If I compare several managed security service providers, and they all hold ISO 27001 certification or have anSOC 2 report, I wouldn’t spend long debating who has the stronger credentials.
At this point, the credentials have already done their job. They tell me the organization is seriously committed to how it manages security, and that it has controls in place that have been independently assessed.
However, I could still be disappointed by an MSSP if I don’t ask the right questions and get evidence of itssecurity policies and processes.
What I want to know is what a company’s security operations look like from day to day, and how can they prove this?
The Credentials Are the Starting Point
One misconception is that the ISO 27001 certification or SOC 2 report is the end result.
I see it as the starting point for security management. Security certifications or an SOC 2 report is a worthwhile standard to achieve, but organizations must go beyond this if they want to prioritize their security obligations.
For me, what matters is what had to happen inside the organization to get there. Security cannot sit with a team in the corner while everybody else gets on with their job. To make these frameworks work properly, security has to become part of how the business operates.
When somebody introduces a new service, changes an application, grants access or works with customer data, the security implications should already be part of that decision.
An approach like that is what gives me confidence — not simply that an organization passed an audit, but that it has built ways of working it can maintain throughout the year.
And that is where different providers can start to look very different, even when the logo on the certificate is exactly the same.
Identical Industry Standards Impact Organizations in Different Ways
I've worked for organizations in various sectors that had the same certification but applied the framework in completely different ways.
This should always be the case to ensure that credentials work for a business, not against it.
A fintech business processing financial transactions navigates different risks, regulatory requirements and technology challenges than an MSSP managing security across multiple environments.
Credentials provide the requirements and discipline to manage risk, but don’t design the security program. Two MSSPs can agree on the same certification requirements and have different levels of operational maturity.
Good Policies Have to Work With Employees, Not Against Them
When I helped Globalgig develop its ISO 27001 and SOC 2 process, writing the policies was not the hardest part. The most difficult task was making sure those policies work in practice.
You can create security processes that look strong on paper because they are supposed to control everything, but just having policies written down doesn’t mean people will follow them. If a process makes it unnecessarily difficult for someone to do their job, they will usually find another way, potentially creating unexpected problems for the business.
So when I was helping to develop Globalgig’s policies, the aim wasn’t to impose a rigid security process that employees had to navigate, but rather to produce a framework that understood how the organization operated, what the controls needed to achieve, and how the two could work together.
I like to see this as setting boundaries. Within these boundaries, everyone can do their work and be productive.
However, setting boundaries only works if you can see what is happening within those controls. Observability is a big part of that. AI is making it easier to surface insights and identify unusual behavior, but at the same time, AI applications and agents are expanding the surface area organizations need to monitor, making it broader, more complex and less predictable. For me, that makes observability even more important in ensuring that the controls behind frameworks such as ISO and SOC 2 are working as intended. This is something we have focused on intensely at Globalgig, both in the services we deliver to clients and within our own environment, including through our work with specialists such as Palo Alto Networks.
The best outcome is when new policies don’t push employees to act in a specific way that conflicts with how they usually work, but are instead part of how the organization works.
Ask for Evidence, Not Just Assurance
When choosing an MSSP, you must be able to trust that they have your best interests at heart and go beyond the minimum standards required by their security credentials.
I’d want to understand what sits behind their credentials. How is access reviewed? How are vulnerabilities identified and addressed? Are incident response and business continuity plans tested, and if so, how often?
I’ve seen expectations around third-party security increase considerably throughout my career. Security assessments that used to involve a handful of written responses can now run up to 100 questions, with supporting evidence requested.
At Globalgig, we provide clients with a summary of the policies behind our ISO framework, alongside evidence, including penetration testing and vulnerability scanning reports. The aim is not to hand over every internal document, but to provide enough visibility and evidence for clients to have confidence in how their data and environment are protected.
I don’t think that level of scrutiny is excessive. If you are trusting another organization with part of your environment, you should understand how it operates, particularly when something goes wrong.
No credential can prevent security incidents, and an MSSP may have to react to cybersecurity threats, even with the most stringent controls. But you should expect them to have tested processes for detecting, escalating, and remediating issues, as well as communicating them.
Without this, resolving issues can take much longer and become costly.
What Sits Behind the Credentials Matters More
ISO 27001 certification or an SOC 2 report can establish an important level of trust. But when several providers hold similar credentials, what differentiates them is how those requirements show up in practice.
The providers I trust most are those that can demonstrate how security is built into the way they operate, make decisions and respond when something goes wrong.