September 2026. Two announcements from two very different industries — both citing the same standard: ISO/IEC 27001:2022.
Aristocrat Interactive's CXS division, the content platform arm of one of the world's largest gaming entertainment companies, announced it had achieved ISO/IEC 27001:2022 certification across all its global offices. Shortly before, Eldik Bank from Kyrgyzstan announced that it too had obtained the same international information security certification.
These are not isolated events. They are signals of a broader shift that is already reshaping how organizations in data-sensitive industries are evaluated by regulators, customers, and partners: ISO 27001:2022 has moved from a competitive differentiator to a baseline expectation — and in some sectors, a requirement.
What Changed in ISO 27001:2022?
The most significant update in ISO 27001:2022 is the restructuring of Annex A — the reference set of information security controls that organizations implement as part of their Information Security Management System (ISMS).
The 2013 version had 114 controls organized across 14 domains. The 2022 version consolidates these into 93 controls grouped under 4 themes:
| Theme | Controls | Scope |
|---|---|---|
| Organizational Controls | 37 | Policies, asset management, supplier relationships, compliance |
| People Controls | 8 | HR security, awareness, responsibilities |
| Physical Controls | 14 | Physical security, environment, equipment |
| Technological Controls | 34 | Access management, cryptography, cloud, monitoring, endpoint |
More importantly, the 2022 version introduced 11 new controls specifically designed to address modern cybersecurity threats that did not exist — or were not yet prominent — when the 2013 version was written:
- Threat Intelligence — organizations must proactively collect and analyze threat intelligence
- ICT Readiness for Business Continuity — ensuring IT systems are prepared to support operations during incidents
- Physical Security Monitoring — structured monitoring of physical security perimeters
- Configuration Management — strict management of system configurations to prevent unauthorized changes
- Information Deletion — verified and secure deletion of data across its lifecycle
- Data Masking — protecting personal data through masking and anonymization techniques
- Web Filtering — controlling web access to reduce web-based attack surfaces
- Secure Coding — security requirements built into the software development lifecycle
These additions reflect the reality that cyber threats have evolved dramatically — from conventional physical intrusions to cloud-native attacks, social engineering, software supply chain compromises, and AI-assisted threats.
Why Banking Chooses ISO 27001:2022
The Eldik Bank announcement illustrates a logic that every bank in the world now faces: customer trust is its core product, and data security is the foundation of that trust.
Banking manages two categories of data that are among the most sensitive in any industry: financial data and personal identity information. A breach of either doesn't just cause financial damage — it can erase decades of reputation in hours.
ISO 27001:2022 provides a comprehensive framework that addresses banking's specific security challenges:
- Structured risk management — systematic identification, assessment, and treatment of information security risks, not just technical controls
- Alignment with banking regulations — ISO 27001 aligns naturally with regulatory frameworks such as PCI DSS for card data, GDPR in Europe, and national financial sector cybersecurity regulations
- Internationally recognized evidence of compliance — a certificate from an accredited body is accepted by international banking partners, auditors, and regulators worldwide
- Standardized incident response — clear incident management procedures reduce response time and minimize the impact when breaches occur
- Supply chain and vendor security — the 2022 version strengthens requirements for managing the security of third-party suppliers and technology vendors
Regulators in many jurisdictions are increasingly citing ISO 27001 as a reference for assessing organizational cybersecurity maturity. This makes certification not just a trust signal to customers, but a practical tool for demonstrating regulatory compliance.
Why Gaming and iGaming Need ISO 27001:2022
Aristocrat Interactive CXS's decision to certify all its global offices — rather than just one headquarters location — makes a statement that goes beyond compliance: information security is treated as an organizational standard, not a single-site initiative.
This is significant because gaming, particularly iGaming (online gaming and betting), handles a combination of data that is exceptionally sensitive:
- Player identity data (passports, national IDs, proof of address for KYC requirements)
- Financial and transaction data (payment methods, deposit history, withdrawal records)
- Behavioral data (play patterns, spending habits, session data)
- Location and device data
In many jurisdictions, iGaming operators seeking licenses are required to demonstrate they have adequate information security controls in place. ISO 27001:2022 is among the most widely accepted frameworks for fulfilling that requirement.
There is also a B2B dimension: gaming content providers like Aristocrat Interactive CXS work with operators across dozens of markets. Each operator they partner with wants assurance that their player data — handled through shared platforms and APIs — is protected to a credible standard. ISO 27001:2022 provides that assurance in a form that every partner organization understands.
The Cross-Industry Signal
What makes September 2026 particularly notable is not just that these certifications happened, but that they happened simultaneously across industries that seem unrelated — a bank in Central Asia and a gaming technology company serving global markets.
The common thread is data sensitivity and trust dependency. Both industries deal with users who entrust them with financial assets and personal information. Both industries operate under regulatory frameworks that are tightening, not loosening. And both industries compete in markets where a data breach can be existential, not just damaging.
For organizations in similarly data-sensitive industries — healthcare, fintech, SaaS, legal services, telecommunications — the question is no longer whether ISO 27001:2022 is relevant. The question is when to begin.
A Practical Roadmap to ISO 27001:2022 Certification
The certification journey follows a consistent structure, though timeline and complexity vary significantly based on organizational size, existing security maturity, and the scope of the ISMS:
- Gap Analysis — assess current information security practices against ISO 27001:2022 requirements. This produces a realistic implementation roadmap and cost estimate.
- ISMS Scope Definition — define precisely which systems, processes, teams, and locations will be included in the ISMS.
- Risk Assessment and Treatment — identify information assets, analyze threats and vulnerabilities, and determine how each risk will be treated (mitigate, transfer, accept, or avoid).
- Control Implementation — implement the relevant Annex A controls based on risk assessment outcomes.
- Training and Awareness — build an information security culture across the organization, not just the IT team.
- Internal Audit — verify internal readiness before the external certification audit.
- Management Review — confirm that senior leadership has reviewed ISMS performance and is committed to continuous improvement.
- Certification Audit — Stage 1 (documentation review) and Stage 2 (implementation audit) by an accredited certification body.
After achieving certification, the cycle continues with annual surveillance audits and a full recertification audit every three years — ensuring the ISMS remains effective as threats and the organization evolve.
How Long Does Certification Take?
Timeline varies by organizational complexity, but here are realistic ranges based on industry experience:
| Organization Size | Typical Timeline | Key Factor |
|---|---|---|
| Small (10–50 staff, limited scope) | 4–8 months | Starting security maturity |
| Mid-size (50–200 staff) | 8–14 months | Number of systems in scope |
| Enterprise (200+ staff, multi-site) | 12–24 months | Geographic distribution, legacy systems |
The single most important variable is the initial gap between current security practices and ISO 27001:2022 requirements. Organizations with existing security policies, documented procedures, and staff awareness programs can move significantly faster than those starting from scratch.
This is why a thorough gap analysis is always the right first step — it transforms an uncertain journey into a planned project with clear milestones and measurable progress.
Conclusion: The Transition from Option to Expectation
The decisions by Aristocrat Interactive CXS and Eldik Bank to achieve ISO 27001:2022 certification were not made in isolation, and they were not driven by regulatory obligation alone. They were business decisions — investments in the credibility and trust that their respective markets increasingly demand.
This trajectory is consistent across industries. As data breaches become more frequent, more damaging, and more public, the organizations that customers, regulators, and business partners trust are those that can demonstrate — not just claim — that their information security practices meet a rigorous, internationally recognized standard.
ISO 27001:2022 is that standard. The question for organizations that haven't yet certified is not whether to begin — it's how soon.
Start with a Free ISO 27001 Gap Analysis
Arafar Nusa's consulting team will assess your current information security posture, identify gaps against ISO 27001:2022 requirements, and build a realistic certification roadmap tailored to your organization's size and complexity.
Contact Us via WhatsApp →