Inside Mailbutler
Project Phoenix: The Plan I Made to Prove I Had One
A one-year plan to prove I had one. Here's what Project Phoenix actually was, what I got right, and what I quietly gave up on along the way.
We hired a certification agency to help us get ISO 27001 certified. It didn't work out the way we expected — and the certification turned out to be far more manageable once we stopped following their playbook.
Former Tanzanian, now happily repatriated European, back in my birth-place of Berlin. I enjoy the little things in life, as well as traveling, hiking and spending time with good friends.
In my last post, I wrote about why we pursued ISO 27001 and what it changed inside Mailbutler. This one is different. This is about what nobody tells you before you hire an ISO 27001 certification agency: what it's actually like to work with one, what went wrong for us, and what I'd tell another founder before they sign anything.
Short version: I wouldn't hire the same agency again. But the certification itself was absolutely worth it — once we stopped outsourcing our thinking.
None of us had ever gone through an ISO 27001 process before. Every search result said the same thing: don't do this alone, get an agency. That made sense to me at the time — we were a small team with zero certification experience, and the idea of a guided roadmap sounded like exactly what we needed.
We compared a few agencies. Calls, pricing, references. The offerings all looked similar: template documentation, a roadmap to follow, general consulting, and a self-service platform to manage the whole thing. Pricing was similar too — somewhere in the €10,000–15,000 per year range, with a two-year commitment. For a company our size, that's a serious upfront bet.
We picked a German agency out of Munich. Good reputation, professional pitch. It felt like the safe choice.
The kickoff call was smooth. They walked us through their platform: a timeline, document management, risk and asset tracking tools, even an "academy" with basic security training for the team. It looked comprehensive. It also, in hindsight, looked like a product built to keep you inside their ecosystem.
We started with their template documents. At first they seemed helpful — a starting point is a starting point. But it didn't take long to notice the real problem:
The templates were built for everyone, which meant they fit no one. The same documentation set they hand a 500-person corporate goes to a five-person startup. We were drowning in policies and procedures that had nothing to do with how we actually work.
We pushed through anyway. Then came the internal audit.
The audit was the moment everything became obvious. Almost none of the over-engineered processes we'd copied from their templates matched our reality. We walked away with a long list of non-conformities — essentially, a list of everything that didn't hold up.
At that point we started over. We wrote our own policies. Our own procedures. Lightweight, but genuinely secure, tailored to a company our size rather than a fictional enterprise customer.
And the agency didn't help much here. Their support ticket system was slow, and when answers did come back, they were generic — the same boilerplate advice regardless of what we'd actually asked.
There was one moment that stuck with me. We were already using Microsoft SharePoint, and it covered everything ISO 27001 actually requires for document management. When we asked about using it instead of their platform, they pushed back with reasons that were vague at best.
I think they just wanted us on their platform for the lock-in.
We built our ISMS in SharePoint anyway. It worked fine.
Once we stopped trying to force our company into their template, the certification suddenly looked much more manageable than we'd assumed. That's the real lesson here: ISO/IEC 27001 doesn't tell you how to run your ISMS — it tells you what areas need to be covered. It's a framework, not a checklist. That distinction gives you a lot more freedom than most certification agencies let on — and it's the single biggest thing I wish someone had told us before we hired ours.
We ended up managing:
Nothing exotic. Nothing that needed a €10,000-a-year platform behind it.
To be fair, not everything about the agency was wasted. Having a structured annual internal audit was genuinely valuable — it's the one thing I'd keep from the whole engagement. My only regret is that we didn't get that first audit earlier, even a partial one covering a few areas. It would have shown us we could scale everything down months before we actually figured that out ourselves.
If you're a founder or exec staring down an ISO 27001 project right now, here's what I actually believe, not what the sales calls from a certification agency will tell you:
Our contract with the agency runs out at the end of the year, and we won't be renewing it. We'll keep our ISMS exactly where it is — lean, in the tools we already use, audited annually by an independent freelancer. Looking back, I don't regret pursuing ISO 27001 for a second. I just regret assuming for so long that we needed someone else to tell us how to do it.
If you're going through this right now, or thinking about starting, I'd genuinely like to hear how it's going for you — drop a comment below, or reach out directly.