- Prompt injection attacks manipulate AI guardrails using natural language, exploiting the semantic gap to get models to ignore developer instructions.
- AI social engineering scales faster and lowers attacker skill barriers, enabling automated, targeted campaigns like deepfakes and credential theft.
- Primary harms include data exfiltration, unauthorized transactions, and malicious or biased outputs that damage reputation and operations.
- Defenses are immature; require layered controls: human in the loop, prompt firewalls, input sanitization, least privilege, fuzz testing, patching, and user training.
Last Updated on September 9, 2026
The 2024 climate change amendment to ISO 27001:2022 requires organizations to consider and potentially address climate change impacts within their information security management System (ISMS). This update reflects a growing global awareness of the interconnection between climate risks, environmental sustainability, and information security.
What should organizations do to ensure compliance with the amended version of ISO 27001:2022 prior to their next audit? This article explains what is most important for business and technical leaders to be aware of.
Why did ISO 27001:2022 need a climate change amendment?
ISO 27001:2022 was amended to address climate change due to increased awareness of how environmental shifts can directly threaten power availability, physical IT systems, and supply chain connections that are integral to information security.
Reflecting the sweeping ramifications of climate change across business areas, in February 2024 the International Organization for Standardization (ISO) introduced a similar amendment into all its Type A management system standards, which are those to which companies can be certified against requirements. This includes about 30 standards including ISO 27001, ISO 9001 for quality, and ISO 22301 for business continuity management. This was to formalize climate risk considerations within governance and strategic planning.
What are the key concerns behind the ISO 27001 update?
Information security management best practices require firms to assess and potentially address climate change related risks.
Top risk drivers for the ISO 27001 climate change amendment include:
- Operational disruption due to power instability. Extreme weather characteristic of the changing climate, such as severe storms or prolonged heat waves, can cause local or widespread power grid blackouts that could interrupt data availability and/or harm data integrity.
- Damage to physical IT infrastructure. Severe weather events like floods or high winds can physically damage data centers, hardware systems, etc., potentially compromising digital security controls.
- Data center overheating issues. High temperatures and extended heatwaves can strain the complex liquid cooling systems needed for AI data centers and other massive IT hardware installations, leading to outages.
- Vendor/supply chain breakdowns. Climate-related events can disrupt vendors’ ability to deliver essential cybersecurity, hosting, or other services or provide critical hardware, software, or other system elements, thus impacting an organization’s information security posture or ability to maintain its ISMS.
- Stakeholder pressure. Regulators, investors, customers, boards, and other stakeholders increasingly expect or mandate organizations to account for climate change risks in their governance structures or sustainability policies, including information security management.
- Corporate environmental accountability. There is a growing global trend to hold corporations accountable for their environmental footprint. This includes integrating climate and sustainability factors into information security management.
- Reputational risks. Businesses that are slow to address climate-related information security risks may face increased stakeholder scrutiny, negative publicity, loss of stakeholder confidence, or reduced customer trust.
How does the climate change amendment change ISO 27001?
The 2024 amendment to ISO 27001:2022 creates a requirement for firms to assess whether climate change is a relevant risk factor for their ISMS. The standard changed in these two ways:
- Clause 4.1 (Understanding the Organization and Its Context) was amended to explicitly require organizations to evaluate climate change risks to digital and/or physical information security operations.
- Clause 4.2 (Understanding the Needs and Expectations of Interested Parties) was amended to note that relevant stakeholders may have specific requirements or expectations regarding climate change.
Specifically, the amendment adds this sentence to the end of subclause 4.1: The organization shall determine whether climate change is a relevant issue.
It also appends this sentence to the end of subclause 4.2: Relevant interested parties can have requirements related to climate change.
These additions to Clause 4 align with ISO 27001’s holistic approach to information security by guiding organizations towards a more adaptive, comprehensive security strategy that encompasses environmental resilience and sustainability.
Some organizations may conclude that climate change is not relevant to their ISMS context. However, it is still important for risk assessment and audit purposes to document that the question was formally evaluated.
How do we consider climate change in our ISMS?
As a leading global standard for information security, ISO 27001 seeks to define comprehensive requirements for building, operationalizing, maintaining, and continuously improving an ISMS that reflects an organization’s unique risks, business goals, size and industry, regulatory demands, etc.
Just as risks, regulations, and other organizational dynamics evolve, so must the ISO 27001 standard as a strategic tool to create a robust, efficient, and sustainable information security posture.
Here are ten essential steps to comply with the ISO 27001 climate change amendment guidance:
- Conduct a management review meeting to determine the relevance of climate change to your ISMS. Does it impact information security risks or business continuity planning?
- Connect with stakeholders to identify whether customers, partners, regulators, investors, etc. have specific climate change-based requirements that would affect your information security policies or controls.
- Document your decision on the amendment’s applicability to your ISMS either way for audit purposes (e.g., in the meeting minutes). Provide details justifying your choice for transparency and to support future climate change decisions.
- If you deem climate change not relevant to your ISMS context, the standard requires no further action.
- If you deem climate change to be applicable to your ISMS, you will need to update relevant policies, documentation, risk assessments, and compliance frameworks to incorporate identified climate change risks and considerations.
- Develop contingency plans and/or mitigation strategies for climate-related disruptions that would impact IT operations or information security.
- Review your disaster recovery and business continuity plans with a view on climate change risks. Your continuity plans need to account for possible disruptions, such as weather-related damage to critical IT infrastructure, per your risk assessment. For example, you might need to identify fallback data centers or backup solutions to maintain continuity of critical systems and processes, notably information security.
- Consider the need to augment employee education and training programs to cover the information security repercussions of climate change and how to reduce related risks (e.g., how to recognize and respond to climate-enabled compound cyber threats like “disaster panic” social engineering attacks).
- Regularly monitor and review climate risk within your ISMS context so it continues to protect sensitive data and enhance business resilience.
- Keep up to date on climate-related industry standards, cybersecurity best practices, and regulations that affect your ISMS.
What businesses are likely to have climate change impacts to their ISMS?
Among the organizations most likely to identify climate change risk within their ISO 27001 ISMS are those with:
- Physical data center infrastructure
- Facilities along the coast or major waterways
- Key supply chain links in disaster-prone regions
- Firms in highly regulated industries (e.g., critical infrastructure)
- Organizations operating in areas with strict environmental regulations
- Customers, partners, or other stakeholders who value environmentally responsible business practices
Table 1 lists examples of climate change risk by industry:
| Data center operators | Extreme high temperatures can overwhelm cooling systems, leading to shutdowns and threatening data availability and business process continuity while increasing the risk of compound cyberattacks. |
| Financial technology (FinTech) companies | Many FinTechs are based in urban areas where heavy rain can cause flash floods that overwhelm drainage systems, infiltrating below-ground IT infrastructure and threatening data access and data integrity. |
| Agricultural technology (AgTech) businesses | Droughts, fires, or floods can damage rural power and cell networks, interrupting remote data monitoring capabilities. |
| Coastal warehousing or logistics firms | Major storms, high tides, or rising ocean levels can flood coastal offices, breaking communications and impacting data access. |
| Regulated industries or government | Stakeholders may require regulated firms to meet strict environmental accountability initiatives |
What’s next?
As climate risks develop, businesses of all kinds need to ensure that their information security management programs can adapt and build resilience.
If you are looking to incorporate climate risk impacts into your ISMS, contact CBIZ Pivot Point Security. Our ISO 27001 experts can help you efficiently align with the amended requirements.