The ISO Quote
ISO 27001 was 18 months from being relevant to that company. Their vendor didn't mention that.
A fintech founder called me.
Their legal team had recommended ISO 27001 certification. Their security vendor had confirmed it. The quote came in at $40,000.
I ran the diagnosis.
ISO 27001 was 18 months from being relevant to that company. Their vendor didn't mention that.
What we found instead
- Three gaps that actually mattered. None of them on the vendor's roadmap.
- A misconfigured access control that had been live for 14 months.
- A vendor integration with no data-handling agreement.
- A gap in incident response that would have taken two weeks to fix.
- Six things they had been paying for with no relevance to their stage, size, or threat profile.
- A SOC retainer sized for a 500-person company.
The $40,000 project became a $15,000 targeted sprint.
ISO 27001 is a real framework. It is also frequently sold to companies that do not need it yet. Because it is the most expensive, most recognized, and most marketable thing a security vendor can propose.
I tell you what you need. Nothing more.
Related: The Security Diagnosis
Fixed scope. Fixed price. Know exactly what you need. And what you don't.
The Security Diagnosis