731 901 601
How much does not having ISO 27001 cost? A bill that makes an impression

How much does not having ISO 27001 cost? A bill that makes an impression

Most companies that do not have ISO 27001 do not have it for one reason: the cost of implementation seems too high. That is understandable. Audits, consultancy, documentation, training, certification – these are real expenses. But there is another side to this bill that companies rarely think about until they have to. It is the cost of not having the certificate. And this bill – when it arrives – is far more staggering.

Direct costs of a security incident

A ransomware attack costs a Polish company on average between tens of thousands and several million zlotys – depending on the scale, industry and duration of the downtime. This is not a statistic from some distant world. It is a reality that Polish companies face every year, with increasing frequency and severity.

What makes up this bill?

The costs of restoring systems and data. Recovering encrypted or lost data, rebuilding IT infrastructure, and purchasing new hardware – this is often the largest item. Companies without regularly tested backups discover at the worst possible moment that restoring the system will take weeks, not days.

Operational downtime costs. Every day that a company cannot operate normally represents lost revenue, contractual penalties for missing deadlines, and overtime for staff trying to rectify the situation. With a monthly turnover of around one million zlotys, a week of downtime amounts to losses of around a quarter of a million.

Legal and regulatory compliance costs. A personal data breach must be reported to the UODO within 72 hours and – in many cases – customers must be notified. Legal representation during proceedings, notification costs, and potential administrative fines – these are further items on a bill that grows by the hour.

Reputational costs. These are the most difficult to quantify, but often the most damaging in the long term. A customer who has discovered that their data has been leaked from your company rarely remains a customer for years to come.

Hidden costs – those that don’t appear in any report

Alongside direct costs, there is a category of losses that are just as real, but much harder to measure.

Lost contracts. A company without ISO 27001 is excluded from tenders and supplier qualification processes where the certificate is a formal criterion. The value of these lost contracts will never appear in any financial report – because the company simply does not know how many contracts it lost before it had a chance to submit a bid.

Longer sales cycle. Corporate clients without ISO 27001 certification require extensive security questionnaires, audit visits and lengthy verification processes. Each such process results in weeks or months of delay in signing the contract – and real costs in terms of time for both parties.

Higher insurance premiums. Insurers are increasingly taking the level of cybersecurity maturity into account when setting cyber insurance premiums. A company without ISO 27001 certification pays more – or may not be able to obtain adequate cover at all.

Worse financing terms. Financial institutions and investors are increasingly assessing ESG risks when making credit and investment decisions. The lack of certified information security management systems is a red flag that may affect financing terms.

The full picture – and what it means

Let’s sum it up. The cost of implementing ISO 27001 for a medium-sized company is – with the right consultancy support – a one-off expense, whilst the cost of maintaining the certificate is a few thousand zlotys a year. These are amounts that fit within any normal operating budget.

On the other hand, we have: the risk of an incident that could cost anywhere from tens of thousands to several million, lost contracts whose value we will never know, longer sales cycles, higher insurance premiums and poorer financing terms.

Companies that have experienced a serious security incident without ISO 27001 certification almost always come to the same conclusion: implementation before the incident was many times cheaper than recovery afterwards. The problem is that they reach this conclusion too late.

Read other posts

The Responsible Person in the GDP system – who is this and what are their responsibilities?

The Responsible Person in the GDP system – who is this and what are their responsibilities?

Within the Good Distribution Practice system, there is one role that cannot be delegated, replaced by a procedure or omitted from the organisational structure – the Responsible Person (RP). read more
BRCGS Packaging Materials Issue 7 – what has changed since April 2025?

BRCGS Packaging Materials Issue 7 – what has changed since April 2025?

From 28 April 2025, all audits of packaging materials manufacturers must be conducted in accordance with the new, seventh edition of the BRCGS Packaging Materials standard. read more
What happens when a company ceases to operate? ISO 22301 and business continuity management

What happens when a company ceases to operate? ISO 22301 and business continuity management

A fire in the server room, a ransomware attack, a pandemic, a flood, a failure of a key supplier – any of these events can bring a company’s operations to a standstill within a matter of hours if it is unprepared. read more
More posts