ISO 27001 in Africa: Your Clients Are Starting to Ask — Here’s What You Need to Know

INVESTOR SOLUTIONS LIMITED - ISO Certification - ISO 27001 in Africa: Your Clients Are Starting to Ask — Here’s What You Need to Know
ISO 27001

A logistics company in Nairobi lost three weeks of operational data to a phishing attack last year. One employee. One email. No backup policy and no incident response plan in place. The business recovered, but it took time and money they hadn’t budgeted for.

Stories like this used to be rare in the East African business conversation. They’re not anymore.

As more African businesses move their operations online, handle customer data through cloud platforms, and deal with increasingly sophisticated clients, the question of information security is shifting. It’s no longer just a technology conversation. It’s a commercial one. And ISO 27001 is the standard that sits at the centre of it.

Why this is coming up in procurement conversations now

Three things are driving it. Kenya’s Data Protection Act came into force in 2019, and the Office of the Data Protection Commissioner has been issuing compliance notices with increasing frequency since 2023. Organisations handling personal data – employee records, customer data, financial information – are expected to show they have real safeguards in place, not just a privacy policy PDF.

The second pressure point is client-side procurement. If you provide services to banks, telecoms, multinationals, or international development organisations, you’ll start seeing ISO 27001 listed as a vendor requirement in RFPs. Some clients ask about it during due diligence. Others have started making it a condition of contract renewal.

Third is the threat environment itself. The African Development Bank‘s digital economy reporting puts cybercrime losses in sub-Saharan Africa above USD 4 billion annually. SMEs take a disproportionate share of that because they’re easier targets than large corporates. And the attacks are getting less sophisticated, not more — which means more businesses are at risk, not fewer.

What ISO 27001 actually involves

The ISO/IEC 27001 standard is not a technology checklist. It’s a management system for information security. The difference matters. Technology tools — firewalls, antivirus, access controls — are part of the picture, but ISO 27001 is concerned with whether there’s a structured, documented approach governing how information risk is identified, assessed, and managed.

What that means practically:

•      You define the scope of what you’re protecting and why

•      You assess the risks — what could go wrong, how likely is it, what’s the impact if it does

•      You implement controls that are proportionate to those risks

•      You run internal audits and management reviews to check that the system is working

•      You act on findings and improve over time

The 2022 version of the standard covers 93 security controls across areas including access management, incident response, cryptography, supplier relationships, and physical security. You don’t implement all of them — you document which ones apply to your context and your justification for excluding any that don’t.

Who in Africa genuinely needs this right now

Not every business is under the same level of pressure, but the following are consistently seeing ISO 27001 come up as a requirement or a strong expectation:

•      ICT firms and software developers working with enterprise clients or government

•      Fintech and financial services businesses handling transactions or account data

•      Healthcare providers managing patient records digitally

•      Businesses that already hold ISO 9001 certification and are looking to strengthen their overall management system

•      Any organisation handling personal data under Kenya’s Data Protection Act or equivalent legislation in their market

How it works alongside other ISO standards

If your organisation already has ISO 9001 or is working toward it, adding ISO 27001 is more straightforward than starting from scratch. The standards share the same high-level structure — the same approach to risk, the same requirements for management review and internal audit, the same document control framework. You don’t rebuild; you extend what you already have.

The same applies to ISO 22301 for business continuity. The three together form a coherent integrated management system, with one audit cycle covering all three. Our management systems consulting team regularly structures these combinations, and it’s typically more cost-effective than running separate implementations.

If your business is an IT service provider, it’s also worth looking at ISO/IEC 20000-1:2018 for IT service management alongside ISO 27001 — the two address complementary risks in the IT space.

The misconceptions worth addressing

‘We’re too small for this to matter.’

Small businesses get targeted more than large ones, not less. Attackers go where controls are weakest. If you handle customer data or financial information, the risk is real regardless of headcount.

‘We already have good IT security.’

ISO 27001 and good IT security tools are not the same thing. The standard is about governance — documented policies, clear accountability, a process for handling incidents. Organisations fail ISO 27001 audits not because their technology is poor but because there’s nothing written down to show how decisions are made and who is responsible.

‘We don’t have time for a long project.’

With structured ISO certification preparation support, most organisations get to certification within six to nine months. The timeline is driven by how consistently the internal team engages with the project, not by the standard’s complexity.

Frequently asked questions

Does ISO 27001 satisfy the requirements of Kenya’s Data Protection Act?

ISO 27001 is widely accepted as evidence of compliance with the requirement to implement appropriate technical and organisational security measures. It doesn’t replace registration with the ODPC where required, but it demonstrates that the security obligations are being taken seriously.

What’s the difference between ISO 27001 and SOC 2?

SOC 2 is a US-originated auditing framework used mainly in North American markets. ISO 27001 is an international standard with recognition across Europe, Asia, and Africa. For African businesses working with international clients across multiple markets, ISO 27001 has broader practical utility.

What does certification cost?

Consulting and implementation typically run USD 3,000 to USD 12,000, depending on scope and how much of a foundation already exists. Certification body fees for the initial audit cycle are usually USD 1,500 to USD 4,000. Annual surveillance audits after that are lower.

Getting started

An information security risk assessment is where most organisations begin. It maps your current state, identifies gaps, and tells you what the implementation project will actually involve. ISL Global’s ISO 27001 information security management consulting covers the full process. Our capacity-building programme also works with your internal team, so they own the system after we leave. For background on the standard itself, the ISO.org page on ISO/IEC 27001 is the authoritative reference.

Leave a Reply

Your email address will not be published. Required fields are marked *