Audit passed, ISO 27001 certificate framed on the wall or displayed as a badge in the website footer. The team celebrates. The reality check next door: the fire door to the server room stands open because the hallway gets too warm. A stranger in overalls walks through the office unbothered, carrying a ladder. Nobody stops him — even though the policy is unambiguous: unknown individuals without a badge must be challenged and escorted immediately.
That this scenario isn't an exaggeration dreamed up by security consultants was proven by well-known security expert Jayson E. Street during a physical penetration test in Beirut.
An international bank wanted to assess how well the physical security of its branches held up. On paper, everything looked perfect: strict access rules, clear ID requirements, defined processes. Street entered the building wearing neither a disguise nor using force — just everyday clothes, a fake badge around his neck, and a friendly smile. Walking past the reception with confidence, he pretended he had just come from the branch manager's office. Instant implicit trust. Nobody questioned his identity or asked for his badge.
The unsettling part: the employees weren't malicious. They simply wanted to be polite and assumed someone else must have already verified the person. On paper, every security measure existed. In reality, confidence and a dash of human helpfulness were enough to bypass the entire security concept.
A certificate only shows that you know how to write documents — not how your employees actually behave day to day.
What certifications really are — and what they aren't
Certifications are proof, for third parties — customers, partners, insurers — that a company meets defined standards for security, privacy, or risk management. They build market trust and shorten sales cycles: instead of answering 500 individual questions on a security questionnaire, you send over the certificate and save weeks in the sales process.
Important framing: certifications assess processes and documentation — not necessarily whether a system is technically impenetrable.
The most important standards at a glance
Three standards show up most often in security questionnaires. They answer different questions and aren't mutually exclusive:
| Standard | What it is | What gets assessed | Notable trait |
|---|---|---|---|
| ISO/IEC 27001 | International standard for an Information Security Management System (ISMS) | Framework, processes, risk management | Under Germany's IT-Grundschutz, both basic and core protection levels are possible |
| SOC 2 Type I | US-centric report based on the AICPA's Trust Services Criteria | Design of security controls at a single point in time | Faster and cheaper than Type II |
| SOC 2 Type II | Deeper variant of the same framework | Whether the controls operated effectively over 3–12 months | Builds more trust by proving long-term effectiveness |
| TISAX | ISO 27001 offshoot for the automotive industry | Information security across the supply chain | Focused on supply-chain and prototype protection |
Put differently: ISO 27001 provides the framework for a certified ISMS, while SOC 2 verifies compliance with security standards against specific principles. Both paths lead to a piece of proof — but neither of them is a penetration test.
Why certifications don't mean you're secure
Executives often treat certificates like a food-safety seal: "Now we're 100% secure." That mindset produces exactly the wrong kind of reassurance attackers hope for — risk blindness.
Snapshot vs. day-to-day reality
Audits are like a visit from the in-laws: two weeks before, everyone frantically tidies up, closes tickets, rotates passwords, and updates documents. The moment the auditor leaves the building, the system often slips right back into old patterns — audit fatigue.
Security is a continuous state. An audit is only a snapshot in time.
The "paper compliance" phenomenon
A policy document doesn't protect any data. You can have 50 pages of password-security policy — if developers still commit their API key to a public GitHub repository, the policy is worthless.
That even AI industry pioneers aren't immune to this trap was shown by the incident surrounding Anthropic's development tool Claude Code: while billions flow into the mathematical and ethical safety of AI models, practice fell apart on the most basic fundamentals of software hygiene when internal source code was unintentionally exposed publicly.
Billions for AI safety, zero for software hygiene: even highly professional organizations don't fail on sophisticated attacks — they fail on the most basic fundamentals.
Human factors
Two patterns recur in nearly every physical assessment — regardless of industry or the certificate on the wall:
Auditors are not penetration testers
Two entirely different disciplines get conflated in boardrooms all the time:
A passed audit is not a passed hacking attempt.
Checkbox mentality crowds out real risk awareness
Teams focus on ticking off the auditor's list instead of analyzing real, novel threats such as AI-driven phishing or zero-day exploits. A company fulfills the requirement of "annual security awareness training" — and the CFO still falls for a deepfake voice call impersonating the CEO, because the static checkbox training never covered modern AI spear-phishing scenarios.
Compliance asks: "Do we have the policy?" Security asks: "Does the protection actually work if we're attacked today?"
The 3 most dangerous myths of compliance
- Hackers don't read certificates
- They exploit misconfigurations, open doors, and unverified people
- A seal doesn't change anything about a propped-open fire door
- One employee holding open a fire door can undo €100,000 of IT infrastructure
- One click on the wrong link does exactly the same
- Security is everyone's job — not just one team's
- Attackers audit you every day — automated and without warning
- Configurations and threat landscapes change daily
- A once-a-year snapshot says nothing about week 30
The path to real security
Certifications remain a sensible starting point — but only if four principles shape the day-to-day reality beyond the audit:
- Adopt an assumed-breach mentality: assume attackers are already on the network or the door is already open. Test response time, not just prevention.
- Red teaming & blue teaming instead of scheduled audits: have red teams — physical and digital — attack unannounced. Follow up together with the blue team in a blameless after-action review.
- Pragmatic policies instead of 100-page PDFs: policies need to work in daily practice. If a door constantly stands open, the problem isn't the employee — it's a broken process, such as poor ventilation in the hallway.
- Foster a no-blame culture: an employee who let the man in overalls through, or clicked a bad link, needs to be able to report it immediately without fear of consequences.
Conclusion: certificate on the wall, door propped open next to it
The most important point first: certifications are far from pointless. They provide a necessary foundation, shorten sales cycles, and force organizations to actually document their processes in the first place. The problem doesn't start with certification — it starts with assuming the work is done once you have it.
Just because something exists on paper doesn't mean it's actually true in practice. "The door exists" is different from "the door is permanently propped open." "We have a SIEM/SOC" is different from "it basically never responds in real-world tests."
This isn't a contradiction between ISO and pentests, where one method makes the other redundant. ISO 27001 and a physical pentest simply answer different questions. The problem only arises when a CISO asks the first question — and treats it as if it answered the second one too.
- Use certificates as a door-opener in sales — but don't rely on them alone.
- Invest in security culture: empower employees to report mistakes without fear — not just in policy documents.
- Test your security realistically through regular red teaming / pentests and hands-on security awareness training.
- Audit vs. Physical Pentest – Why compliance certificates fail against real attacks
- Red Team Pentest Purple Team – What the difference is – and when you need which
- NIS2, Kritis, Physical Security Compliance – What operators of critical infrastructure actually need to implement
Is your certificate just hanging on the wall while the fire door next to it stays propped open?
We help companies stop just ticking off compliance and start building real, lived security instead.
Request an Initial Consultation →