Providing secure and reliable personal financing services to clients through an ISO/IEC 27001:2022–compliant ISMS.

ACOM (M) SDN. BHD.
Case Study
  • Security
  • Global
ACOM (M) SDN. BHD.

ACOM (M) SDN. BHD. provides secure and reliable personal financing services by implementing an Information Security Management System (ISMS) in accordance with the ISO/IEC 27001:2022 standard.
ABeam Consulting supported the efficient implementation of ISMS by leveraging its consultants’ extensive experience and expertise.

Challenge

  • In today’s digital landscape, cybersecurity threats are increasing, making it more challenging to safeguard customers’ personal data.
  • ACOM made a strategic decision to implement ISMS;however, it requires substantial investment of time, expertise, and resources, and cross-departmental collaboration.
  • Transitioning from existing, informal practices to a structured, risk-based approach necessitates a cultural shift, ongoing training, and persistent reinforcement.

ABeam Solution

  • ABeam accelerated ISMS implementation by deploying experienced consultants and leveraging proven frameworks, templates and best practices—minimizing inefficiencies and reducing implementation costs.
  • ABeam facilitated stakeholder alignment through workshops and established effective cross-functional collaboration channels.
  • Comprehensive risk assessments ensured that security controls not only protected critical operations and customer commitments but also supported business agility.
  • A culture of continuous improvement was embedded through regular reviews, corrective actions, and internal audits, fostering a resilient and self-improving security environment.

Success Factors

  • Strong commitment and engagement from ACOM management ensured that the ISMS initiative was strategically aligned with organizational goals.
  • Structured workshops and robust communication channels fostered a shared understanding and seamless collaboration across departments.
  • Proactive engagement of ISMS committee members from the front office, back office, legal, and IT—working in close partnership with ABeam—enabled the effective implementation of ISMS that was seamlessly integrated with existing business operations.
  • The integration of systematic reviews, objective yet consultative internal audits, and targeted corrective measures established a resilient security culture.

Client Challenges

Navigating the Expansive Scope and Complexity of ISO/IEC 27001:2022 Requirements

Cybersecurity threats continue to grow in both scale and sophistication. As ACOM pursues its mission to enrich the Malaysian economy and empower individuals through personal financing services, ACOM prioritizes safeguarding customer information by continuously enhancing its cybersecurity resilience.

Before partnering with ABeam, ACOM benefited from general guidance on information systems and security management provided by its parent company, ACOM Co. Ltd. in Japan. ACOM also had established risk management processes, including internal audits focused on legal and regulatory compliance, as well as robust Governance, Risk, and Compliance (GRC) practices that maintained comprehensive corporate policies and standard operating procedures. While these existing processes laid solid foundation for Information Security Management System (ISMS), they were not specifically designed to meet the rigorous requirements of the ISO/IEC 27001:2022 standard. As a result, integration and alignment were necessary to ensure that ISMS operations complemented existing practices without creating redundancy, paving the way for a more effective and certifiable security management framework.

The ISO/IEC 27001:2022 standard can be challenging to interpret due to its formal, high-level language, which is often descriptive rather than prescriptive. The standard does not explicitly specify the exact steps organizations must take to achieve compliance. Instead, it leaves the approach to fulfilling each requirement up to the organization—whether that means implementing a new system or establishing a manual process. For organizations pursuing certification for the first time, it can be difficult to determine precisely what actions are needed to meet each requirement. Additionally, the 93 controls outlined in Annex A of the ISO/IEC 27001:2022 standard may appear daunting and overwhelming, especially for those new to the framework.

When implementation team members are not well versed with the ISO/IEC 27001:2022 requirements, several issues can arise. These may include the establishment of inadequate controls and the omission of mandatory documentation, both of which can result in non-conformities during the certification assessment. The number and severity of such non-conformities can complicate the process of obtaining or maintaining certification.

ISO/IEC 27001:2022 Key Requirements ISO/IEC 27001:2022 Key Requirements

Key Project Success Factors

Strategic Leadership, Cross-Functional Collaboration, and Continuous Improvement

Securing endorsement and dedicated resources from ACOM management was fundamental to the success of the ISMS initiative. This top-level support ensured that the project was strategically aligned with organizational goals and fully resourced for optimal execution. Leadership’s active involvement set a clear direction, empowered teams, and fostered a culture of accountability. Their commitment not only provided the necessary momentum but also reinforced the importance of information security across all levels of the organization, making it a shared priority and enabling rapid, decisive progress toward ISO/IEC 27001:2022 certification.

ABeam and ACOM conducted structured workshops and established effective communication channels, enabling a shared understanding of ISMS objectives across all departments.
These efforts accelerated risk assessment, risk treatment, and documentation activities, cultivating broad organizational commitment. Regular ISMS Committee Meetings were held not only to monitor progress but also to encourage active questioning and provide constructive advice. Tailored awareness training sessions were delivered to diverse audiences—including front office, back office, information security officers, and top management—ensuring everyone understood their roles and responsibilities in maintaining a secure environment.

Proactive engagement of ISMS committee members from the front office, back office, legal, and IT—working in close partnership with ABeam Consulting—enabled the effective implementation of information security management processes that were seamlessly integrated with existing business operations. ABeam provided practical guidance on each requirement and clarified auditor expectations, ensuring that all stakeholders could contribute effectively. This collaborative approach ensured that all stakeholders were empowered to contribute meaningfully, resulting in a unified and resilient security posture.

To sustain the initiative, ABeam and ACOM implemented systematic reviews, internal audits, and corrective actions, strengthening the organization’s security posture. ABeam shared insights into typical pitfalls and common reasons for nonconformities, equipping ACOM with the knowledge to avoid these issues and ensure a smooth certification process. Risk-driven prioritization of controls safeguarded critical operations while maintaining productivity and business agility. This ongoing cycle of review and improvement embedded a culture of continuous enhancement, ensuring the ISMS remained effective and aligned with evolving business needs.

BEFORE & AFTER: The Impact of ISMS Implementation BEFORE & AFTER: The Impact of ISMS Implementation

ABeam’s Contribution

Delivering Efficient and Audit-Ready ISMS Implementation Through Close Partnership

ABeam played atransformative role in ACOM’s ISMS journey, delivering a seamless, efficient, and cost-effective path to ISO/IEC 27001:2022 certification. ABeam accelerated ISMS implementation by deploying seasoned consultants with deep expertise in both the technical requirements of ISO 27001 and the practical realities of facing ISO assessment auditors from leading certification bodies. Leveraging proven frameworks, templates, samples, and best practices, ABeam minimized inefficiencies and reduced development costs, ensuring every step was audit-ready and aligned with industry standards.

Embodying the “Real Partner” philosophy, ABeam worked on-site as an integrated member of the ACOM team. This close collaboration fostered stakeholder alignment through multiple streams of targeted workshops and established robust cross-functional communication channels, ensuring all teams moved forward together. ABeam’s consultants were not just advisors—they were active participants, sharing responsibility and ownership throughout the project lifecycle.

After ISMS was implemented in ACOM, ABeam conducted internal audits that simulated the certification assessment, combining objective evaluation with a consultative approach. This enabled the team to identify gaps, receive practical advice, and confidently address ISO 27001 certification assessment auditor expectations.

ABeam tailored the project schedule to fit ACOM’s unique needs, successfully implementing the ISMS within a focused six-month program. This approach ensured that business-as-usual operations continued without disruption. ABeam’s one-stop support package covered all aspects of implementation, including vulnerability scans and internal audits, eliminating the need for ACOM to engage multiple partners and reducing both cost and time.

Through ongoing reviews, corrective actions, and internal audits, ABeam helped embed a culture of continuous improvement, establishing a resilient and sustainable information security environment for ACOM.

ABeam ISMS Support Package ABeam ISMS Support Package
ABeam ISMS Support Model Schedule ABeam ISMS Support Model Schedule

By implementing an ISMS, ACOM has strengthened its information security framework while improving governance, building stakeholder trust, and establishing a scalable foundation for sustainable growth.
Furthermore, strengthening the information security framework and improving governance within an organization helps build stakeholder trust and establishes a foundation for sustainable business growth.
ABeam contributes to these efforts by aligning security measures with management priorities and business objectives.


“It was a challenge to achieve ISMS certification in just 2nd year of business in Malaysia. Yet, it also became a defining opportunity to demonstrate our belief that safeguarding customer data is essential to building customer trust —and that trust is the starting point for success of the business.

Although ISMS certification was pursued at an early stage of our business, it was made possible with ABeam’s practical consulting and guidance. They helped us navigate the complexities of ISMS and clearly understand that it is not a one-time effort, but an ongoing commitment to continuous improvement. Their guidance reflected a deep understanding of our business and underlying beliefs and focused on what truly works in the real world.”

Yukiko Kusumoto
Director / Executive Officer
Planning Division
ACOM (M) SDN. BHD.

Yukiko Kusumoto Director / Executive Officer Planning Division ACOM (M) SDN. BHD.

“At ACOM, customer trust is fundamental to everything we do. As a lean, small-sized organization, establishing effective information security governance was a key challenge for us.

With ABeam alongside us, their expertise, responsiveness, and collaborative approach provided the support we needed to implement a robust yet practical information security framework.
ABeam delivered a tailored solution that fits our operational landscape and demonstrated that strong governance and information security are achievable for small organizations with the right partner.”

Nasuha Sukri
Legal and Compliance
ACOM (M) SDN. BHD.

Nasuha Sukri Legal and Compliance ACOM (M) SDN. BHD.

Customer Profile

Company name
ACOM (M) SDN. BHD.
HQ Location
D-07-05, D-07-06, D-07-07 & D-07-08, Menara Suezcap 1, KL Gateway, No. 2, Jalan Kerinchi, Gerbang Kerinchi Lestari, 59200 Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur
Estd.
2021
Business
Licensed Moneylenders
Capital stock
Not Disclosed
ACOM (M) SDN. BHD.

Apr 28, 2026

Contact

Click here for inquiries and consultations