ISO 27001 for international software companies: A case study

Date

17 August 2026

Author

Share

Fast-growing software companies move quickly. 

New teams. New clients. New cloud environments. New markets. 

But while the business scales, security often can grow in pieces. 

That was the reality for an international software development company with more than 620 employees operating across Belgium, Germany, Poland, the United States, and India. 

Different offices followed different security practices. Cloud environments expanded rapidly. Development teams shipped fast, but security controls were not always consistent across the organization. 

At the same time, enterprise clients increasingly required ISO 27001 certification before signing contracts, while regulations like GDPR, NIS2, and the Indian DPDP Act added even more pressure. 

The company didn’t have a lack of talent or technology. 

It had a lack of structure. 

What followed was a complete transformation of how security was managed across the business, from governance and cloud security to secure software development and international compliance. 

This case study explores how the company unified security across five countries and successfully achieved ISO 27001:2022 certification. 

Where it started: rapid growth without consistency 

Like many fast-scaling technology companies, each office had gradually developed its own way of working. 

Some teams had mature security practices. Others relied heavily on informal processes. 

The initial assessment revealed several critical challenges: 

Inconsistent security practices across locations 

The Belgian headquarters maintained formal change management processes, while other offices operated with varying levels of structure. 

The Indian development center relied largely on informal peer review. The US office selectively applied SOC 2 principles, while Germany and Poland lacked a documented security framework entirely. 

Gaps in the Secure Development Lifecycle (SDLC) 

Although development teams used agile methodologies and CI/CD pipelines, security was not formally embedded into the software development lifecycle. 

There were: 

  • No mandatory secure coding standards 
  • No structured vulnerability management process 
  • No required security testing gates 
  • Limited security validation before deployments 

Cloud sprawl and excessive privileges 

The organization used both AWS and Azure environments spread across multiple accounts and subscriptions. 

The assessment identified: 

  • 23% of cloud accounts with excessive permissions 
  • 11 instances of hardcoded credentials stored inside repositories 
  • inconsistent cloud monitoring and hardening practices 

International data transfer risks 

Because customer data was processed by teams in India, GDPR-compliant transfer mechanisms were required. 

Existing Standard Contractual Clauses had not been supplemented with Transfer Impact Assessments following Schrems II requirements, creating legal and compliance exposure. 

Client audit fatigue 

The absence of a recognized certification created a significant operational burden. 

The company responded to approximately: 

  • 14 security questionnaires per year 
  • 6 client audits annually 

This consumed large amounts of leadership, legal, and engineering time. 

The organization needed more than isolated fixes. 

It needed a unified security structure that could scale globally. 

Our approach: centralized governance with localized execution 

Rather than forcing a one-size-fits-all model across five countries, a centralized ISMS was designed with localized execution. 

The goal was clear: 
Create consistent governance while respecting operational and regulatory differences across jurisdictions. 

Phase 1 –  Multi-site discovery and gap analysis (Weeks 1–8) 

A complete assessment was performed across all five countries through a combination of on-site workshops and remote interviews involving: 

  • Developers 
  • DevOps engineers 
  • Project managers 
  • Country managers 
  • Executive leadership 

The existing environment was mapped against ISO 27001:2022 Annex A controls and applicable privacy regulations. 

The assessment identified: 

  • 167 total gaps 
  • 89 core ISO 27001 control gaps 
  • 41 governance and measurement gaps 
  • 37 detection and response weaknesses 

For the first time, leadership had a complete and consolidated view of organizational security maturity. 

Phase 2 – ISMS architecture and governance (Weeks 6–16) 

A hub-and-spoke governance model was introduced. 

The Belgian headquarters managed: 

  • policies 
  • risk methodology 
  • management reviews 
  • Statement of Applicability 
  • centralized governance 

At the same time, local ISMS representatives were assigned in each country to ensure operational alignment. 

To simplify global operations, a tiered documentation structure was developed: 

Level 1 – Global policies 

28 company-wide policies applied consistently across all locations. 

Level 2  Regional requirements 

Country-specific supplements addressed: 

  • GDPR obligations 
  • US privacy laws 
  • Indian DPDP requirements 

Level 3 – Operational procedures 

Team-specific work instructions aligned security requirements with day-to-day workflows. 

A Global Security Steering Committee was also established, creating regular collaboration between all regions. 

Phase 3 – Secure development lifecycle integration (Weeks 10–24) 

One of the most important transformations involved integrating security directly into the software development process. 

Instead of treating security as a separate control function, it became part of the developer workflow itself. 

A formal Secure SDLC framework was implemented, including: 

  • Threat modeling during sprint planning 
  • SAST integrated into CI/CD pipelines 
  • Automatic blocking of deployments with critical findings 
  • Software Composition Analysis (SCA) for open-source dependencies 
  • DAST testing in staging environments 
  • Mandatory peer security code reviews 

At the same time, a centralized vulnerability management platform was deployed to aggregate findings from all scanning tools and enforce SLA-driven remediation timelines. 

This significantly improved visibility and accountability across engineering teams. 

Phase 4 – Cloud security and data transfer controls (Weeks 14–26) 

A full cloud security posture assessment was conducted across AWS and Azure environments. 

The remediation program addressed: 

  • 156 cloud misconfigurations 
  • 23 over-privileged IAM roles 
  • all 11 hardcoded credentials found in repositories 

To maintain long-term visibility, Cloud Security Posture Management (CSPM) tooling was introduced with continuous compliance monitoring against CIS Benchmarks. 

At the regulatory level, compliant international data transfer mechanisms were implemented through: 

  • updated Standard Contractual Clauses 
  • Transfer Impact Assessments 
  • supplementary encryption and pseudonymization controls 
  • stricter access restrictions 

This ensured that security improvements aligned not only with ISO 27001, but also with evolving international privacy obligations. 

Phase 5 – Internal audits and certification (Weeks 28–38) 

Internal audits were performed across all five countries through a combination of on-site and remote assessments. 

A centralized evidence package was created, reducing certification preparation efforts by approximately 50%. 

The organization successfully achieved ISO 27001:2022 certification with a multi-site scope covering all international operations under a single certification body. 

The result: measurable security and business improvements 

The transformation produced both operational and commercial impact. 

Security improvements 

  • Secure SDLC coverage increased from ad hoc adoption to 100% of projects 
  • Critical and high vulnerabilities in production dropped from approximately 18 per quarter to fewer than 3 
  • Cloud misconfigurations decreased from 156 identified issues to fewer than 10 under continuous monitoring 
  • Hardcoded credentials in repositories were completely eliminated 

Operational improvements 

  • Client questionnaire response times decreased from 3–4 weeks to 2–3 days 
  • Bespoke client audit preparation reduced from 6 audits annually to just 1 
  • The ISO 27001 certification was accepted by 89% of clients in place of separate assessments 

Commercial impact 

Most importantly, the certification directly enabled three enterprise contracts that had previously been blocked due to the absence of ISO 27001 certification. 

One of these included a major German financial services client worth €1.2 million annually. 

What made the difference 

Several factors played a critical role in the success of the transformation: 

Centralized governance with local ownership 

The hub-and-spoke model ensured consistency without ignoring cultural and operational differences between regions. 

Developer-focused security integration 

By embedding security directly into CI/CD pipelines and agile workflows, adoption became part of normal development operations rather than an external burden. 

Business-driven security strategy 

Leadership was able to clearly measure the commercial value of certification by tracking previously blocked sales opportunities and reduced audit overhead. 

How Dadir can support your organization 

Many growing technology companies face similar challenges: 
rapid expansion, distributed teams, increasing regulatory pressure, and inconsistent security practices across locations. 

Dadir helps organizations establish structured, scalable, and internationally aligned cybersecurity programs that support both operational resilience and business growth. 

We support organizations with: 

  • ISO 27001 implementation and certification 
  • Secure SDLC integration 
  • Cloud security governance 
  • GDPR and international data transfer compliance 
  • Multi-site ISMS governance 
  • Risk management and operational security maturity 

Because for international software companies, security is no longer only a technical requirement. 

It has become a business requirement. 

 

WHO IS THE DADIR TEAM?

Read our other blogs