SP-Lutsk

ISO/IEC 27001 Readiness for a Multi-Tenant Logistics SaaS Platform

Electronic access control reader mounted on a concrete wall in an industrial corridor

Client scenario

Business archetype

Multi-Tenant Logistics SaaS Platform

The scale

Mid-market WMS/TMS SaaS vendor serving dozens of 3PL and fulfillment clients on shared infrastructure.

The objective

Pass an enterprise customer's ISO/IEC 27001 vendor security review within one quarter, without freezing the product roadmap.

The Challenge

Current State

A large prospective customer made ISO/IEC 27001 evidence a hard requirement before signing. The platform had grown for four years without a formal ISMS - access decisions were made ad hoc, by whoever set up a given client's account.

  • No documented access control policy - roles were granted by habit, not by design
  • Former employees and contractors still had standing access to production systems
  • No centralized logging of who accessed which tenant's data, or when
  • Security ownership was informally split across two engineers with no other job description for it

“Pain” Point

The immediate pressure was commercial, not technical:

  • The deal was worth more than the company's entire current customer base
  • The customer's security team had already flagged the gap in a preliminary questionnaire
  • Engineering leadership had never run a gap assessment against a real framework
  • There was no time to pause feature work for a multi-quarter compliance project
  • The instinct was to write policy documents to match what the auditor wanted to see. That would have passed a paper review and failed the first real incident.

    Hidden Risks

    • Multi-tenant data isolation had never been formally tested, only assumed
    • Shared admin credentials existed for at least one legacy integration
    • No incident response plan existed beyond "call the CTO"

    A vendor security review is often the first time these gaps get looked at directly.

    Constraints & Risks

    Technical Constraints

    • One-quarter deadline tied to a live commercial negotiation
    • Zero downtime tolerance - the platform could not go offline to fix access control
    • Legacy integrations that predated any access control policy
    • A small engineering team already at capacity on product work

    Operational Risks

    • Losing the deal if evidence was not credible, not just present
    • Overcorrecting into process that engineers would quietly route around
    • Treating this as a one-time audit response instead of a standing capability

    Decision & Trade-offs

    01. The Core Decision

    Run a scoped ISO/IEC 27001 gap assessment against Annex A controls first, before writing a single policy document. The gap assessment became the priority list.

    • Access control audit across every production system and integration
    • Revocation of standing access for anyone without a current, documented need
    • Centralized audit logging for cross-tenant data access
    • A named, accountable owner for security - not a shared responsibility
    02. The Trade-offs

    We prioritized:

    • Fixing real access control gaps over drafting comprehensive policy first
    • A narrow, verifiable ISMS scope over a company-wide rewrite
    • Evidence an auditor could independently verify over self-reported checklists

    Feature work continued in parallel. The security work ran as its own sprint track, not a company-wide freeze.

    03. Why Not Just Write the Policy Documents?

    Because policy documents that describe controls nobody actually runs are worse than no documents - they create liability without reducing risk.

    Every policy we wrote described a control that was already implemented and tested, not an aspiration for the next quarter.

    Impact

    What changed after the engagement.

    Operational Outcome

    • Access control audit completed and standing access revoked platform-wide
    • Centralized, queryable logs for all cross-tenant data access
    • A named security owner with defined authority, not a shared afterthought
    • An incident response plan tested against a tabletop scenario before go-live

    Business Value

    • The enterprise deal closed on schedule
    • The gap assessment became a reusable ISMS foundation, not a one-time exercise
    • Security evidence became a sales asset for later enterprise deals
    • Zero disruption to the product roadmap during the engagement

    Key Notes

    Lessons Learned

    What we learned from this engagement.

    1

    A gap assessment against a real framework beats writing policy from a template.

    2

    Access control debt accumulates silently in fast-growing SaaS teams.

    3

    Security ownership needs a name attached to it, not a shared understanding.

    4

    Compliance work run as its own sprint track does not have to freeze the roadmap.

    Compliance is a byproduct of good architecture, not a separate project.

    Find out what a vendor security review would find in your systems today.