ISO 27001 — Arafar Nusa

ISO 27001:2022 Becomes the Information Security Standard of Choice for Banking and Gaming

Published October 3, 2026  •  8 min read

September 2026. Two announcements from two very different industries — both citing the same standard: ISO/IEC 27001:2022.

Aristocrat Interactive's CXS division, the content platform arm of one of the world's largest gaming entertainment companies, announced it had achieved ISO/IEC 27001:2022 certification across all its global offices. Shortly before, Eldik Bank from Kyrgyzstan announced that it too had obtained the same international information security certification.

These are not isolated events. They are signals of a broader shift that is already reshaping how organizations in data-sensitive industries are evaluated by regulators, customers, and partners: ISO 27001:2022 has moved from a competitive differentiator to a baseline expectation — and in some sectors, a requirement.

🔒 Key context: ISO 27001:2022 replaces the 2013 version. Organizations holding ISO 27001:2013 certificates had until October 2025 to transition. Certificates issued under the 2013 version are no longer considered valid under the current standard.

What Changed in ISO 27001:2022?

The most significant update in ISO 27001:2022 is the restructuring of Annex A — the reference set of information security controls that organizations implement as part of their Information Security Management System (ISMS).

The 2013 version had 114 controls organized across 14 domains. The 2022 version consolidates these into 93 controls grouped under 4 themes:

ThemeControlsScope
Organizational Controls37Policies, asset management, supplier relationships, compliance
People Controls8HR security, awareness, responsibilities
Physical Controls14Physical security, environment, equipment
Technological Controls34Access management, cryptography, cloud, monitoring, endpoint

More importantly, the 2022 version introduced 11 new controls specifically designed to address modern cybersecurity threats that did not exist — or were not yet prominent — when the 2013 version was written:

These additions reflect the reality that cyber threats have evolved dramatically — from conventional physical intrusions to cloud-native attacks, social engineering, software supply chain compromises, and AI-assisted threats.

Why Banking Chooses ISO 27001:2022

The Eldik Bank announcement illustrates a logic that every bank in the world now faces: customer trust is its core product, and data security is the foundation of that trust.

Banking manages two categories of data that are among the most sensitive in any industry: financial data and personal identity information. A breach of either doesn't just cause financial damage — it can erase decades of reputation in hours.

ISO 27001:2022 provides a comprehensive framework that addresses banking's specific security challenges:

Regulators in many jurisdictions are increasingly citing ISO 27001 as a reference for assessing organizational cybersecurity maturity. This makes certification not just a trust signal to customers, but a practical tool for demonstrating regulatory compliance.

Why Gaming and iGaming Need ISO 27001:2022

Aristocrat Interactive CXS's decision to certify all its global offices — rather than just one headquarters location — makes a statement that goes beyond compliance: information security is treated as an organizational standard, not a single-site initiative.

This is significant because gaming, particularly iGaming (online gaming and betting), handles a combination of data that is exceptionally sensitive:

In many jurisdictions, iGaming operators seeking licenses are required to demonstrate they have adequate information security controls in place. ISO 27001:2022 is among the most widely accepted frameworks for fulfilling that requirement.

There is also a B2B dimension: gaming content providers like Aristocrat Interactive CXS work with operators across dozens of markets. Each operator they partner with wants assurance that their player data — handled through shared platforms and APIs — is protected to a credible standard. ISO 27001:2022 provides that assurance in a form that every partner organization understands.

🎮 Industry context: According to a 2025 industry analysis by sigma.world, ISO 27001 is among the six key ISO certifications shaping casino and gaming operator compliance standards in 2025. Information security certification has moved from a competitive edge to a baseline expectation in regulated gaming markets.

The Cross-Industry Signal

What makes September 2026 particularly notable is not just that these certifications happened, but that they happened simultaneously across industries that seem unrelated — a bank in Central Asia and a gaming technology company serving global markets.

The common thread is data sensitivity and trust dependency. Both industries deal with users who entrust them with financial assets and personal information. Both industries operate under regulatory frameworks that are tightening, not loosening. And both industries compete in markets where a data breach can be existential, not just damaging.

For organizations in similarly data-sensitive industries — healthcare, fintech, SaaS, legal services, telecommunications — the question is no longer whether ISO 27001:2022 is relevant. The question is when to begin.

A Practical Roadmap to ISO 27001:2022 Certification

The certification journey follows a consistent structure, though timeline and complexity vary significantly based on organizational size, existing security maturity, and the scope of the ISMS:

  1. Gap Analysis — assess current information security practices against ISO 27001:2022 requirements. This produces a realistic implementation roadmap and cost estimate.
  2. ISMS Scope Definition — define precisely which systems, processes, teams, and locations will be included in the ISMS.
  3. Risk Assessment and Treatment — identify information assets, analyze threats and vulnerabilities, and determine how each risk will be treated (mitigate, transfer, accept, or avoid).
  4. Control Implementation — implement the relevant Annex A controls based on risk assessment outcomes.
  5. Training and Awareness — build an information security culture across the organization, not just the IT team.
  6. Internal Audit — verify internal readiness before the external certification audit.
  7. Management Review — confirm that senior leadership has reviewed ISMS performance and is committed to continuous improvement.
  8. Certification Audit — Stage 1 (documentation review) and Stage 2 (implementation audit) by an accredited certification body.

After achieving certification, the cycle continues with annual surveillance audits and a full recertification audit every three years — ensuring the ISMS remains effective as threats and the organization evolve.

How Long Does Certification Take?

Timeline varies by organizational complexity, but here are realistic ranges based on industry experience:

Organization SizeTypical TimelineKey Factor
Small (10–50 staff, limited scope)4–8 monthsStarting security maturity
Mid-size (50–200 staff)8–14 monthsNumber of systems in scope
Enterprise (200+ staff, multi-site)12–24 monthsGeographic distribution, legacy systems

The single most important variable is the initial gap between current security practices and ISO 27001:2022 requirements. Organizations with existing security policies, documented procedures, and staff awareness programs can move significantly faster than those starting from scratch.

This is why a thorough gap analysis is always the right first step — it transforms an uncertain journey into a planned project with clear milestones and measurable progress.

Conclusion: The Transition from Option to Expectation

The decisions by Aristocrat Interactive CXS and Eldik Bank to achieve ISO 27001:2022 certification were not made in isolation, and they were not driven by regulatory obligation alone. They were business decisions — investments in the credibility and trust that their respective markets increasingly demand.

This trajectory is consistent across industries. As data breaches become more frequent, more damaging, and more public, the organizations that customers, regulators, and business partners trust are those that can demonstrate — not just claim — that their information security practices meet a rigorous, internationally recognized standard.

ISO 27001:2022 is that standard. The question for organizations that haven't yet certified is not whether to begin — it's how soon.

Start with a Free ISO 27001 Gap Analysis

Arafar Nusa's consulting team will assess your current information security posture, identify gaps against ISO 27001:2022 requirements, and build a realistic certification roadmap tailored to your organization's size and complexity.

Contact Us via WhatsApp →
📋 FREE: ISO 9001:2015 50-Point Certification Preparation Checklist