Caxton, one of the UK’s leading fintechs, has just completed a two-year journey to ISO 27001 certification, giving them an in depth perspective on what the process really involves – from the investment and internal changes to all the speed bumps along the way.
More broadly, it raises an interesting question – is ISO 27001 moving beyond a security benchmark and becoming a commercial necessity for growing businesses? And does the trust it brings justify the time and investment required to achieve it?
Recently completing a two-year journey towards ISO certification has felt like a big achievement for my team at Caxton. The certification also sends a powerful signal to our customers that their money and their data is safe with us.
The process that got us here was instructive in many ways but in particular, it got me thinking about the thousands of SMEs and other businesses out there that don’t have dedicated information security teams. How can they too ensure the highest standards of security and what did I learn from the certification process that others can draw upon?
Trust the process
First up however, why did we go for ISO 27001, and why should every business be putting security at the heart of what they do? The answer to that is simple – trust.
Data released earlier this year by the Office of National Statistics revealed that ecommerce spend in the UK hit new highs earlier this summer, accounting for nearly a third of all purchases. Growing volumes of B2B spending too is now done online.
Each of these purchases is based on trust and, if that trust is undermined, the consequences for a business can be significant. But with 43% of businesses in the UK having experienced a cyber-breach or attack in the last twelve months, and with emerging AI systems enabling ever-more sophisticated cyber attacks, the trust businesses build with their customers has never been more important.
To demonstrate the care businesses take with customer data, security and risk management, many businesses opt for external validation, in particular an ISO certification. Indeed, my own team at Caxton recently concluded a two year journey towards ISO 27001 certification, meaning we can now demonstrate the highest standards of security to our thousands of customers who trust us with their payments.
But what about the wider SME economy? The thousands of businesses who form the backbone of the economy, but don’t have dedicated information security teams? As AI makes deepfakes, hacks and other cybercrime ever easier, how can these businesses protect themselves and maintain the trust of customers?
The Expertise Gap
The truth is that – and while it might not be the appropriate route for every business – ISO certification is a process that scales in complexity to reflect the relative complexity of the business applying. So, for us, a business running millions worth of payments globally for thousands of clients as well as thousands of business customers, the complexity of certification reflected the complexity of our business.
For an SME with a relatively straightforward business model and limited sensitivities, the process would likely be much easier.
So, it’s not the complexity per se that’s acting as a barrier, it’s the expertise gap. As anybody who has worked within or run an SME knows, it’s often the case that senior people have multiple roles and their attention is being constantly pulled in multiple directions. While some SMEs might have a dedicated IT or security team, many won’t. This leaves firms struggling to know where to begin with building proper security processes and building a roadmap towards the kind of gold-standard security signified by ISO.
Alongside this, the cost of the risk assessments and external audits and assessors can also add up, regardless of the size of a business. With business finances tight across the UK and many business owners looking nervously towards the budget later in the Autumn, any extra cost at this stage is difficult to justify.
Inaction too however, can come with a cost and this is something many SME owners I speak to need to wrestle with.
Getting the Board onboard
Given the kind of strategic financial and operational decisions that need to be made between investing in security or risking a breach, it’s unsurprising to find that this conversation is increasingly going to the very top of businesses of all sizes.
31% of businesses now deal with cyber-security at board level, a number which is increasing year on year. Despite this, it remains the case that less than half of businesses use any multi-factor authentication, and just 15% review the cyber risk of their immediate suppliers. For those who haven’t been through it, the ISO certification process from the outside can be something of a mystery.
But simple security measures such as better authentication and auditing of suppliers can take SMEs – even those without big IT budgets and lots of staff time to dedicate – a long way towards the kind of best practice that will mitigate risk and keep data safe.
Starting with a single step
The real takeaway for me from Caxton’s own ISO journey is that it starts with a single step. This is as true for a FTSE listed bluechip as it is for a regional SME. So what does this look like in practice?
The first step is to simply start building the processes needed to create the security your business and your customers deserve. In some ways starting with a complete blank slate is actually an advantage. This means that processes can be built and designed in a way that aligns with ISO 27001 from day one, rather than having to amend or retrofit existing processes. Remember too, security isn’t a one off. ISO certification and general security best practice means regularly testing, checking and upgrading systems.
The threat landscape doesn’t stand still, and neither can your security.
£197 million was paid out to UK businesses to help them recover from cyber incidents in 2024, a 230% year-on-year increase with the average financial impact of an attack standing at more than £20,000. More than the financial impact however, the reputational and trust impact of cyber breaches can be immense.
Given this, cybersecurity and processes that protect your business and customers are vital. There’s no one way of delivering this and, while my ISO journey was long and complicated, getting started on your own security journey doesn’t need to be.
