Management of Information Security on the rise

23 Mar, 2013

ISO 27001, Information Security, Management standard, ISO 27001 certification

With the recent headlines identifying areas of major security breaches, SME businesses are now turning to the ISO 27001 information security management system to help protect their businesses against cyber threats and ensure there are no vulnerabilities in their existing systems.

More and more companies are now realising that possession of a security policy by itself does not prevent breaches; staff need to understand it and put it into practice. Only 26% of respondents with a security policy believe their staff have a very good understanding of it; 21% think the level of understanding is poor.

The Economist 2002, explained that: “The human side of computer security is easily exploited and constantly overlooked. Companies spend millions of dollars on firewalls, encryption and secure access devices, and it’s money wasted, because none of these measures address the weakest link in the security chain;  the weakest link is people” .

According to one survey conducted by Infosec (2012) 70% of large organisations detected significant attempts to break into their networks in the past year. The average cost of the worst security breach for large organisations was between £110,000 and £250,000 whereas for small business the cost ranged from £15,000 to £30,000. The root cause, the survey report said, was often the failure to invest in educating staff about security risks, with 75% of organisations where the security policy was poorly understood experiencing staff-related breaches.

It’s important to remember that threats to information security do not come through IT alone. Unhappy staff, resentful ex-employees, deceitful managers and competitors can all have access to your confidential information and can use this to the detriment of the business and its reputation. This can be purposeful or accidental. Information is not confined to electronic format but encompasses all forms of communication including verbal and hard copy.ISO 27001 Certification
By implementing a robust information security system like the ISO 27001, ensures that adequate training and records are in place for all staff so that they know what is expected of them. This can prevent most accidental breaches of security and ensure that the company is reviewing their policies on a regular basis to keep up to date with the advancements in technology.


ISO Quality Services Ltd are proud to specialise in the implementation and certification of the Internationally recognised ISO and BS EN Management Standards.

Do you want to get ahead of your competition? Win more tenders or save time and money on reoccurring issues? Contact us today on 0330 058 5551 or email info@isoqsltd.com.

Alternatively, you can request a quote by filling out our enquiry form and a member of our team will be in touch shortly.

Related Posts

Why Make Your Recruitment Agency Your Partner?

12 Sep, 2022

In a candidate driven market how can you not only attract the right applicants, but ensure you’re gaining a long-term employee who will grow with your business?

Environmental: Aerial view of green land and blue sky

How Can SECR Help You Reach Net Zero?

16 Aug, 2022

Net Zero, Greenhouse Gas and Environment issues are driving Commercial Energy obligations and responsibilities are changing worldwide. The UK is leading this revolution.

Our Award-Winning Week!

15 Jul, 2022

Less than a week after our win at the Worcestershire Social Media Awards, we were proud to be taking home another award, but what did we win this time?

ISOQSL Bingo Box an Award Winning Campaign

4 Jul, 2022

We were excited to attend the Worcestershire Social Media Awards last week where we were up for a whopping five awards including Best Social Media Campaign by a Business for our Christmas charity campaign.  Here’s how we got on…