Live data from Hacker News

Ask HN: Is the ISO 27001 certification worth it?

news.ycombinator.com

91–100 of 104 posts

Re: Ask HN: Is the ISO 27001 certification worth it?

#91
post #14

If you are a b2b company your customers will start to ask you at a certain point. Not having it can break a deal for sure although having it won't make the deal. My advice to you is gradually improve your infosec posture and policies etc but rather than kicking off the certification, wait until a customer asks you for it during vendor due dilligence, then say "we're working towards it" and immediately after the meeti…

This has been the best answer in my opinion, the cost of achieving the certification is only worth it if you have prospect customers demanding for it (so that their business will "pay" for the cost). Oftentimes, companies from the USA will prefer SOC2 Type2 instead of ISO. So in my experience it is best to check with the market. Regarding B2C companies, in my experience you'd like to get an ISO certification to reduc…

Yeah exactly that's the reason. In my last company we did eventually have to get ISO27001, SOC2 and ISAE3402 but by waiting until the customer demand is there you get the best sequencing and avoid duplication of effort as far as possible.

Your time and focus is an extremely precious resource especially early on in a startup's lifetime.

Re: Ask HN: Is the ISO 27001 certification worth it?

#92
We[1] are one of few software houses, that actually got it. And we're relatively small (30+ people on board).

Certification is not easy and it's not cheap (don't anyone tell you it's otherwise), it's time consuming, but can be done in few weeks (we managed to get certified in 3 months). It's worth mentioning, that instead of covering whole company, you can cover only small department fitted in one room. Maybe not best practice, but certainly possible. And being slightly paranoid beforehand helps a lot. Also - given how time consuming it is once you have it, it's worth to have someone (somehow) dedicated to it in the company - fortunately my great COO does most of the paperwork and checks processes between audits.

Most of our (potential) clients do not ask often about it, but I think it helps to mention ISO at some point. Bigger clients dealing with personal (or health) data do require it and it's a deal breaker.

1. https://prograils.com

Re: Ask HN: Is the ISO 27001 certification worth it?

#93
I've been through this. I started a B2B SaaS and the very first customer required us to get it before we could go live.

I found engaging a specialist consulting company invaluable to guide us through understanding the spec and designing processes and policies that were proportionate to our size and skillset. But be warned, there are a lot of chancers in this space - e.g. I had a few companies say they could give us a pre-written set of policies and give us the cert in a couple of weeks. Do. Not. Do. This. This consultancy even sat in on our first external audit to help us work our way through it, which turned out to be critical as the auditor went off-beam and started faulting us for not doing things that weren't even in the spec. So this isn't something you can wing your way through - you have to become an expert and thoroughly understand the spec, and its implications, in depth.

I spent a couple of months, full time, on getting to grips with the spec, grinding down scope and coming up with the lightest-touch policies possible that would a) still be useful and b) satisfy the auditors. And yet it's still critically important that you get an auditor who understands small companies - there are still some out there that are adamant it has to be a massively cumbersome thing that takes entire teams just to run.

But, be warned, this does place an ongoing admin burden on your company that you wouldn't otherwise have. Documenting and evidencing actions that wouldn't necessarily need it before, as well as conducting your own internal audits to ensure you're still doing the things you said you'd do.

So I would not recommend getting it until you're forced to by a client.

The good news is I was able to argue all the things we were doing as a matter of course in our software dev lifecycle could be mapped directly onto 27001's requirements. Things like declaring that the documentation of our networking and infrastructure _is_ our terraform scripts. Just because an auditor doesn't know how to read them doesn't mean they're not a perfectly valid form of documentation for the team using them.

So, yes, small, agile companies can gain and maintain certification (our last external audit by the British Standards Institute was passed with no non-conformities), but it's hard work and means spending effort that doesn't directly add value to the business.

Re: Ask HN: Is the ISO 27001 certification worth it?

#94

We[1] are one of few software houses, that actually got it. And we're relatively small (30+ people on board). Certification is not easy and it's not cheap (don't anyone tell you it's otherwise), it's time consuming, but can be done in few weeks (we managed to get certified in 3 months). It's worth mentioning, that instead of covering whole company, you can cover only small department fitted in one room. Maybe not bes…

Ahh, ISO.

"you can cover only small department fitted in one room" - this is the most important part to remember when someone comes in waving their ISO certification and has beautiful badge on their website. You can certify your secretary, her cat and her desk in whatever fancy ISO certification you want. Funnily enough it does not really cost that much, there are consulting companies that gladly organize this for a few thousand dollars. This works like this for all ISO certifications.

Another thing, introduction of ISO in the company means only that there is some process to do X within the company. This process can be totally nuts and useless, but ISO certification holds as the process is there.

In general ISO makes a lot of sense for production line environment (like cars production, etc.) - the process is everything there, having someone to review this process is important and valuable, many other ISO certs are just marketing tool that does not really tell much without going into details what processes are covered by ISO.

Re: Ask HN: Is the ISO 27001 certification worth it?

#95
post #94

We[1] are one of few software houses, that actually got it. And we're relatively small (30+ people on board). Certification is not easy and it's not cheap (don't anyone tell you it's otherwise), it's time consuming, but can be done in few weeks (we managed to get certified in 3 months). It's worth mentioning, that instead of covering whole company, you can cover only small department fitted in one room. Maybe not bes…

Ahh, ISO. "you can cover only small department fitted in one room" - this is the most important part to remember when someone comes in waving their ISO certification and has beautiful badge on their website. You can certify your secretary, her cat and her desk in whatever fancy ISO certification you want. Funnily enough it does not really cost that much, there are consulting companies that gladly organize this for a…

Haha, yeah. We've covered whole company, but yeah, you're right and it's a joke.

Regarding processes - yes and no - if you can viably proof, that process is not (yet) needed and you're doing things in reasonably manner, then you're good. It's up to you what processes you'll introduce to the company. What we think we did well is that whole certification did not change how we work and it was (almost) painless for our employees (or at least I like to think so).

Re: Ask HN: Is the ISO 27001 certification worth it?

#96
I actually looked into those certifications as a person who's considering one day starting a small 1 person SaaS company. It seems like both ISO 27001 and SOC 2 can both easily cost more than 10'000$ to get, even for very small organizations.

That is a dealbreaker. There is precisely 0 value for anyone working at such a small scale to attempt to pursue those certifications - their costs will not only take up a lot of their time, but probably also exceed their revenue. That said, at that scale it's likely that also doing enterprise sales will simply not be possible, given the long purchase cycles and ample bureaucracy.

It should probably only be a concern with at least 20 employees or more, when targeting enterprises. Until then, there might as well be fully automated purchasing funnels, with no way to "contact sales", with the "enterprise plans" simply being self-hosted offerings: if any potential clients want to ensure compliance, they can simply buy the source code and a license for X number of cores/instances/whatever and put it on their fully compliant servers, do code audits, make their own customizations etc.

Of course, if you don't jump through enough of the bureaucratic hoops put in place by the enterprises, then it's likely that they won't even purchase your code.

Re: Ask HN: Is the ISO 27001 certification worth it?

#97

(I work at/cofounded Vanta) We work with companies doing B2B sales and looking for help with compliance certifications like ISO 27001 and SOC 2. Some folks come to us early but most come with a deal on the line — which is to say, this is a process you can start “just in time” if you must. From what I’ve seen, saying “no I won’t go through your security review process” is an (obvious) dealbreaker, but there’s a lot of…

We just signed up with Vanta to do our SOC2. I have to say that the process is a lot of work but can give a +1 for any other SaaS to use Vanta, they make the process simpler and lore automated helping guide you through the complexity and you have regular calls with your Vanta account rep, who actually gets on zoom calls with you every couple of weeks to make sure you get through the process, which is amazing support.

Thanks Christina and the Vanta team for making the SOC2 compliance process… digestible :)

Re: Ask HN: Is the ISO 27001 certification worth it?

#98
I would definitely recommend ISO 27001 or SOC2 which is the equivalent in the US, but with a few caveats. Having gone through the process myself I can without a doubt say it elevates your security posture by introducing an almost uncomfortable amount of rigor in your processes and procedures. The caveat here is that it is an intense process - weeks or months to prepare for and the security procedures you put in place are especially heavy for a smaller company. Maintaining these certifications takes a lot of work too and you would almost need to hire a security officer to keep up with it.

Re: Ask HN: Is the ISO 27001 certification worth it?

#99
ISO27001 is quite hard to achieve, and gets harder the bigger you are. In large companies it is a years' long initiative, if it is achievable at all. So for a smaller supplier, particularly if you have a SaaS product, it is of immense value and can be used as a differentiator.

We are really pleased that we went through the effort. From a sales perspective it makes a significant difference including being positive for marketing and reducing the sales cycle. From a technical perspective, all of the value that it provides to sales and revenue means that the technical team gets the resources needed to do a better job of security (which is the point of the process)

Post reply on HN