惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
D
DataBreaches.Net
Microsoft Security Blog
Microsoft Security Blog
V
Visual Studio Blog
GbyAI
GbyAI
美团技术团队
云风的 BLOG
云风的 BLOG
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
博客园 - 叶小钗
Engineering at Meta
Engineering at Meta
博客园 - 三生石上(FineUI控件)
N
Netflix TechBlog - Medium
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
Google Developers Blog
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
U
Unit 42
P
Proofpoint News Feed
V
V2EX

Enterprise – Silicon Republic

Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey
Opinion: Why ISO 27001 alone won't save your data from it...
silicon · 2026-05-01 · via Enterprise – Silicon Republic

Nahla Davies looks at the blind spot between information security controls and genuine data integrity governance.

There’s a strange kind of confidence that comes with getting ISO 27001 certified. The audit’s done, the certificate’s on the wall, and suddenly everyone in the building sleeps a little better at night. It feels like you’ve handled the security question once and for all.

But here’s what nobody talks about at the celebration dinner: most of the data risks that actually burn companies in 2026 have very little to do with whether you passed an audit. They’re messier than that.

They live in the mundane, everyday chaos of how teams create, move, copy and forget about data. And that’s exactly where ISO 27001, for all its value, starts running out of answers.

The certification covers the framework, not the mess

ISO 27001 is genuinely useful. Let’s get that out of the way. It gives organisations a structured approach to information security management, and it forces leadership to actually think about risk in a systematic way. For companies that had nothing before, it’s a massive step forward.

But the standard was designed to assess whether you have the right policies, controls and processes in place. It’s checking that the architecture exists. What it can’t do is follow your data around on a Tuesday afternoon when someone in marketing copies a client list into a personal Google Sheet to ‘just quickly check something’.

That’s where the gap lives. The certification tells auditors you’ve built the walls. It doesn’t tell anyone what’s happening inside the rooms. And in most organisations, what’s happening inside the rooms is borderline chaotic.

Think about how data actually moves through people in a modern company. It starts in one system, gets exported into a spreadsheet, emailed to a colleague, uploaded to a shared drive, duplicated across three departments, and eventually forgotten in a folder nobody’s opened since last quarter. None of that necessarily violates your ISO 27001 controls. All of it creates risk.

The standard asks whether you have an asset inventory and data classification policy. Most certified companies do. But the reality of enforcing classification at scale, across thousands of files and dozens of tools, is a completely different problem. It’s like having a fire evacuation plan pinned to the wall while half the exits are blocked with furniture. Technically compliant, but practically dangerous.

Data governance is the part everyone skips

There’s a reason data governance keeps coming up in security conversations, even though it sounds painfully boring. It’s because governance is the layer that sits between policy and reality. It’s the part that answers questions like: who actually owns this dataset? When was it last reviewed? Does anyone know it’s still being stored in three places?

ISO 27001 touches on some of this. Annex A has controls around information classification, access management and asset ownership. But the standard treats these as boxes to check during an audit cycle. In practice, data governance requires constant, active attention. It’s operational, not periodic.

Most companies that get certified build their documentation, assign their roles, and move on. Six months later, the data landscape has shifted entirely. New tools get adopted, teams reorganise, people leave and their access lingers. The certificate stays valid. The risks multiply.

And this is particularly true with unstructured data, which makes up the vast majority of what most organisations hold. Emails, documents, chat logs, shared files. ISO 27001 doesn’t have a great answer for the sheer volume and unpredictability of unstructured data. It assumes you can classify and control it. Anyone who’s tried knows that’s optimistic at best.

What’s really needed alongside certification is a living, breathing data governance practice. One that maps where sensitive data actually resides (not just where it’s supposed to), monitors how it moves, and flags when something drifts outside acceptable boundaries. That’s not an audit exercise. It’s an ongoing operational function.

Compliance creates a floor, not a ceiling

There’s a broader point here that applies beyond ISO 27001. Compliance frameworks, by their nature, set a minimum bar. They define what ‘acceptable’ looks like at a given point in time, even with edge cases like using AI for software testing. But threats evolve, technology changes, and the way people work shifts constantly. A standard that’s reviewed every few years simply can’t keep pace with how quickly the data landscape moves.

This is especially relevant as AI tools become embedded in everyday workflows. Employees are feeding company data into large language models, using AI assistants to summarise internal documents, and generating content based on proprietary information. ISO 27001 wasn’t written with that reality in mind. The 2022 update made strides, sure, but the speed of AI adoption has outpaced what any standard can reasonably address.

Companies that treat certification as the finish line tend to develop blind spots in exactly these areas. They’re compliant on paper but exposed in practice. The data risks they face aren’t coming from sophisticated external attacks (though those matter too). They’re coming from inside the house, from the everyday, unglamorous ways people interact with information.

The smartest organisations use ISO 27001 as a foundation and then build upward. They invest in data discovery tools that map shadow data. They implement real-time monitoring for sensitive information. They train employees not just on policy, but on the practical habits that keep data from wandering into places it shouldn’t be. Certification becomes the starting point of the security conversation, not the conclusion.

Final thoughts

ISO 27001 deserves its reputation as a serious, credible framework. Getting certified takes real effort, and it signals that an organisation takes information security seriously.

But there’s a growing disconnect between what the certificate proves and what modern data environments actually demand. The biggest risks today come from data sprawl, from duplication and drift and the quiet entropy of information that nobody’s actively managing.

Addressing that takes more than a framework. It takes a culture of continuous governance, practical tooling, and an honest look at the gap between how data should behave and how it actually does. The certificate opens the door. What you build behind it is what actually matters.

By Nahla Davies

Nahla Davies is a software developer and tech writer. Before devoting her work full time to technical writing, she managed – among other intriguing things – to serve as a lead programmer at an Inc 5,000 experiential branding organisation, where clients include Samsung, Time Warner, Netflix and Sony.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.