Introduction
Picture this: You’re a CEO, lying awake at 3 AM, wondering if your company’s data is safe from cyber villains lurking in the digital shadows.
Enter ISO 27001, the cybersecurity blanket that might just help you catch some Z’s.
Before we continue, compliance, like cybersecurity, is full of confusing terms, phrases and acronyms. Our A-Z cybersecurity glossary is here to help you get your head around all of these.
What is ISO 27001?
ISO 27001 is an international standard that provides a framework for establishing, implementing, maintaining, and continuously improving an information security management system (ISMS).
In plain English?
It’s a structured way to protect your company’s information assets, whether that’s customer data, trade secrets, or your CEO’s embarrassing email drafts.
Think of ISO 27001 as the cybersecurity world’s equivalent of a driving license. Just as you wouldn’t hire a taxi driver without a license, many organisations won’t work with companies that can’t prove they take information security seriously.
Why Should You Care? (Spoiler Alert: Everyone Else Does)
Here’s the thing about ISO 27001… It’s become the gold standard for information security compliance. Much like how SOC 2 compliance is expected in the US market, ISO 27001 has become the go-to requirement for organisations serious about cybersecurity.
The beauty (and annoyance) of ISO 27001 is that it’s deliberately vague. Don’t worry, that’s actually a feature, not a bug!
The standard is designed to accommodate organisations of any size and industry, from massive multinational banks to your local bakery that’s gone digital. One size fits all, but you get to tailor it to your specific needs.
And while this is very inclusive, it leaves you wondering: what do I actually need to do?
The Real-World Impact: Where Penetration Testing Comes In
Now, here’s where things get interesting (and where we cybersecurity folks get excited). ISO 27001 isn’t just about writing policies and hoping for the best; it requires you to actively identify and manage vulnerabilities.
This is where penetration testing becomes your secret weapon. While ISO 27001 doesn’t explicitly require penetration testing (that pesky vagueness coming back to haunt us), it does require you to show evidence of vulnerability management. This is where most companies turn to penetration testing.
The standard specifically mentions vulnerability management in several key controls:
- Annexe A 12.6.1 – Management of technical vulnerabilities
- Control 8.8 – Management of technical vulnerabilities
- Clause 6.1.2 – Risk assessment processes
Penetration testing serves as a crucial method for meeting these requirements. Think of pen testers as your friendly neighbourhood cybersecurity detectives. They poke, prod, and try to break into your systems (legally, of course!) to find weaknesses before the bad guys do.
ISO 27001 Penetration Testing: What You Actually Need
If you have landed here wondering how ISO 27001 penetration testing actually works, the honest starting point is that the standard never uses the words “you must run a penetration test” as we mentioned above. What it does do is ask you to manage technical vulnerabilities and to prove you are doing it, and a penetration test is the most credible evidence most organisations can put in front of an auditor.
In the current version of the standard, ISO/IEC 27001:2022, the control that matters most here is Annex A 8.8, Management of Technical Vulnerabilities. It replaced the old 2013 references (A.12.6.1 and A.18.2.3) and takes a broader, more proactive view of finding weaknesses before they are exploited. Annex A 8.29, Security Testing in Development and Acceptance, is the other one worth knowing, because it expects security testing to be built into how you release software rather than bolted on at the end. A penetration test feeds both of these, and the findings flow back into your risk assessment under Clause 6.1.2 and into your Statement of Applicability, which is the document your auditor will keep coming back to.
How often should you test?
This is the question we get asked most, and the frustrating answer is that ISO 27001 does not set a fixed frequency. It ties everything back to your risk assessment, meaning that a business handling sensitive data at scale is expected to test more often than a small, low-risk operation.
In practice, most certified organisations settle on testing at least once a year and again after any significant change, which is to say a new application, a major infrastructure move, or anything that meaningfully alters your risk. It also helps to line your testing up with the certification cycle. Certification runs on a three-year rhythm, with the initial Stage 2 audit, annual surveillance audits in between, and a full recertification at the end, so having fresh test evidence ready for each of those checkpoints keeps auditors happy and saves a scramble.
Internal, external, and getting the scope right
A thorough ISO 27001 pen test usually looks at your systems from two angles. External testing takes the view of an attacker on the internet with no access, probing your perimeter and anything internet-facing. Internal testing assumes someone is already inside, whether through a compromised laptop or a rogue insider, and asks how far they could move and what they could reach. The two answer different questions, and for most organisations both are worth doing.
Crucially, the scope should match the scope of your ISMS. There is little value in testing systems that sit outside your certification boundary, and equally there is real risk in leaving in-scope systems untested. Mapping this against your Statement of Applicability before testing begins is the difference between evidence an auditor accepts and a report that raises more questions than it answers.
What auditors actually want to see
A clean report with no findings is not the goal, and an auditor will not reward you for one. What a certification body wants is proof that your vulnerability management process works: findings identified and risk-rated, a clear owner for each, remediation carried out, and a retest confirming the fix held. The test is evidence of a living process, not a certificate in its own right.
This is also why the choice of tester matters. Auditors expect competent, independent testing, and in the UK, CREST accreditation is a widely recognised mark that the work has been done to a professional standard. Our penetration testing services are CREST-accredited and scoped with your ISMS and Statement of Applicability in mind, covering both the network and web application sides that ISO 27001 controls touch. If you also handle card payments, it is worth reading how the same testing supports PCI DSS penetration testing, which is far more prescriptive about frequency and scope than ISO 27001 is.
The Not-So-Fun Part: The Price Tag
Let’s talk about the elephant in the room: the cost.
Implementing ISO 27001 isn’t exactly pocket change. Costs can vary wildly depending on the size of the business, anywhere from £5k to £30k+, and this is without including consultancy and penetration testing costs (as well as every other associated cost).
It’s like having a really expensive gym membership, except instead of getting abs, you get peace of mind and regulatory compliance.
For many organisations, this investment pays dividends in client trust, reduced insurance premiums, and the ability to compete for contracts that require ISO certification; however, we admit that it is a massive barrier to entry.
So, while ISO 27001 is for everyone in theory, the reality is that it’s not.
What Can You Do Instead?
If you’re a smaller business or just starting your cybersecurity journey, there are some excellent stepping stones that won’t require selling a kidney to fund.
Cyber Essentials & Cyber Essentials Plus
Cyber Essentials is like ISO 27001’s more approachable younger sibling. It covers the fundamental security controls that prevent the majority of cyber attacks. Think of it as learning to walk before you run a marathon. It’s government-backed, widely recognised in the UK, and significantly more budget-friendly.
Cyber Essentials Plus is the middle child. It’s more expensive than Cyber Essentials, but often significantly cheaper than ISO 27001. Check out our article on Cyber Essentials if you want to learn more.
Annual Penetration Testing
Regular penetration testing, even without the full ISO framework, can still provide tremendous value.
You get the security insights and vulnerability management without the extensive documentation requirements. It’s like having a personal trainer without committing to a full lifestyle overhaul.
Here’s a pro tip from the cybersecurity trenches: don’t just test the same things over and over again. Smart organisations rotate their test scopes annually, ensuring comprehensive security coverage rather than repeatedly checking the same boxes.
Want to learn more about penetration testing? Check out our comprehensive guide.
Industry-specific Alternatives
Industry-specific alternatives might also be worth exploring. Depending on your sector, there might be compliance frameworks that are more relevant to your specific risks and regulatory requirements.
The key is to start somewhere. Perfect is the enemy of good when it comes to cybersecurity. Having some structured approach to security is infinitely better than crossing your fingers and hoping for the best. Don’t believe us? Check out our article on non-perfect cybersecurity.
Conclusion
ISO 27001 might seem like just another compliance hoop to jump through, but it’s actually an effective (and somewhat vague and expensive) roadmap to better cybersecurity.
And while perfect and impenetrable cybersecurity is effectively impossible, ISO 27001 forces you to think systematically about protecting your information assets and provides a framework that’s recognised globally.
Sure, the paperwork isn’t thrilling, and the costs can make your finance team wince. But when you’re sitting across from a potential client who asks about your ISO 27001 certification, you’ll be glad you invested in it.
Plus, your 3 AM worries about data breaches might just become a thing of the past.
Remember, in the world of cybersecurity, being proactive always beats being reactive. ISO 27001 helps ensure you’re playing defence before you need to worry about offence.