Information security: Why many ISMS fail to reach their full potential

Portrait Burkhard Wolkewitz

From

Burkhard Wolkewitz

Posted on

2.7.2026

Information security is on the agenda for many medium-sized companies due to ISO 27001 or NIS2. And external pressure is growing: customers want to know if their data is protected, insurance companies require proof, and management realizes that this topic can no longer be delegated. But even though the importance of information security is rarely questioned today, it often remains unclear what role it should actually play within the company.

Anyone who honestly asks themselves, "What is the state of information security in my company?" often encounters the same challenge. The topic sits with the IT department and stays there. As soon as the next audit is due, it is dragged out for everyone again.  

The crux of the matter is not whether a company has an ISMS (Information Security Management System), but how information security is understood, organized, and practiced. Ultimately, that determines the real impact an ISMS can have.  

What role does the ISMS play in the company?  

In practice, there are many variations: small companies organize information security differently than large ones, and manufacturing companies have different priorities than service providers. The role of the information security officer also depends heavily on the maturity level, history, and corporate culture. Nevertheless, many approaches can be broken down into three basic models:

Document Managers: Information security as a compliance obligation

Here, information security is primarily understood as a necessary duty. The ISMS exists to get certificates on the wall, prepare for audits, and maintain policies for the next inspection. The system exists, but it doesn't live.  

A typical sign of this is that information security exists separately from daily work. Policies are maintained because an audit is coming up, and risk analyses are created only because a standard requires it. Employees, and especially managers, often see information security as an annoying extra task rather than a necessity or a safeguard for their daily work.  

The result: The potential of an ISMS remains untapped. Because if information security only becomes visible shortly before an audit, its impact ends as soon as the audit conversation is over.  

IT Security Guardians: Information security as a technical control function  

Here, those involved have understood that an ISMS offers advantages for the company that go beyond mere compliance. The realization that information security serves not just for documentation, but for protection, is a real step forward!

However, problems arise when information security is held directly responsible for the security of the entire organization – and this responsibility lands solely with the IT department. After all, IT managers do not carry out most business processes themselves. Nevertheless, they are expected to assess risks that arise in departments where they have no direct insight.  

This leads to unrealistic expectations: the IT department becomes overwhelmed, the departments feel controlled, and the desired impact fails to materialize. Instead of working together on secure processes, a divide emerges between IT managers and the rest of the staff. Yet even ISO 27001 establishes as a core requirement that the sole responsibility for implementing an ISMS must not be transferred entirely to IT.

Security Drivers: Information security as a business lever

In this model, information security management is understood as what it is: a management system that enables the organization to deal with information risks consciously. While the ISMS alone does not create security, it acts as the most important tool that makes security in the company possible in the first place. In this model, the responsibility for secure processes remains where they are carried out: in the departments. The role of the ISMS is to provide orientation, supply methods, create transparency, and enable improvements. The most important metric is then not "audit passed," but "security posture improved."

How do you find the right management system?

When a company views information security as a driving force for greater security, the next question immediately arises: Which management system best supports this role?  

Management systems can be interpreted in very different ways. Some are merely collections of documents, while others are ambitious integration projects. Ideally, a management system should encompass the sum of all the rules a company follows when handling information. Here, too, we distinguish between three typical approaches:

The silo world: A separate system for every standard

The initial impulse in many companies to house information security in its own dedicated system is understandable. After all, quality management, data protection, risk management, and compliance all have their own structures, documents, and responsibilities.

While this may look neat and clearly defined at first glance, in practice it leads to the creation of information silos. The same processes are viewed from different angles without the insights ever converging. This weakens not only the effectiveness of the ISMS but also that of all other management systems. To truly understand the connections, you need the big picture, not just fragments.  

The parallel world: Integration only on paper  

To avoid scattered data silos, you need an integrated system. Quality management and information security management often look at the same workflows from different perspectives. ISO 9001 asks: How well does this process work? While ISO 27001 wants to know: How secure is the information within this process?

However, many integrated systems stop halfway. They bring technical topics together into one system but still form a parallel world to the organization. The structure follows an artificially created order rather than the lived reality. As a result, the documentation is integrated but ineffective. Employees cannot relate to it, and managers do not use it for steering the business.  

The real world: The management system as the sum of all rules  

An effective management system does not start with standards—it starts with the reality of the company. The foundation for this is formed by processes as central hubs where information is created, processed, shared, and stored. This is why processes are the ideal anchor for an ISMS.  

When processes are at the center, different perspectives can be meaningfully connected. A process description then shows:

  • how work is done,
  • which information requires protection,
  • what risks exist,  
  • who is responsible,  
  • and what evidence is generated.  

In this way, many individual facets combine to form a holistic picture. And this is exactly where impact is created: employees use the management system because it helps them in their daily work, and managers use it because it provides guidance. This is how information security fulfills its intended purpose as a central contribution to the company's stability.  

The most important takeaway for your company  

Companies do not need to reinvent information security. But they must decide what impact they hope to achieve. This only happens when the ISMS enables the company to deal with information risks systematically—along the actual processes that people use to do their jobs.  

Real impact is seen in everyday life—not in an audit. It happens when employees know which information in their process needs protection and when managers identify risks before they become incidents. If an organization is well-prepared for an emergency, even a cyberattack does not have to lead to a total shutdown.

What this requires is a new approach to information security management: empowerment instead of parallel documentation and IT control. Only with this understanding can an ISMS fulfill its purpose as the living set of rules by which a company handles its information.  

Where to start? Your next steps  

The first step is an honest look at where your company currently stands. Ask yourself the following questions:

  • Who has access to your management system?  
  • Only the information security officers and the IT department?  
  • Or do sales, development, production, and purchasing also use it—because they find guidance for their daily work there?  

Looking to the future is just as important. Think about what role you want information security to play for you in the future. Do you view it...

  • as a function that secures certificates?  
  • as a technical control authority?  
  • or as a driver that supports the company in systematically managing information risks?  

Once you have found the answers to these questions, you are ready for the next step.

No items found.

Your question to Carsten

Sign in to get in touch with Carsten directly.

Don't miss any more new posts!

Always stay up to date: In our newsletter, we provide you with a fresh update on the Modell Aachen Insights every month.

Desktop and mobile illustration

Similar posts

See all posts