Building a cybersecurity function from scratch: lessons from zero to ISO 27001
From no InfoSec function to zero major audit findings. The people, process, and tools decisions that got us there.
When I took on cybersecurity, there was no InfoSec function. No DLP. No formal controls. Just a growing risk surface and a team that knew something needed to change.
First 90 days: visibility before action
I didn't start by buying tools. I started by understanding what we had: all assets, all access points, all data flows. You can't protect what you can't see. We ran Nessus scans, mapped our external attack surface with NMAP, and built an asset inventory from scratch.
Every security investment should be traceable to a specific risk. If you can't name the risk, don't buy the tool.
DLP and enterprise controls
Data Loss Prevention was the first major implementation. We mapped our sensitive data classifications, identified egress points, and implemented controls across email, endpoint, and cloud. The key was getting HR and Legal involved early so controls were enforceable, not just technical.
The ISO 27001 journey
We achieved ISO 27001 certification with zero major audit findings. The secret wasn't documentation. It was making the controls real. Auditors can tell immediately when a control exists on paper but not in practice.
- Incident response procedures were rehearsed, not just written
- Access reviews happened quarterly, not annually
- Security awareness was embedded in onboarding and weekly team meetings, not a once-a-year checkbox
The number that mattered
Security incidents dropped by 50%. More importantly, when incidents did occur, we detected and contained them faster. The MTTI (Mean Time to Identify) improvement was as significant as the incident reduction itself. Detection speed is often undervalued in security programs. It shouldn't be.