Ah, but there COULD be good reasons, initially, couldn't there? Taking a simple statement, from one person - who has not stated THEIR motivations - as a condemnation of managements' support or commitment is dangerous, don't you think?
You are correct Andy N.
Initially, management can try to "test the water" with a limited scope. It worked with ISO/IEC 27001:2005 as that standard was poorly written in relation to determining the scope. When ISO/IEC 27001:2013 arrived, the requirements for determining the scope became more detailed than the previous version.
Stating upfront that management does not want to change the scope is, IMHO, akin to refusing to step out of the box to look at things which could do more benefit to the organization.
My suggestion is go thru the "new" shall requirements; re-assess the limits and boundaries of the ISMS by looking at the issues, both internal and external; and then come to a decision.
But deciding on staying put without going through the thought process seems a bit wonky.
Happy New Year everyone!
Richard