Services

ISO/IEC 27001 as the organisational foundation

An information security management system (ISMS) to ISO/IEC 27001 brings order to your security and at the same time provides internationally recognised evidence. Instead of isolated one-off measures, a system emerges that captures risks, derives measures, checks their effectiveness and improves continuously.

Risk-based, not a checklist

At its core the standard is a risk-based approach: you identify your assets worth protecting, assess the risks, and select suitable measures from the catalogue in Annex A. Which measures you implement, and why, you record in the Statement of Applicability. This documented line of reasoning is what distinguishes an ISMS from a mere collection of technical controls — and what convinces certifiers and authorities alike.

The bridge to NIS2

ISO/IEC 27001 and NIS2 overlap strongly. A functioning ISMS covers a large part of the measures under Article 21, from risk analysis to training. We build your ISMS so that it serves both ends, and map the controls to the NIS2 obligations.

Our services

Setting up and developing the ISMS, internal and second-party audits, preparation for third-party certification, and mapping the measures to NIS2. You work directly with a certified ISO/IEC 27001 Lead Auditor — not an intermediary team. In OT-adjacent environments in particular, we make sure the measures fit operational technology.

How an ISMS project runs

An ISMS takes shape in manageable stages: first we clarify context and scope, then comes the risk assessment from which the Statement of Applicability follows. We then implement the chosen measures or support your team in doing so, run internal audits and close any deviations. Only once the system holds do you go into external certification — with no nasty surprises in the audit. We keep the documentation deliberately lean and focused on what matters.

When certification is worthwhile

Certification is especially worthwhile when customers or tenders demand it, when you need NIS2 evidence, or when you want to put your information security on a traceable footing for good. Even without formal certification an ISMS is valuable: it brings clarity to responsibilities, risks and measures — and makes security controllable rather than accidental.

Further reading: NIS2 & ISO/IEC 27001 · vCISO & Ongoing Advisory

Start an ISO 27001 project

A free intro call, no commitment, a reply within 24 hours.