Case study — Cobalt Systems

Securing a fast-scaling SaaS company with ISO 27001

Securing a fast-scaling SaaS company with ISO 27001

Building customer trust and unlocking enterprise deals with certified information security — turning what had been a persistent and costly sales blocker into a genuine, repeatable selling point.

Background

Cobalt Systems is a fast-growing software-as-a-service company with a strong product and an ambitious, capable team. As it matured, its customer base changed fundamentally, and with it, the rules of the game. Instead of selling to small teams who signed up with a credit card and asked few questions, Cobalt was now pursuing large enterprises — organisations with serious security requirements, formal procurement processes, dedicated risk teams, and a very low tolerance for uncertainty. The product was more than good enough to win this business, but the sales motion had quietly run into an invisible wall that no amount of product excellence alone could break through.

The challenge

Every enterprise opportunity now arrived accompanied by a long, detailed and often intimidating security questionnaire, and each one slowed the deal to a crawl. Prospects wanted concrete, credible assurance about how their data was stored, who could access it, how it was backed up, how incidents were handled and how it was protected against a growing catalogue of threats — and they wanted all of this established convincingly before they would sign anything at all. Cobalt found itself answering the same demanding questions again and again, from scratch, burning valuable engineering time that should have gone into the product, and steadily losing momentum in deals that ought to have closed cleanly. Security had, in effect, become the single biggest bottleneck in the entire business.

Worse, answering questionnaires ad hoc did not really build trust; it merely responded to it question by question. Sophisticated buyers could sense the difference between a company that had genuinely organised its security and one that was assembling reassuring answers on demand.

Our approach

We guided Cobalt through ISO 27001 certification, holding firmly to one principle throughout the entire engagement: build a genuine information-security management system, not a hollow box-ticking exercise that would crumble the first time an experienced enterprise buyer looked closely. A certificate that did not reflect reality would have been worse than useless, because it would have invited scrutiny it could not survive.

  • A risk assessment grounded firmly in how the business actually operates, rather than a generic template downloaded and lightly edited.
  • Controls deliberately designed to fit and complement a fast-moving engineering culture, not to fight against it and be quietly bypassed.
  • Evidence and documentation robust enough to stand up to serious, sceptical enterprise due diligence.
  • Awareness training so that security became part of the everyday culture across the whole company, not just the security team’s isolated concern.

The implementation journey

We began by understanding how Cobalt genuinely built and ran its software, so that the security management system would describe and improve reality rather than contradict it. The risk assessment focused on what actually mattered to the business and its customers. Controls were chosen and adapted to work with the company’s existing tools and rhythms, so that doing the secure thing became the easy, default thing rather than an obstacle to be resented. We paid particular attention to the human side, because most security failures are ultimately human: everyone, not just engineers, came to understand their part in protecting customer data.

What changed

Certification reframed the entire conversation with prospects. Instead of Cobalt scrambling to answer each questionnaire from a blank page, it could point to an independently verified management system that already addressed the great majority of the questions in a structured, credible way. Trust that had previously taken weeks of back-and-forth to build was now largely established before the first security call even began. The certificate did the heavy lifting that individual answers never could, because it represented an outside authority’s verdict rather than the company’s own assurances.

The outcome

  • Security reviews in the sales cycle became dramatically faster, because the certificate answered most questions up front and pre-empted many others.
  • New enterprise contracts that had explicitly required certification were won, contracts that had previously been unreachable.
  • Security shifted from being a blocker at the very end of the sales process to being a positive selling point at the very start of it.
  • A repeatable, scalable system that grows with the company, rather than being reinvented painfully for every new deal.

Lessons for growing technology companies

Cobalt’s experience offers a clear lesson for any technology company moving upmarket. There comes a point where informal, ad hoc security is no longer enough, not because it is necessarily weak, but because it cannot be proven to demanding buyers. ISO 27001 solves the proof problem, but only if the underlying system is real. The companies that benefit most treat certification not as a marketing exercise but as an opportunity to genuinely organise their security — and then let the certificate communicate that reality efficiently to every future customer.

Looking ahead

With a mature information-security management system in place, Cobalt can pursue ever-larger customers with confidence, extend into adjacent standards such as privacy management on the same foundation, and treat security as a durable competitive advantage rather than a recurring obstacle. The wall that once blocked its growth has become a door.

← Back to all case studies