{"id":6872,"date":"2015-07-13T16:23:55","date_gmt":"2015-07-13T16:23:55","guid":{"rendered":"https:\/\/multiacademstg.wpengine.com\/27001academy\/?p=6872"},"modified":"2025-07-10T17:17:52","modified_gmt":"2025-07-10T17:17:52","slug":"how-to-make-your-investment-in-iso-27001-profitable","status":"publish","type":"post","link":"https:\/\/advisera.com\/27001academy\/blog\/2015\/07\/13\/how-to-make-your-investment-in-iso-27001-profitable\/","title":{"rendered":"How to make your investment in ISO 27001 profitable"},"content":{"rendered":"<p>Nothing motivates executives more than profits; so, if you\u2019re proposing your <a href=\"\/27001academy\/what-is-iso-27001\/\" target=\"_blank\" rel=\"noopener noreferrer\">ISO 27001<\/a> project to your top management, you should figure out how this project can increase the profit of your company. \u201cBut how?\u201d you may be wondering. \u201cProfit cannot be created with this kind of a project; there are only costs!\u201d<\/p>\n<p>Actually, you\u2019re wrong \u2013 ISO 27001 can have a positive financial impact on your company. Here\u2019s how.<\/p>\n<h2>How is information security related to profits?<\/h2>\n<p>Profit can be created in two ways: (1) by increasing revenues, and (2) by decreasing costs. Let\u2019s examine both of these from an ISO 27001 perspective.<\/p>\n<p>Many companies are going for ISO 27001 certification because they need this certificate to get a new client through a tender, or because they want to convince their potential customers that they will safeguard their data in the best possible way. So, the point is \u2013 in many cases a company wouldn\u2019t get new clients if they didn\u2019t implement ISO 27001. Since every new client brings in additional revenue, the only question is whether this additional margin is higher than the investment in ISO 27001 \u2013 and it very often is.<\/p>\n<p>Further, the whole philosophy of ISO 27001 is preventive: the main idea is to prevent incidents from happening, or if they do happen, to decrease their impact to a minimum level. In other words, this means that the costs incurred because of incidents won\u2019t happen at all, or they will happen in a much smaller amount. Again, the question is whether this savings is bigger than the investment in ISO 27001 \u2013 and again, the answer is mainly yes.<\/p>\n<p>Of course, this doesn\u2019t mean you can afford to invest huge amounts of money in information security \u2013 you have to make sure you keep the ISO 27001 costs down, because otherwise it won\u2019t create the financial impact you wanted it to. See also:\u00a0<a href=\"https:\/\/advisera.com\/27001academy\/blog\/2012\/06\/19\/5-ways-to-avoid-overhead-with-iso-27001-and-keep-the-costs-down\/\" target=\"_blank\" rel=\"noopener\">5 ways to avoid overhead with ISO 27001 (and keep the costs down).<\/a><br \/>\n<div id=\"middle-banner\" class=\"banner-shortcode\"><\/div><script>loadMiddleBanner();<\/script><br \/>\n<div id=\"side-banner-trigger\" class=\"banner-shortcode\"><\/div><\/p>\n<h2>It\u2019s all about risk management<\/h2>\n<p>When I mentioned the preventive philosophy of ISO 27001, I actually meant the risk management: to prevent bad things from happening, first you have to find out which bad things (i.e., <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=information-security-controls&amp;doc=incident-log\" target=\"_blank\" rel=\"noopener noreferrer\">incidents<\/a>) could happen \u2013 this is called risk assessment. Once you have a list of potential incidents (i.e., risks), you can start thinking about how to mitigate them, or in ISO 27001 words \u2013 how to treat the risks using various information security safeguards. All this together is nothing more than risk management. (To learn more about this concept, read <a href=\"\/27001academy\/knowledgebase\/the-basic-logic-of-iso-27001-how-does-information-security-work\/\" target=\"_blank\" rel=\"noopener\">The basic logic of ISO 27001: How does information security work?<\/a><\/p>\n<p>The concept of risk management has existed in companies for a very long time \u2013 executives throughout the world insure their buildings, vehicles, and other higher-value assets against different threats (i.e., they transfer the risks to an insurance company), but they also tend to diversify their products and their markets because they don\u2019t want to put all their eggs in the same basket \u2013 i.e., they want to reduce the risk of relying on a single product or a single market.<\/p>\n<p>In smaller companies this <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=risk-management&amp;doc=risk-assessment-and-risk-treatment-methodology\" target=\"_blank\" rel=\"noopener noreferrer\">risk management<\/a>\u00a0is informal, and in larger companies it is more explicit and formal, but the point is \u2013 managers are used to <a href=\"https:\/\/advisera.com\/27001academy\/iso-27001-documentation-toolkit\/?rel=risk-management&amp;doc=risk-treatment-plan\" target=\"_blank\" rel=\"noopener noreferrer\">managing risks<\/a>, and this kind of thinking is something they do understand.<\/p>\n<p>It is true that executives normally do not view information security from this perspective of risk management, so if you want to succeed when speaking to them, then you need to treat your information security as just another way of managing risks. It is a rather novel way to present a security project, but it is also the most effective, because instead of firewalls and disaster recovery sites, now you can start speaking about money \u2013 and this is the language they do understand.<\/p>\n<h2>Which concrete steps are required?<\/h2>\n<p>So, knowing all this, what should you do? Basically, the following steps would be advisable:<\/p>\n<ul>\n<li>Define which potential benefits your company could achieve by implementing ISO 27001 \u2013 see <a href=\"\/27001academy\/knowledgebase\/iso-27001-implementation-checklist\/#benefits\" target=\"_blank\" rel=\"noopener noreferrer\">Four key benefits of ISO 27001 implementation<\/a>.<\/li>\n<li>Try to calculate the profit achieved by such benefits \u2013 see <a href=\"https:\/\/advisera.com\/27001academy\/free-tools\/free-return-security-investment-calculator\/\" target=\"_blank\" rel=\"noopener noreferrer\">Return on Security Investment Calculator<\/a>.<\/li>\n<li>Calculate the total investment needed for ISO 27001 implementation \u2013 see <a href=\"https:\/\/advisera.com\/27001academy\/knowledgebase\/iso-27001-implementation-checklist\/#costs\" target=\"_blank\" rel=\"noopener\">How much does ISO 27001 implementation cost?<\/a><\/li>\n<li>Prepare yourself to present the case to your executives \u2013\u00a0<a href=\"https:\/\/advisera.com\/27001academy\/webinar\/iso-27001-benefits-how-to-get-management-buy-in-free-webinar-on-demand\/\" target=\"_blank\" rel=\"noopener noreferrer\">ISO 27001 benefits: How to get management buy-in<\/a>\u00a0.<\/li>\n<\/ul>\n<p>Would you agree with these steps? What do you see as the biggest obstacles in getting the support from your top management?<\/p>\n<p><em>Check out this free PowerPoint presentation <\/em><a href=\"https:\/\/info.advisera.com\/27001academy\/free-download\/project-proposal-for-iso-27001-implementation-powerpoint\" target=\"_blank\" rel=\"noopener noreferrer\">Project proposal for ISO 27001 implementation<\/a>\u00a0<em>that will help show you which items would be the best to present to your top management.<\/em><br \/>\n<em><span class=\"notion-enable-hover\" data-token-index=\"0\">To learn how to implement ISO 27001 in the most cost-efficient way when compared to other solutions, and to save your employees time,\u00a0<\/span><\/em><a class=\"notion-link-token notion-focusable-token notion-enable-hover\" tabindex=\"0\" href=\"https:\/\/advisera.com\/conformio\/\" target=\"_blank\" rel=\"noopener\" data-token-index=\"1\"><span class=\"link-annotation-unknown-block-id-1092142182\">sign up for a 14-day free trial<\/span><\/a>\u00a0<em><span class=\"notion-enable-hover\" data-token-index=\"3\">of Conformio, the leading ISO 27001 compliance software.<\/span><\/em><!-- notionvc: abcd8b52-23aa-4cc7-ae92-72a9df831c54 --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nothing motivates executives more than profits; so, if you\u2019re proposing your ISO 27001 project to your top management, you should figure out how this project can increase the profit of your company. \u201cBut how?\u201d you may be wondering. \u201cProfit cannot be created with this kind of a project; there are only costs!\u201d Actually, you\u2019re wrong &#8230;<\/p>\n","protected":false},"author":26,"featured_media":6875,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[381,815,816],"class_list":["post-6872","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-iso-27001","tag-top-management","tag-benefits"],"acf":[],"_links":{"self":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/6872","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/users\/26"}],"replies":[{"embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/comments?post=6872"}],"version-history":[{"count":3,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/6872\/revisions"}],"predecessor-version":[{"id":104377,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/posts\/6872\/revisions\/104377"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/media\/6875"}],"wp:attachment":[{"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/media?parent=6872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/categories?post=6872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/advisera.com\/27001academy\/wp-json\/wp\/v2\/tags?post=6872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}