Sarah, an IT manager at a mid-sized financial firm, noticed increasing phishing attempts targeting her company. Recognizing the risks, she pursued the ISO/IEC 27001 Lead Implementer certification. Armed with new expertise, she overhauled the firm's ISMS, introduced comprehensive security policies, and trained staff on best practices. Within a year, security incidents dropped by 60%, and Sarah was promoted to Director of Information Security.