Back to Insights

The ISO Quote

ISO 27001 was 18 months from being relevant to that company. Their vendor didn't mention that.

A fintech founder called me.

Their legal team had recommended ISO 27001 certification. Their security vendor had confirmed it. The quote came in at $40,000.

I ran the diagnosis.

ISO 27001 was 18 months from being relevant to that company. Their vendor didn't mention that.

What we found instead

  • Three gaps that actually mattered. None of them on the vendor's roadmap.
  • A misconfigured access control that had been live for 14 months.
  • A vendor integration with no data-handling agreement.
  • A gap in incident response that would have taken two weeks to fix.
  • Six things they had been paying for with no relevance to their stage, size, or threat profile.
  • A SOC retainer sized for a 500-person company.

The $40,000 project became a $15,000 targeted sprint.


ISO 27001 is a real framework. It is also frequently sold to companies that do not need it yet. Because it is the most expensive, most recognized, and most marketable thing a security vendor can propose.

I tell you what you need. Nothing more.

Related: The Security Diagnosis

Fixed scope. Fixed price. Know exactly what you need. And what you don't.

The Security Diagnosis