top of page

SME controls - a new ISO27k standard?

10 minutes ago
7 min read

I'm currently working on a proposed new ISO27k information security standard for SMEs - Small to Mid-sized Enterprises with up to about 250 people. ISO/IEC 27001 makes business sense for organisations towards the upper end of the range and beyond, but what about those tiddlers buried at the bottom of the heap?



SMEs are like krill, thumb-sized prawn-like sea creatures weighing just a gram or so ... yet a single blue whale scoops-up something like 20 tons (millions) of the tasty little morsels every day. Yum yum. The krill themselves consume an unknown number of microscopic single-cell phytoplankton, without which both they and the bluies would go hungry.


All ecosystems work on the same basis: food chains. In the business world, we call them supply chains. The entire edifice is critically dependent on the tiniest ones at the base, lots of them. LOTS and LOTS. It is estimated that more than 95% of all businesses are SMEs. Some say 99%.


Micro-businesses ('solopreneurs') and small family businesses with at most a handful of people are lucky to have anyone 'in IT', let alone information risk and security specialists. They are so busy doing whatever they do best and trying to stay afloat that everything else is a distraction, often struggling with essentials such as tax accounting and other compliance obligations.


Safety looks a bit different for a business running on a knife edge.


Risk is a way of life. Security, a luxury.


In decades past, cybersecurity barely even entered the picture for many SMEs - maybe some sort of antivirus, the occasional backup and (in a good year) a new app on floppy disk or a thrift-shop PC. Not much point securing the office when it's a corner of the kitchen or a grubby second-hand desk at the back of the store.


Then along came the Interwebs, and suddenly the whole world opened up before them ... and for everyone else. Rather than simply competing with Jane's Emporium along the way or a mail-order company in a nearby city, SMEs face the daunting challenge of appealing to, and surving in, a cut-throat global market.


And lately things have got nasty, really nasty on the Internet. Aside from global competitors, today we face scammers, fraudsters, hackers, ransomware gangs, criminals and spooks - well resourced and determined adversaries, increasingly AI-enabled.


Its so unfair!!


For the krill, there's safety in numbers ... until a pod of ravenous whales sweeps through and that's that. No safety now, just the luck of the draw. For an individual krill, the whales are an existential threat, one of many. For the whales, climate change is existential because it threatens the phytoplankton. Either way, there's really not much they can do. The chain is hanging by a thread.


SMEs do at least have the advantage of being able to recognise and respond to the threats ... but how? It's a scary world out there. Which way should they swim? How fast? Where to start? What next? How much will it cost? Will it save more than it costs?


For an SME stakeholder looking for advice, searching the interwebs for "SME security guidance" is free and easy but it would take hours just to browse the first few pages of websites, and there are dozens of pages, hundreds maybe. Go ahead, take a quick look for yourself. Most are well-meaning, genuine, even good, but the sheer volume and variety of advice is mind-boggling and the technical language often disappointingly obscure, littered with jargon.


ISO/IEC JTC 1/SC 27/WG 1 has started work on an information security standard specifically for SMEs, hoping to make sense of all that jazz with (hopefully) a rational, straightforward, good practice approach in plain English. My aim, for what it's worth, is to help the committee set off on the right foot with a first draft that has a suitable structure, a sound approach, and hopefully a sensible set of SME-oriented infosec controls to set it rolling. At least that's my plan. Hopefully I'll get the chance to propose and explain it at the WG1 virtual meeting tomorrow morning (2am NZ time! Wish me luck!).


As an infosec consultant, I've worked with/for hundreds of SMEs so far this millennium, written a number of SME security guidelines and developed an appreciation for the challenges in this area ... but standardisation is tough given the variety of SMEs Out There, the sheer number of information, compliance, safety and [other] business risks they face, dynamics, and the technical complexities just beneath the surface.


I've also worked for a few whales and they too are finding things tougher than ever.


So, I set out by researching, comparing and contrasting a bunch of published SME guidelines to draw out the security controls they recommend. That turned out to be more complicated than I expected because they don't even agree on the meanings of 'cybersecurity', 'control' or indeed 'SME'.


For the micro-SMEs (the phytoplankton), the advice typically collapses to crude checklists with a handful of controls - often 8 for some reason. Every one has a different list of ~8, some markedly so. And few if any make a genuine attempt to explain and justify the controls in business terms.


Some of the SME guidance seems to be aimed at IT professionals, implying SMEs large enough to have an actual IT team/function, or at least someone who sports the IT hat most days (the krill). The language here is mostly technical, jargon-infested, and the controls are almost entirely technological, so presumably it has been written by IT pro's who don't get out much. Security controls for OT (Operational Technology) and other types of tech are vanishingly rare, callously disregarding relevant concerns of another chunk of the intended SME audience.


Over-use of 'cyber' is an annoyance, at least for me. Not only is the term vague and undefined, it clearly skews the guidance towards IT, digital data, the Internet, that sort of thing to the point that other forms of information, risk and security are conspicuously absent. Hold that thought ...


One SME guideline - ironically enough, apparently written for ISO by an unnamed author from SC 27 according to the cover - seems unlikely to be of much value except to the whales. "This handbook focuses on guiding SMEs in developing and implementing an information security management system (ISMS) in accordance with ISO/IEC 27001, in order to help protect yourselves from cyber-risks." Try explaining the concept of a formal, certifiable ISMS to a micro-SME, let alone persuading them down that route! BTDT It's a tough sell even for SMEs at the top end of the [unstated] range. Yes, I know 27001 formally applies to all types and sizes of organisation, and that some small, very small, even tiny SMEs have been certified, so the guideline beats the standard's drum: explore your cyber-risks, evaluate and treat them. Rinse. Wash. Repeat. Unlike most other SME security guides, it studiously avoids recommending specific controls other than those specified as requirements in the standard's main body e.g. "an ISMS policy".


OK, enough cynical criticism from me, let's move on.


My analysis of published guidance on infosec and cybersec controls recommended for SMEs identified about 24 controls - well, actually, dozens of them if you were to pick out all the individual items but by grouping closely related controls together I settled on 'just' two dozen, for now. Here's the list:


The order of the controls reflects their popularity in the guidelines I surveyed, so controls relating to computer accounts (such as user authentication and access controls) are the most common, while [software] development controls were by far the least popular - no surprise really given that some whales no longer develop software as they once did (he said, pointedly ignoring shadow IT and shadow AI).


For some SME controls, I've consciously and deliberately broadened the scope beyond the usual cyber realm, for example:

  • SME6 concerns social and business networks as well as digital data networks ... because there are relevant information risks and security controls in those too.

  • Development security is so rarely noted in SME guidance that it would not have made it onto the list at SME24 had it not presented the opportunity to mention other forms of development besides software e.g. product, market, workforce and business development: again there are information risk and security aspects worth considering.

  • SME10, the physical security control, brings up safety. I have in mind ensuring safe working conditions for SME workers and SMEs designing and producing safe products (goods and services). At a still broader level, SMEs in some supply chains play their parts in critical infrastructure and national security, with obvious safety implications. Seems to me safety is a neglected part of information security or cybersecurity, at least in terms of the ISO27k standards.


  • On much the same theme, the idea of treating workers or people as information assets pops up in several controls because, well, we are, aren't we? We don't just earn our salaries/fees by providing muscle power. Our grey matter, proprietary knowledge, creative ideas, insight, decision-making capabilities and opinions make us difficult if not impossible to replace, even with the latest shiniest generation of cyborgs. We suffer distraction, fatigue, exhaustion, dysregulation, burnout and other mental health challenges, bias and prejudice, social engineering and plain old human error - in other words, yet more information risks. In my experience, phytoplankton and krill SMEs are way better at spotting and responding appropriately to trouble in the human domain than the whales, but nevertheless I feel SME guidance is worthwhile. Maybe the whales have something to learn here too!


Right, well, if you're still with me, here's the bottom line: download the draft SME Controls document (also included in the free ISO27k Toolkit). Feedback welcomed, encouraged, nay demanded. What have I neglected, misrepresented or garbled? Which SME-relevant risks and controls have I missed? What would you drop from the list or recombine? Please get back to me soon as the window for contributing to the ISO27k standard is shrinking faster than our glorious leaders' popularity ...

 
 

​

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page