731 901 601
How much does not having ISO 27001 cost? A bill that makes an impression

How much does not having ISO 27001 cost? A bill that makes an impression

Most companies that do not have ISO 27001 do not have it for one reason: the cost of implementation seems too high. That is understandable. Audits, consultancy, documentation, training, certification – these are real expenses. But there is another side to this bill that companies rarely think about until they have to. It is the cost of not having the certificate. And this bill – when it arrives – is far more staggering.

Direct costs of a security incident

A ransomware attack costs a Polish company on average between tens of thousands and several million zlotys – depending on the scale, industry and duration of the downtime. This is not a statistic from some distant world. It is a reality that Polish companies face every year, with increasing frequency and severity.

What makes up this bill?

The costs of restoring systems and data. Recovering encrypted or lost data, rebuilding IT infrastructure, and purchasing new hardware – this is often the largest item. Companies without regularly tested backups discover at the worst possible moment that restoring the system will take weeks, not days.

Operational downtime costs. Every day that a company cannot operate normally represents lost revenue, contractual penalties for missing deadlines, and overtime for staff trying to rectify the situation. With a monthly turnover of around one million zlotys, a week of downtime amounts to losses of around a quarter of a million.

Legal and regulatory compliance costs. A personal data breach must be reported to the UODO within 72 hours and – in many cases – customers must be notified. Legal representation during proceedings, notification costs, and potential administrative fines – these are further items on a bill that grows by the hour.

Reputational costs. These are the most difficult to quantify, but often the most damaging in the long term. A customer who has discovered that their data has been leaked from your company rarely remains a customer for years to come.

Hidden costs – those that don’t appear in any report

Alongside direct costs, there is a category of losses that are just as real, but much harder to measure.

Lost contracts. A company without ISO 27001 is excluded from tenders and supplier qualification processes where the certificate is a formal criterion. The value of these lost contracts will never appear in any financial report – because the company simply does not know how many contracts it lost before it had a chance to submit a bid.

Longer sales cycle. Corporate clients without ISO 27001 certification require extensive security questionnaires, audit visits and lengthy verification processes. Each such process results in weeks or months of delay in signing the contract – and real costs in terms of time for both parties.

Higher insurance premiums. Insurers are increasingly taking the level of cybersecurity maturity into account when setting cyber insurance premiums. A company without ISO 27001 certification pays more – or may not be able to obtain adequate cover at all.

Worse financing terms. Financial institutions and investors are increasingly assessing ESG risks when making credit and investment decisions. The lack of certified information security management systems is a red flag that may affect financing terms.

The full picture – and what it means

Let’s sum it up. The cost of implementing ISO 27001 for a medium-sized company is – with the right consultancy support – a one-off expense, whilst the cost of maintaining the certificate is a few thousand zlotys a year. These are amounts that fit within any normal operating budget.

On the other hand, we have: the risk of an incident that could cost anywhere from tens of thousands to several million, lost contracts whose value we will never know, longer sales cycles, higher insurance premiums and poorer financing terms.

Companies that have experienced a serious security incident without ISO 27001 certification almost always come to the same conclusion: implementation before the incident was many times cheaper than recovery afterwards. The problem is that they reach this conclusion too late.

Read other posts

Documentation under ISO 9001:2026 – what’s changing and what documents does the new standard actually require?

Documentation under ISO 9001:2026 – what’s changing and what documents does the new standard actually require?

One of the most common questions we hear from companies preparing to transition to the new version of the standard is a very practical one: what exactly do I need to have on paper? read more
Your supply chain is only as strong as its weakest link—ISO 28000 changes that

Your supply chain is only as strong as its weakest link—ISO 28000 changes that

Every company that manages a supply chain knows it doesn’t control everything. It controls its warehouse, its vehicles, and its employees. read more
The S46 System – how to register a company in the KSC Register and what to bear in mind by 3 October 2026

The S46 System – how to register a company in the KSC Register and what to bear in mind by 3 October 2026

So far, we have written about who is affected by the NIS 2 Directive, what obligations it imposes, and why it is worth treating it as more than just a formality. read more
More posts