ISO 27001: Simply Not Optional.

A practical guide for marketing agencies
Last update: January 2025
ISO 27001 is not just an abstract security standard. It is a concrete tool. With it, you can increase your customers' trust. At the same time, you protect your marketing agency from data breaches. In this article, you will get a clear overview of the standard's requirements. The article describes the process from initial assessment to the final certification audit. We will show you a fictional example. A marketing agency called SpotOn Media tackles these steps in practice. They implement them successfully.
What is ISO 27001?
ISO/IEC 27001 is the core of the ISO/IEC 27000 family of standards, which revolves around information security. Essentially, it's about introducing and continuously improving an Information Security Management System (ISMS). Specifically, this means: You establish processes, policies, and technical measures. These measures provide the best possible protection for your data, customer data, and all IT systems.
Why is this relevant for marketing agencies?
- Increased customer trust: Clients want to be sure that their sensitive data (e.g., campaign data, budget plans) is handled confidentially.
- Process optimization: Structured workflows and clear responsibilities bring more efficiency to your daily processes.
- Legal protection: You can better protect yourself against data loss and demonstrate that you are well-positioned in terms of compliance (e.g., GDPR).
Core Elements of the Standard
ISO 27001:2022 is divided into seven main chapters that cover the entire lifecycle of an ISMS:
- Context of the organization (Chapter 4)
- Here you clarify which external and internal factors affect your agency (e.g., legal frameworks, competitive situation).
- Leadership (Chapter 5)
- Management establishes guidelines to ensure that security is "top priority."
- Planning (Chapter 6)
- You define objectives, risks, and measures that directly impact your ISMS strategy.
- Support (Chapter 7)
- Resources, roles and responsibilities, as well as competencies and communication channels are defined.
- Operation (Chapter 8)
- This covers the practical implementation and ongoing operation of your ISMS, e.g., conducting risk treatment or security awareness training.
- Performance evaluation (Chapter 9)
- Internal audits, management reviews, and key figures: You check whether everything is working as planned.
- Improvement (Chapter 10)
- Continuous learning and adaptation: You take corrective and preventive actions when vulnerabilities arise.
In Annex A, you will find reference controls in four areas (organizational, human resource, physical, technological). They help you select and adapt the appropriate controls for your agency.
Example: SpotOn Media tackles ISO 27001
Let's say the fictional agency SpotOn Media has a large customer base and manages sensitive data for advertising campaigns. The management has decided to raise their processes to a new level of security with ISO 27001. How do they proceed specifically?
- Preparation
- Management assembles an internal project team consisting of IT management, HR representatives, and a project manager.
- Together, they define which departments and locations will be included in the ISMS (e.g., only the German headquarters or also international branches).
- As-Is Analysis
- At SpotOn Media, an inventory is taken: What sensitive data exists? Where is it stored? What software is used?
- The first risks are quickly identified: unencrypted laptops in the field, missing emergency plans, and inconsistent password policies.
- Documentation and Planning
- The agency creates central documents such as the Information Security Policy and procedural instructions for handling customer data.
- A risk management process is introduced, which defines which risks are still tolerable and which must be urgently addressed.
- Implementation
- SpotOn Media employees are trained on how to recognize phishing emails and how to manage passwords securely.
- At the recommendation of the project team, the agency invests in Multi-Factor Authentication (MFA). They segment the internal network. This way, an attack cannot paralyze the entire company.
- Emergency plans (Incident Response Plans) are created so that in an emergency, it is clear who needs to be informed and how to quickly resume operations.
- Review and Certification
- After a few months, SpotOn Media conducts an internal audit and corrects any remaining weaknesses (e.g., missing encryption for mobile devices).
- An external audit by an accredited certification body is scheduled. The team is well prepared: The documentation is complete, all employees know their roles.
- Ongoing Improvement
- After successful certification, SpotOn Media decides to review and further develop the ISMS every year. This way, they remain technologically and organizationally up-to-date.
The path to certification for marketing agencies
As the example of SpotOn Media shows, a planned, structured approach pays off. The following phases have proven successful in practice:
Phase 1: Preparation and Analysis
- Documentation of existing security measures
- Identification of information assets
- Risk assessment and definition of the project scope
Phase 2: ISMS Setup
- Create Information Security Policy
- Define procedures and work instructions
- Risk Management (assessment criteria, acceptance criteria)
Phase 3: Implementation
- Technical and organizational measures (e.g., firewall, MFA, training)
- Testing emergency processes
- Training employees
Phase 4: Internal Audit & Certification
- Conduct internal audit
- Management review
- Certification audit by an accredited body
Practical Implementation for Marketing Agencies
In the marketing environment, the following points are particularly important:
- Customer Data Handling
- Sensitive customer data (e.g., campaign budgets, targeting information) must be encrypted and have clear access rights.
- Regular review of whether data is still needed (deletion concepts).
- Secure Project Workflows
- Consider security requirements already during campaign planning (Privacy by Design).
- Clear role distribution in every project: Who is allowed to edit data? Who is only allowed to view it?
- Basic Technical Security
- A professional firewall and endpoint protection are mandatory.
- VPN access and encrypted communication (TLS 1.3) for remote work are essential.
- Organizational Aspects
- Personnel management: Clear guidelines on confidentiality and security checks for new hires.
- Document management: Classification guidelines and clear version control to minimize errors or ambiguities.

Costs and Effort
- One-time costs
- Consulting services and, if applicable, external project managers for ISMS setup.
- Training on topics such as phishing detection or risk management.
- Procurement or expansion in the IT area (e.g., firewalls, encryption solutions).
- Costs for the certification audit itself.
- Ongoing Costs
- Effort for regular surveillance audits (usually annually).
- Maintenance and updating of technical systems.
- Further training and education for employees.
SpotOn Media, for example, invested around four months in structuring its processes and closing technical gaps. In the end, all project participants were surprised at how much they benefited not only in terms of security but also organizationally.
Success Factors
- Management Commitment
- The management must stand behind the project. This creates acceptance and ensures that budget and resources are available.
- Employee Involvement
- Early and transparent communication promotes motivation: Every employee understands why security is important for the company.
- Ongoing training keeps awareness high and ensures sustainable changes in daily work.
- Pragmatic Approach
- Focus on the most important risks first, rather than trying to tackle all potential eventualities at the same time.
- Plan progress in stages so that the team is not overwhelmed and successes remain visible.
Further Resources
- Official ISO Website for ISO/IEC 27001
- BSI IT-Grundschutz and ISO 27001
- German Accreditation Body (DAkkS)
This guide is based on the official ISO/IEC 27001:2022 and best practices from the field. For certification, one should work with accredited consulting companies. It is also advisable to involve certification bodies. SpotOn Media did this to successfully complete the project.

Mario Lohe
General Manager with 15+ years of experience in business operations, agile transformation, and AI enablement. Former Director of Operations at Havas Creative Group, Head of Operations at Audiencly. Certified: CSPO, CSM, ISO 31000, Systemic Coach (DCA).
Verwandte Artikel

The Ecological Footprint of AI: Challenges and Solutions
The rapid development of artificial intelligence (AI) brings with it enormous potential as well as significant ecological challenges. AI technologies are fundamentally reshaping our daily lives and business...

Automation: Balancing Relief and Control
Automation is becoming increasingly important for accelerating processes and drastically improving efficiency in companies. But what if these automations arise without formal approval...

Is Our Digital Life Still Safe? Strategies Against Data Theft
In an increasingly digitized world, data theft poses a serious threat. When personal data such as names, addresses, bank information, or access data falls into the wrong hands...

