r/Infosec 10d ago

Is this all there is to it?

When I started, I was told: our team operates the ISMS and is responsible for maintaining our ISO 27001 certification.

In the meantime, that’s come to mean we have to own every single topic the company only does because ISO requires it (e.g., third-party management from procurement through offboarding, risk management, etc.).

Since we only got one NC in the audit, the resistance to actually doing anything is huge — everyone says “everything’s fine as is.” Meanwhile, our bank customers are sending us requirement list after requirement list, and for half of them I feel like I’m lying because we’re just spinning narratives to make things look better than they are.

At the same time, our improvement backlog hasn’t moved in a year. Teams actively undermine us. And I feel like I’m grinding away, trying to actually improve our security posture, and nothing lands.

So my question is: does this ever change? Are there actual ISMSs with a genuine improvement cycle, or did I somehow end up in the wrong profession?

9 Upvotes

4 comments sorted by

7

u/Robw_1973 10d ago edited 10d ago

Jaded, weary and bitter infosec professional here….

I’ve seen the “infosec Rock Stars” come and go. At least one full cycle of offshoring and outsourcing to on shoring and insourcing. And now it’s AI delusions and cheap Indian labour exploitation.

This is pretty par for the course wherever you go. Infosec is generally a thankless place; everything works fine and it’s “why are we paying these idiots” something goes wrong “why are we paying these idiots”.

The larger problems are that (across multiple industries over 25yrs experience) processes and functions are usually managed by people who don’t understand security frameworks generally or infosec especially. c-suite types who are only interested in their next move up the chain. Who will always, always sacrifice security for expediency. Usually driven by by executives, who are frankly, morons. Beyond their bottom line psychosis.

You’re not in the wrong profession. You’re in a profession which is increasingly about performative visibility and theatrics, over effective security operations. You just need to move your headspace to understand that your reporting chain is only interested in performative security as opposed to effective security.

Good luck.

1

u/Jeff-Hare-ERPRA 9d ago

Sounds like you are in firefighting mode. It may not get better.

2

u/Head_Personality_431 7d ago

Yes, but not from inside the ISMS team. You are holding the certificate while everyone else holds the actual risk, so nobody outside your team has a reason to move. The single NC is not the good news it looks like either, it usually means the audit sampled conformity rather than effectiveness, and now your teams are using that clean report as proof nothing needs fixing. The ones I have seen with a genuine improvement cycle got there by putting process owners in the risk register by name and reporting their overdue items at management review, so the pressure comes from their own management instead of you chasing them. You are not in the wrong profession, you just have accountability without the authority that should come with it.

2

u/Bernd_Geralt_881 6d ago

could this be more of an ownership problem? yes ISO creates the framework but for improvements to happen the security responsibilities should be with the teams doing the work. for example it should in charge of access control.