ISMS & ISO 27001
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Core expertise
Services
The information security management system is at the centre. Whatever it uncovers — risks, gaps, improvements — we implement together with your team. The services below are examples, not a closed catalogue.
Building, operating and integrating management systems — our core expertise.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Core expertise
Ongoing support for an existing ISMS: risks, controls, evidence, audits and reviews that keep happening — not just before the audit.
Core expertise
Introduce or maintain a quality management system according to ISO 9001 — practical, process-oriented and ready to integrate with other standards.
Combine quality, information security and AI governance in one integrated management system with shared processes.
Understanding regulatory requirements and turning them into effective measures for people, processes and technology.
Understand which cybersecurity regulations apply, identify the gaps and implement practical technical and organizational measures.
Awareness training connected to your ISMS, policies and systems — so employees understand not only what to do, but why.
Develop a clear incident response plan with your team: roles, escalation, communication, reporting and lessons learned.
When a gap is identified, we help you find the most appropriate measure: existing technology, process, open source or a suitable vendor.
Governing and securing the use of AI — embedded in existing governance.
Get an overview of AI use, set clear rules, assess risks and prepare for the EU AI Act and ISO/IEC 42001 — without creating another silo.
Plan and secure private or self-hosted AI: local models, controlled knowledge access and data sovereignty — governed like any other critical system.
When measures need technology or financing: market knowledge instead of guesswork.
Requirement-driven vendor selection with curated intelligence on 350+ cybersecurity vendors and a strong European and open-source focus.
Identify relevant funding programs for cybersecurity, digitalization and AI projects in Germany, the federal states and the EU.
Integrated ISMS support
An ISMS continuously produces work: requirements, risks, findings, objectives. Our support follows what your management system identifies — from the requirement to a measure that is implemented, evidenced and reviewed.
Many consultants would write “implement stronger authentication” into a report and leave. This is what it can look like with us instead:
This is not a closed catalogue. If an activity, risk, control or improvement comes out of your ISMS, there is a good chance we can help you address it.
We do not claim to provide every specialist service ourselves — for example 24/7 SOC, MDR, penetration testing, digital forensics, emergency incident response or legal advice. Where these are needed, we help you define the requirement, find suitable specialists or solutions and integrate the result into your ISMS.
How deep we get involved
Every engagement is different. Most combine these three kinds of support — and shift over time as your team takes over.
We explain what is required, what the problem is, which options exist and what we recommend.
We work with your team to design processes, create structures, prepare documentation, run workshops and close gaps.
We help coordinate recurring activities, follow up on actions, review risks, prepare audits and reviews — and keep the momentum.
Part of the team — not a transfer of responsibility
Working alongside you does not mean we take over your management responsibilities. Risk ownership, process ownership, decisions and legal responsibilities stay with your organization unless something specific is agreed. Our role: help you do the work — and do it well.
The big picture
If it comes out of your ISMS, there is a good chance we can help — or we will tell you honestly who is a better fit.