0%
BACK TO OVERVIEW

Certified, But Not Secure: What ISO 27001, SOC 2 & Co. Actually Prove

Audit passed, ISO 27001 certificate framed on the wall or displayed as a badge in the website footer. The team celebrates. The reality check next door: the fire door to the server room stands open because the hallway gets too warm. A stranger in overalls walks through the office unbothered, carrying a ladder. Nobody stops him — even though the policy is unambiguous: unknown individuals without a badge must be challenged and escorted immediately.

That this scenario isn't an exaggeration dreamed up by security consultants was proven by well-known security expert Jayson E. Street during a physical penetration test in Beirut.

An international bank wanted to assess how well the physical security of its branches held up. On paper, everything looked perfect: strict access rules, clear ID requirements, defined processes. Street entered the building wearing neither a disguise nor using force — just everyday clothes, a fake badge around his neck, and a friendly smile. Walking past the reception with confidence, he pretended he had just come from the branch manager's office. Instant implicit trust. Nobody questioned his identity or asked for his badge.

<3 min.
Until he was behind the bank's teller counter
Full access
To IT systems via planted USB drives (rubber duckies)
1 PC
Unplugged and carried out of the building under his arm
0
Employees who questioned his identity

The unsettling part: the employees weren't malicious. They simply wanted to be polite and assumed someone else must have already verified the person. On paper, every security measure existed. In reality, confidence and a dash of human helpfulness were enough to bypass the entire security concept.

A certificate only shows that you know how to write documents — not how your employees actually behave day to day.

What certifications really are — and what they aren't

Certifications are proof, for third parties — customers, partners, insurers — that a company meets defined standards for security, privacy, or risk management. They build market trust and shorten sales cycles: instead of answering 500 individual questions on a security questionnaire, you send over the certificate and save weeks in the sales process.

Important framing: certifications assess processes and documentation — not necessarily whether a system is technically impenetrable.

The most important standards at a glance

Three standards show up most often in security questionnaires. They answer different questions and aren't mutually exclusive:

Standard What it is What gets assessed Notable trait
ISO/IEC 27001 International standard for an Information Security Management System (ISMS) Framework, processes, risk management Under Germany's IT-Grundschutz, both basic and core protection levels are possible
SOC 2 Type I US-centric report based on the AICPA's Trust Services Criteria Design of security controls at a single point in time Faster and cheaper than Type II
SOC 2 Type II Deeper variant of the same framework Whether the controls operated effectively over 3–12 months Builds more trust by proving long-term effectiveness
TISAX ISO 27001 offshoot for the automotive industry Information security across the supply chain Focused on supply-chain and prototype protection

Put differently: ISO 27001 provides the framework for a certified ISMS, while SOC 2 verifies compliance with security standards against specific principles. Both paths lead to a piece of proof — but neither of them is a penetration test.

Why certifications don't mean you're secure

Executives often treat certificates like a food-safety seal: "Now we're 100% secure." That mindset produces exactly the wrong kind of reassurance attackers hope for — risk blindness.

Snapshot vs. day-to-day reality

Audits are like a visit from the in-laws: two weeks before, everyone frantically tidies up, closes tickets, rotates passwords, and updates documents. The moment the auditor leaves the building, the system often slips right back into old patterns — audit fatigue.

Security is a continuous state. An audit is only a snapshot in time.

The "paper compliance" phenomenon

A policy document doesn't protect any data. You can have 50 pages of password-security policy — if developers still commit their API key to a public GitHub repository, the policy is worthless.

That even AI industry pioneers aren't immune to this trap was shown by the incident surrounding Anthropic's development tool Claude Code: while billions flow into the mathematical and ethical safety of AI models, practice fell apart on the most basic fundamentals of software hygiene when internal source code was unintentionally exposed publicly.

Billions for AI safety, zero for software hygiene: even highly professional organizations don't fail on sophisticated attacks — they fail on the most basic fundamentals.

Human factors

Two patterns recur in nearly every physical assessment — regardless of industry or the certificate on the wall:

01
Physical security
Fire doors or server-room doors stand open because it's convenient. When security processes slow down the workflow — 2FA on every tab switch, heavy doors with no card reader — people always take the path of least resistance. The door gets propped open.
02
Human factor / culture
The policy says "wear your badge and challenge strangers." Reality says "I don't want to be rude" or "he probably is a technician." Out of fear of confrontation — "what if that's the foreman and I make a fool of myself?" — nobody stops the man in overalls. Classic tailgating.

Auditors are not penetration testers

Two entirely different disciplines get conflated in boardrooms all the time:

Checks evidence
Auditor
Sampling · documentation · point in time
Checks samples and evidence: "show me the log of the last risk analysis"
Often has only a few days for hundreds of controls
Whoever hands over the right 10 servers for the sample sheet passes — even if 90 others are unpatched
Checks reality
Penetration tester
Active attack · social engineering · exploitation
Actively tries to hack your systems
Runs social engineering and exploits any weaknesses found
Checks whether protection actually holds up under real attack

A passed audit is not a passed hacking attempt.

Checkbox mentality crowds out real risk awareness

Teams focus on ticking off the auditor's list instead of analyzing real, novel threats such as AI-driven phishing or zero-day exploits. A company fulfills the requirement of "annual security awareness training" — and the CFO still falls for a deepfake voice call impersonating the CEO, because the static checkbox training never covered modern AI spear-phishing scenarios.

Compliance asks: "Do we have the policy?" Security asks: "Does the protection actually work if we're attacked today?"

The 3 most dangerous myths of compliance

Myth 1
"No hacker can touch us"
Certified = unbreachable
  • Hackers don't read certificates
  • They exploit misconfigurations, open doors, and unverified people
  • A seal doesn't change anything about a propped-open fire door
Myth 2
"Security is IT's job"
Responsibility gets outsourced
  • One employee holding open a fire door can undo €100,000 of IT infrastructure
  • One click on the wrong link does exactly the same
  • Security is everyone's job — not just one team's
Myth 3
"One audit a year is enough"
Snapshot instead of continuous state
  • Attackers audit you every day — automated and without warning
  • Configurations and threat landscapes change daily
  • A once-a-year snapshot says nothing about week 30

The path to real security

Certifications remain a sensible starting point — but only if four principles shape the day-to-day reality beyond the audit:

  • Adopt an assumed-breach mentality: assume attackers are already on the network or the door is already open. Test response time, not just prevention.
  • Red teaming & blue teaming instead of scheduled audits: have red teams — physical and digital — attack unannounced. Follow up together with the blue team in a blameless after-action review.
  • Pragmatic policies instead of 100-page PDFs: policies need to work in daily practice. If a door constantly stands open, the problem isn't the employee — it's a broken process, such as poor ventilation in the hallway.
  • Foster a no-blame culture: an employee who let the man in overalls through, or clicked a bad link, needs to be able to report it immediately without fear of consequences.

Conclusion: certificate on the wall, door propped open next to it

The most important point first: certifications are far from pointless. They provide a necessary foundation, shorten sales cycles, and force organizations to actually document their processes in the first place. The problem doesn't start with certification — it starts with assuming the work is done once you have it.

Just because something exists on paper doesn't mean it's actually true in practice. "The door exists" is different from "the door is permanently propped open." "We have a SIEM/SOC" is different from "it basically never responds in real-world tests."

This isn't a contradiction between ISO and pentests, where one method makes the other redundant. ISO 27001 and a physical pentest simply answer different questions. The problem only arises when a CISO asks the first question — and treats it as if it answered the second one too.

  • Use certificates as a door-opener in sales — but don't rely on them alone.
  • Invest in security culture: empower employees to report mistakes without fear — not just in policy documents.
  • Test your security realistically through regular red teaming / pentests and hands-on security awareness training.

Is your certificate just hanging on the wall while the fire door next to it stays propped open?

We help companies stop just ticking off compliance and start building real, lived security instead.

Request an Initial Consultation →
Tags // #Pentesting #SecurityAudit #ISO27001 #Certification #SOC2 #TISAX #Tailgaiting

© AccessGranted X GmbH