
Most companies that do not have ISO 27001 do not have it for one reason: the cost of implementation seems too high. That is understandable. Audits, consultancy, documentation, training, certification – these are real expenses. But there is another side to this bill that companies rarely think about until they have to. It is the cost of not having the certificate. And this bill – when it arrives – is far more staggering.
A ransomware attack costs a Polish company on average between tens of thousands and several million zlotys – depending on the scale, industry and duration of the downtime. This is not a statistic from some distant world. It is a reality that Polish companies face every year, with increasing frequency and severity.
What makes up this bill?
The costs of restoring systems and data. Recovering encrypted or lost data, rebuilding IT infrastructure, and purchasing new hardware – this is often the largest item. Companies without regularly tested backups discover at the worst possible moment that restoring the system will take weeks, not days.
Operational downtime costs. Every day that a company cannot operate normally represents lost revenue, contractual penalties for missing deadlines, and overtime for staff trying to rectify the situation. With a monthly turnover of around one million zlotys, a week of downtime amounts to losses of around a quarter of a million.
Legal and regulatory compliance costs. A personal data breach must be reported to the UODO within 72 hours and – in many cases – customers must be notified. Legal representation during proceedings, notification costs, and potential administrative fines – these are further items on a bill that grows by the hour.
Reputational costs. These are the most difficult to quantify, but often the most damaging in the long term. A customer who has discovered that their data has been leaked from your company rarely remains a customer for years to come.
Alongside direct costs, there is a category of losses that are just as real, but much harder to measure.
Lost contracts. A company without ISO 27001 is excluded from tenders and supplier qualification processes where the certificate is a formal criterion. The value of these lost contracts will never appear in any financial report – because the company simply does not know how many contracts it lost before it had a chance to submit a bid.
Longer sales cycle. Corporate clients without ISO 27001 certification require extensive security questionnaires, audit visits and lengthy verification processes. Each such process results in weeks or months of delay in signing the contract – and real costs in terms of time for both parties.
Higher insurance premiums. Insurers are increasingly taking the level of cybersecurity maturity into account when setting cyber insurance premiums. A company without ISO 27001 certification pays more – or may not be able to obtain adequate cover at all.
Worse financing terms. Financial institutions and investors are increasingly assessing ESG risks when making credit and investment decisions. The lack of certified information security management systems is a red flag that may affect financing terms.

Let’s sum it up. The cost of implementing ISO 27001 for a medium-sized company is – with the right consultancy support – a one-off expense, whilst the cost of maintaining the certificate is a few thousand zlotys a year. These are amounts that fit within any normal operating budget.
On the other hand, we have: the risk of an incident that could cost anywhere from tens of thousands to several million, lost contracts whose value we will never know, longer sales cycles, higher insurance premiums and poorer financing terms.
Companies that have experienced a serious security incident without ISO 27001 certification almost always come to the same conclusion: implementation before the incident was many times cheaper than recovery afterwards. The problem is that they reach this conclusion too late.