This study explores the implementation of ISO/IEC 27001:2022 in a resource-constrained biotech small and medium enterprise (SME) in Taiwan. The company adopted a phased approach, achieving ISO/IEC 27001:2013 certification in April 2023 and transitioning to the 2022 standard by April 2025. By leveraging open-source tools for security monitoring, log management, and training, the company achieved a 31% reduction in security incidents, a 40% improvement in employee cybersecurity awareness, and a 10-point increase in customer satisfaction. The total implementation cost was approximately 35% below typical industry benchmarks. This mixed-methods case study, guided by a control classification framework (ACT–TRG–SCP) and interpreted through threat response, technology adoption, and institutional theories, provides a replicable roadmap for resource-limited SMEs to strengthen their Information Security Management System (ISMS). Limitations include reliance on internal auditing and biotech-specific applicability, suggesting the need for cross-industry research to enhance generalizability. The findings demonstrate that strategic use of open-source tools can enable robust ISMS compliance in high-stakes sectors.
Huang et al. (2026) studied this question.