Skip to main content
Cyber Security 9 min read By Adv. Or Elyashiv

Why ISO 27001 Certification Won't Shield You From Legal Liability

ISO 27001 has become a cornerstone of cyber risk management, but certification alone does not eliminate a company's legal exposure or the personal risk to its officers.

קראו בעברית

When ISO 27001 Certification Doesn't Protect the Company

An Israeli technology company completed a full ISO 27001 certification process, received its certificate, and proudly displayed it on its website and in due diligence materials shared with customers. A few months later, a security incident exposed customers' personal data. Customers argued that the certification had created a reasonable expectation of a certain level of protection, one that did not actually exist in practice.

This scenario is not unusual. Many companies treat ISO 27001 certification as a finish line, when legally it is only a starting point. This article examines the legal shift from "compliance with the standard" to "actual accountability," and what that means in practice for technology companies operating in Israel.


What Legal Weight Does ISO 27001 Actually Carry in Israel

The Privacy Protection Law, 5741-1981, as amended by Amendment 13, and the Privacy Protection Regulations (Data Security), 5777-2017, do not directly require ISO 27001 certification. However, the Privacy Protection Authority and other regulators commonly treat the standard as an indicator that "reasonable security measures" are in place, calibrated to the sensitivity of the data being processed.

In practice, this means certification can serve as supporting evidence for a company in a regulatory or legal proceeding, but it is not conclusive. A court or regulator may still examine whether the controls documented under the standard were actually implemented, and whether they were proportionate to the specific risk that materialized.

As of the date of this article, there is no provision under Israeli law that grants an ISO 27001 certificate an automatic "presumption of compliance."


Why the Focus Is Shifting From Compliance to Actual Accountability

ISO 27001 is built around a core document known as the Statement of Applicability, which sets out which controls were adopted, which were excluded, and why. The certificate confirms that a risk management process was documented and reviewed at a given point in time — it does not confirm that the controls actually functioned in real time.

When regulators or courts examine a security incident, the central question is rarely "was the company certified." The more relevant questions are substantive: were the documented controls actually implemented, did the risks accepted as "residual risk" remain reasonable, and were processes updated to reflect evolving threats.

This reflects a broader shift from a formal review of "meeting requirements" to a substantive review of "actual accountability" — consistent with the general direction of cyber and privacy regulation, which increasingly emphasizes outcomes over documentation.


ISO 27001 Commitments in Contracts and What They Create

SaaS agreements, outsourcing contracts, and managed services agreements frequently include a clause requiring the vendor to maintain valid ISO 27001 certification throughout the term of the engagement. Such a clause is not merely declaratory — it constitutes a contractual representation and ongoing obligation.

Loss of certification, even temporarily, can constitute a breach of contract giving rise to termination rights, indemnification claims, or the exercise of audit rights granted to the customer. Many companies fail to notice that a blanket commitment to "maintain valid certification at all times" can be overly broad, and poorly suited to the reality that recertification processes take time to organize.


Director and Officer Liability During a Cyber Incident

The Companies Law, 5759-1999, imposes on directors a duty of care and a duty of loyalty, which include reasonable oversight of cyber risk management. ISO 27001 certification can serve as an indication that the board acted responsibly when approving an information security policy, but it does not relieve the board of its ongoing duty of oversight.

Following Amendment 13 to the Privacy Protection Law, companies are now subject to breach notification obligations toward the Privacy Protection Authority for serious security incidents, as well as duties to document and respond in an orderly manner. A company that relies on its ISO 27001 certificate as a substitute for an actual incident response mechanism may find itself in breach of the notification duty itself, separate and apart from any question of tort liability.

It is advisable for a company's incident response process to be reviewed legally as a distinct matter from the certification process, so that the company can demonstrate an independent, documented, and rehearsed response capability.


The Gap Between the ISO 27001 Certificate and Operational Reality

An ISO 27001 audit is sample-based — the auditor reviews a limited sample of controls and processes, not the entirety of the organization's ongoing operations. The certificate is not confirmation that every system and component in the organization meets the standard's requirements at every given moment.

In addition, the scope of certification may be limited to a particular department, product, or technology environment, while the legal or regulatory incident occurs precisely in an area that falls outside that scope. This gap between "what was certified" and "what actually happened" is one of the central points on which a company's liability is examined.

It is advisable to conduct a periodic legal review of the Statement of Applicability and the risk register, to confirm that the exclusions and working assumptions adopted by the information security team meet the required legal standard of reasonableness — not merely the technical threshold of the standard itself.


What Companies Should Do to Bridge the Standard and the Law

The gap between technical certification and legal accountability can be narrowed, but doing so requires proactive action rather than passive reliance on the results of the annual audit.

  1. Conduct a legal review of the Statement of Applicability and risk register, alongside the ISO process rather than merely as part of it.
  2. Ensure incident response procedures align with breach notification obligations under the Privacy Protection Law as amended by Amendment 13.
  3. Revisit contractual clauses relating to ISO 27001 with customers and vendors, and ensure they are proportionately drafted.
  4. Align cyber insurance policy requirements with the actual scope of certification, to avoid coverage gaps.
  5. Document board-level discussions on cyber risk management as independent evidence of reasonable oversight.

ISO 27001 remains an important tool for managing information security risk, but it should function as one layer within a broader framework of corporate governance, sound contracting, and legal incident response processes. Companies that examine the gap between the standard and the law on an ongoing basis, rather than only at recertification time, will be better positioned to handle both a future cyber incident and any regulatory or legal scrutiny that follows.


The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.

Adv. Or Elyashiv
Written by

Adv. Or Elyashiv

Founder of Or Elyashiv Law Firm, specializing in technology law, privacy protection, intellectual property, and commercial law. Advising tech companies, startups, and international investors. Data Protection Officer (DPO), a graduate of the Tel Aviv University training program for data protection officers, held in cooperation with the Israeli Privacy Protection Authority.

View All Articles

Examining Legal Exposure Beyond Your ISO Certificate?

The cybersecurity team at Or Elyashiv Law Firm advises technology companies on the gap between technical certification and legal liability, drafting contractual clauses, and building incident response mechanisms.