Customer Stories

Certified in under six months. How Stora reached ISO 27001 without hiring a security team.

Services

  • Security Consulting

We already had solid security practices, but I hadn’t led an ISO 27001 certification before. Instil helped us turn those practices into a practical, independently certified ISMS in under six months, without the process taking over my day job or requiring us to introduce a new set of tools.


Phil McClure

Head of Platform Engineering

Stora started as one self-storage operator's fix for his own facility. It's now the operating system behind more than 600 self-storage businesses across 15+ countries.

Stora's platform runs the back end of self-storage, from bookings and subscriptions to dynamic pricing, facility maps and unit status, access control integrations and a public API, all behind a storefront each operator can call their own.

Stora decided not to wait for a customer to demand it. As the business set its sights on larger, more established operators, ISO 27001 would put the right security credentials in place before procurement ever asked. With no dedicated security lead on a fast-growing team, the certification fell to Phil McClure, Head of Platform Engineering and co-founder, on top of his existing role. Stora engaged Instil to guide the business through building an information security management system (ISMS) and getting certified to ISO 27001.

Challenge

Stora already treated security as a business priority. Like many scaling startups, though, it had no certified framework to back that up.

First formal security standard - Stora had its own working practices around security, but nothing certified or externally validated. ISO 27001 would be the company's first structured, audited approach to information security.

No dedicated security lead - stretched across a fast-growing product, the team had nobody whose job it was to own security. Getting certified meant building a process that a generalist, already busy with a full-time role, could realistically run.

Getting ahead of a higher bar - Stora wanted the certification in place before landing larger, more established operators, whose procurement processes were increasingly likely to demand it, instead of scrambling to build one once a deal depended on it.

Approach

Instil ran the ISMS build in short, focused sessions that fit around Phil's existing role, not a single intensive push that competed with it.

Weekly working sessions - Phil and Tom Shields, a senior Instil consultant, met weekly to work through each part of the ISMS in turn, giving the process a steady, manageable rhythm instead of a single heavy audit sprint.

Built to fit the client's existing tech stack - Instil doesn't introduce new tools for the sake of easier delivery. The team assesses how a business already communicates and stores its documents, then builds the ISMS to fit that stack rather than around it. Instil doesn't run its own ISMS platform either, the same approach has been used to build inside Confluence, SharePoint, Google Workspace or anywhere the customer works.

No new tooling for Stora - for Stora, that meant building the ISMS inside Notion, alongside the company documents and policies already kept there, rather than asking the business to adopt something new just to get certified.

Company-wide awareness training - security awareness training, covering practical topics like phishing, was delivered remotely to the whole company, reaching Stora's distributed staff without requiring travel or in-person sessions.

Kept deliberately lightweight - the process was scoped to suit a team wearing multiple hats, prioritising a workable, sustainable framework over documentation for its own sake.

The working relationship stayed collaborative and low-friction throughout, shaped around the reality of a busy team, not a standard template.

Impact

Stora turned its existing security practices into a certified, independently audited ISMS in under six months.

ISO 27001 certified in under six months - with no prior hands-on experience of the certification process, Phil formalised Stora's existing security practices into a certified ISMS in under six months, faster than he expected going in.

Zero non-conformities - Stora passed both audit stages, remote stage one and stage two, with no major or minor non-conformities raised, a clean result for a first-time certification.

Risk management became a lasting habit - ISO 27001 gave Stora a formal risk framework it didn't have before. Phil applied it quickly, flagging a third-party AI vendor outage as a risk in one working session that fed directly into reducing reliance on a single AI provider. Quarterly risk meetings and a live risk register have continued since certification, with plans to open the register up department by department as Stora scales, the kind of practice usually seen in much larger organisations.

Whole-company security awareness training completed - every member of staff, including remote workers, completed security awareness training as part of the certification, with no separate in-person rollout needed.

No dedicated security hire required - Stora reached certification without adding a dedicated security or compliance role, running the process alongside Phil's existing platform engineering responsibilities.

Stora now has a certified ISMS to point to the moment security comes up in procurement, viewable at its Trust Centre, and a credential its sales team can lead with rather than defend against. Since certifying, Phil has already noticed more prospects, particularly in Europe, asking about Stora's ISO 27001 status. Larger-operator sales cycles take time to close, but Stora is now equipped to compete for procurement-led deals it couldn't have pursued with confidence six months ago.

Every client gets something different out of building an ISMS. For Stora it was risk. Phil picked it up fast, to the point he was flagging risks and thinking about how to mitigate them. That’s probably one of the best things a client can walk away with.

Tom Shields, Senior Consultant, Instil

Stora turned its existing security practices into an ISO 27001 certified ISMS in under six months, clearing a bar, clearing a bar larger self-storage operators now expect before they'll sign. If a security certification is standing between you and the customers you want to win, Instil can get you there without pulling focus from everything else your team is building. Let's talk.