ISO 27001 is about getting organised. It forces companies to document risks, assign ownership, schedule reviews, and make implicit practices explicit. The certification is just the by-product. The real value is building a security-conscious organisation.
ISO 27001 timeline depend on 4 things:
- Company size
- Security maturity
- Dedicated ownership
- Team engagement
3-9 months with a full-time owner.
12-18 months without one.
Certification is the outcome. Organization is the real work.
Startups don’t lose deals with a clear “no”—they lose them in security questionnaires. Missing answers, outdated PDFs, or “we’re working on it” all read the same: no.
The winners aren’t more secure. Just more prepared.
Startups don’t skip security because they don’t care.
They skip it because most security tools were built for enterprises with huge budgets and dedicated teams.
Then a customer asks for ISO 27001, a GDPR audit lands, or a breach happens.
That’s the gap I’m trying to close.
Laid off in January.
It gave me clarity: Most startups don’t need more security complexity — they need security that actually fits how they work.
Now building @UnicisTech: open-source security, privacy, compliance, and governance for smaller teams.
What can go wrong with a small IKEA kitchen? A lot. Scratched worktops, wrong assembly, missing parts, no doors. Reported → no call for 2 weeks. Waited 2h in store → promised call, nothing. Even hung up on me. German IKEA support is a nightmare. @IKEA_FAMILY
Just finished a #marathon on Sunday and finally got to visit the vibrant city of #Brighton for the first time! Smashed my personal best with a time of 3:35:06 — buzzing! More will come on my blog https://t.co/Rbe3I25mV9 #brightonmarathon#running