigour you’d hope to see. The problem? Nobody had ever defined what to do if a supplier ticked no to anything. The questionnaire went out, the responses came back, and they sat in a folder. There was no threshold, no escalation process, no follow-up. Ticking the boxes had become the point, rather than what the answers actually meant.

I’ve seen the same questionnaire copied wholesale from another organisation’s ISMS — adapted for use without any real understanding of what it was asking or why. Which is arguably worse, because at least if you wrote it yourself you’d probably have a view on what a bad answer looked like.

The software problem

Supplier risk isn’t just about the companies you formally contract with. It’s also about the tools your staff download and start using without telling anyone.

I’ve seen this across multiple clients — particularly smaller organisations where people are practical and just want to get things done. Someone finds a useful tool, signs up with a work email address, possibly connects it to shared files or systems, and suddenly you have a supplier relationship that nobody in the ISMS has reviewed, approved, or even knows about. The data it touches might be personal data. The company behind it might be based somewhere that complicates your data transfer obligations. It might not have been around long enough to have any meaningful security track record.

The standard asks for controls around this. The challenge is making those controls realistic for an organisation where the ISO Manager isn’t copied on every app download. Where should that responsibility sit? Who actually has the visibility to catch it? These aren’t rhetorical questions — they need real answers built into your procedures, not just a policy that says staff should ask first.

The visibility problem

This one is the most human of all the failures I’ve seen, and I think it’s the most common.

One client had put real effort into their supplier management process. The person responsible was diligent, thorough, and genuinely committed to getting it right. The problem was that people simply didn’t tell her when new suppliers were being brought on board. Not maliciously — they just didn’t think to. They arranged something, it started, and the ISMS team found out later. Or didn’t find out at all.

The solution they eventually landed on was pragmatic: move the trigger point to Finance, because Finance pays the invoices. If a new supplier appears on a purchase order, that’s when the vetting process kicks in. It’s not a perfect system — there are still edge cases — but it removed the dependency on people remembering to flag something that didn’t feel, to them, like an information security decision.

When I carried out their most recent audit, we still found six suppliers who hadn’t been captured in the process. One of them handles the personal data of their customers.

Six. Including one handling customer personal data.

They have a good ISMS. They take it seriously. And they still had six.

What this actually means for your organisation

ISO 27001 certification tells you that at the point of audit, your documented ISMS met the requirements of the standard. It doesn’t tell you whether your people understand why those requirements exist. It doesn’t tell you whether the controls work when nobody’s watching. And it definitely doesn’t tell you whether the humans in your organisation are making good security decisions on a Tuesday afternoon when something just needs to get done.

That’s not a criticism of the standard — it’s one of the better frameworks out there, and I’ve spent a long time working with it. But the certificate is a starting point, not a destination.

The organisations I’ve seen do this well are the ones where information security isn’t just a compliance exercise that happens before the audit. It’s where people across the business — not just the ISO Manager — have a working understanding of what they’re supposed to do and why it matters. Where the supplier vetting process is part of how things actually get bought, not a separate step that relies on someone remembering. Where staff know what to do when they want to use a new tool, because it’s been explained to them in a way that makes sense.

That last bit is something I think about a lot, and it’s part of the reason we built our ISO 27001 staff awareness course at RiskReady. Because the gap between having an ISMS and having an organisation that actually operates securely is almost always a people gap. And you can’t close a people gap with a policy document.

If you’re ISO 27001 certified and you’re wondering whether your ISMS is genuinely working — or if you’re trying to build the kind of staff awareness that makes the controls stick — it might be worth a look.

Share The Post

Helen Molyneux Director RiskReady

Helen Molyneux is the founder of Cambridge Risk Solutions, a specialist resilience consultancy with nearly two decades of experience in business continuity, crisis management and information security. She holds Lead Auditor certifications for ISO 22301 and ISO 27001, and has worked across both public and private sectors helping organisations prepare for, respond to, and recover from disruption. RiskReady is her e-learning platform, built to make that same practical expertise accessible to individuals and teams at every level.

Find out more about Cambridge Risk Solutions →

Leave a Comment

Your email address will not be published. Required fields are marked *