ISMS calendar
A clear annual plan of recurring activities, owners and deadlines — ideally inside your existing tools.
Management systems
Certification is a milestone, not the finish line. We help you operate and improve an existing ISMS so that it stays current, useful and audit-ready — without a hectic sprint before every surveillance audit.
Most ISMS problems are not in the design. They appear in daily operation, month after month.
You choose the scope. Some customers want a monthly rhythm, others support for specific cycles.
A clear annual plan of recurring activities, owners and deadlines — ideally inside your existing tools.
Regular review of risks and treatment plans, including new systems, suppliers and changes.
Checking whether controls are implemented and effective, and keeping the SoA current.
A clean structure so that evidence is collected continuously instead of right before the audit.
Keeping policies and procedures current and aligned with how you actually work.
Structured review of critical suppliers and service providers.
Planning and performing internal audits and preparing meaningful management reviews.
Tracking findings and corrective actions until they are really closed.
Maintaining the action list, following up on open activities and keeping the ISMS moving between audits.
When a review finds a gap, we help determine and implement the next step — process, technology, vendor or training.
Integrated ISMS support
An ISMS continuously produces work: requirements, risks, findings, objectives. Our support follows what your management system identifies — from the requirement to a measure that is implemented, evidenced and reviewed.
Many consultants would write “implement stronger authentication” into a report and leave. This is what it can look like with us instead:
This is not a closed catalogue. If an activity, risk, control or improvement comes out of your ISMS, there is a good chance we can help you address it.
We do not claim to provide every specialist service ourselves — for example 24/7 SOC, MDR, penetration testing, digital forensics, emergency incident response or legal advice. Where these are needed, we help you define the requirement, find suitable specialists or solutions and integrate the result into your ISMS.
How deep we get involved
Every engagement is different. Most combine these three kinds of support — and shift over time as your team takes over.
We explain what is required, what the problem is, which options exist and what we recommend.
We work with your team to design processes, create structures, prepare documentation, run workshops and close gaps.
We help coordinate recurring activities, follow up on actions, review risks, prepare audits and reviews — and keep the momentum.
Part of the team — not a transfer of responsibility
Working alongside you does not mean we take over your management responsibilities. Risk ownership, process ownership, decisions and legal responsibilities stay with your organization unless something specific is agreed. Our role: help you do the work — and do it well.
We look at your ISMS as it is today: documentation, risks, controls, evidence, open findings and people involved.
We agree on what needs attention first — usually what matters for the next audit and for real risk reduction.
We set up a recurring rhythm of activities with clear owners, integrated into your existing processes and tools.
We work alongside your team: reviews, workshops, audits and follow-up. We explain, you decide.
Findings, incidents and changes feed back into the ISMS so it becomes more useful every cycle.
Part of your team, not an external compliance police force
We work with your information security officer, IT, process owners and management as colleagues. The aim is an ISMS that becomes part of normal operations — and a team that needs less outside help over time.
Organizational adoption
An ISMS can be perfectly documented and still fail — if people see it as bureaucracy, believe security belongs to IT, or only act right before the audit. That is why adoption is part of every implementation we do.
Over time your people become increasingly able to manage their responsibilities, recognize risks and changes, maintain processes and evidence, prepare audits and suggest improvements. We can keep supporting you — but your own ISMS maturity should grow.
ISMS maintenance is the ongoing operation and improvement of an information security management system after it has been introduced: reviewing risks, monitoring controls, updating documents, collecting evidence, running internal audits and management reviews, and closing corrective actions.
An ISO/IEC 27001 certificate is typically valid for three years. In between, the certification body carries out annual surveillance audits, followed by a recertification audit. Throughout this period the ISMS must demonstrably be operated and improved.
Yes. We start with a health check to understand the existing structure. Where it works, we keep it. Where it does not, we improve it step by step — without rebuilding everything.
We can take over or support many of the tasks associated with this role in close cooperation with your team. What is sensible depends on your organization, size and regulatory requirements — let us talk it through.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Awareness training connected to your ISMS, policies and systems — so employees understand not only what to do, but why.
Develop a clear incident response plan with your team: roles, escalation, communication, reporting and lessons learned.
Certification is not the finish line. What ISMS maintenance involves, which activities recur every year, and how to avoid the pre-audit panic.
Can an ISO 27001 ISMS use your existing tools? Yes — how wikis, document management, ticketing and project tools can carry large parts of it.
How to implement ISO 27001 step by step: scope, gap analysis, risk assessment, SoA, measures, internal audit and certification — realistically explained.
Tell us what is painful. We will suggest a support model that fits your team.