Skip navigation

Information security for the mid-size enterprise

An adaptable approach to reliable certification

ISO 27001 consulting from practitioners – from the first gap analysis to a successful audit.

Seasoned practitioners who speak your language

As a fully certified company, we have firsthand experience of ISO 27001 and apply its principles as part of day-to-day business, supported and guided by our in-house ISMS. We know exactly how to align your organisation with the standard so as to maximise your benefits and impress your auditors. The advice provided by our consultants combines technical expertise with a pragmatic understanding of the mid-sized enterprise to create lean, audit-ready processes that strengthen your workflows, give your teams long-term support and provide a clear path to certification.

Information security doesn’t have to be complex or hamper your day-to-day business. We translate ISO 27001 into lean, pragmatic processes that are an exact fit for your corporate structure. Together, our team works with yours to create an audit-ready ISMS while carefully addressing the typical concerns that prevent many companies from pursuing certification.

1. Maintain operational capability

Create space to pursue your core business. Our structured approach to support minimises the workload for your departments and frees up operational capacities.

2. Ensure compliance but stay agile

Security standards without rigid structures: we integrate ISO 27001 into your processes so that your decision-making remains agile and your workflows stay flexible.

3. Fulfil regulatory requirements to the letter

Whether you need certification to meet tender specifications, customer requirements or regulatory standards, we get your company over the line quickly, calmly and with full legal compliance.

two people hand closeup working on a laptop

The best rollout plan is the one that doesn’t disrupt your routine. To make your path to ISO 27001 as smooth as possible, you need a partner who speaks your language and translates the ISO requirements into day-to-day practice. Our key advantages – your practical benefits:

1. Real practical experience from own operations

Our business applies BSI C5 standards and its own ISMS each and every day. We’re aware of the typical issues encountered and know exactly where auditors will be looking.

2. Made-to-measure – not off-the-shelf

Instead of imposing a one-size-fits-all solution, we tailor ISO 27001 to your company’s size, available tools and unique culture.

3. Technological and operational know-how

We speak the same language as your IT, developer and business teams, transposing asset management, access rights and risks directly into your business processes.

1. Kick-off

We use a carefully structured kick-off meeting to clarify your goals, your overall conditions and the optimum scope for your certification. You get a clear roadmap that provides a realistic breakdown of milestones, work packages and time resources, and gives you planning certainty from day one of your project.

2. Analysis

We conduct targeted and minimally disruptive interviews with your key employees to analyse your existing IT and process landscape. We identify existing strengths and real gaps between current processes and ISO 27001, and transfer the results to a prioritised, company-specific action plan.

3. Rollout

We provide you with active advice and assistance for creating security models, policies and the pragmatic risk assessment. We also anchor all actions taken onto your existing workflows and inventory – this ensures that your ISMS is up-to-date, accepted by your teams and allows daily business to continue undisturbed.

4. Certification

Before the official audit, we give your ISMS a dry run in a simulated internal audit, to ensure any remaining gaps can be closed comfortably by audit day. We accompany you through the audit with the external auditor and you can rely on us to provide the same level of support for future surveillance audits.

Pragmatic asset management

Typical approach: Complex rollout of expensive additional software plus months of configuration.

Our practical approach: We use existing inventory lists and systems. We work with your team to extend these where necessary to include the required standard fields (level of protection, responsible person, etc.) – lean, cost-effective and 100% audit-ready.

Focused risk assessment

Typical approach: Pages and pages of theoretical tables that are never used in day-to-day business.

Our practical approach: Our facilitators organise a compact workshop with your management team to evaluate the real threats to your business. You get a plain-language risk matrix that your team can work with and keep up-to-date – and which auditors accept unchallenged.

Andreas Bögemann

Ready for your ISO 27001 certification?

Let’s work together to identify a lean and audit-capable approach to certification in your company.