Information security for mid-sized companies

Information security by design.

We build your ISMS, guide you to ISO 27001 certification and keep your NIS2 and DORA compliance stable in everyday operations. Independent, pragmatic and all the way to a passed audit.

Vendor-independent Fixed price instead of flat rate Active across the DACH region
Compliance status actively monitored
ISO/IEC 27001
ISMS certified
compliant
BSI IT-Grundschutz
Modules modelled
compliant
NIS2 Directive
Art. 21 measures
implemented
DORA
ICT risk management
ready
0% guided through the audit,
all the way to certification
Who we are

Security that does not end on paper

WM Best Service is your external partner for information security in the DACH region. We translate standards into lived practice, so that compliance does not remain a project but becomes the normal state.

0+
Security projects supported
0
Standards from a single source
0
Countries in the DACH region
0%
Audit pass rate
Our services

What we deliver for your security

From the first gap analysis to ongoing operations: modular services that build on one another and adapt to your maturity level.

Our services

Four building blocks, one system

  • Managed Services
  • Setup & Implementation
  • Compliance & Regulation
  • Analysis & Assessment
Learn more

Managed Services

Security as an ongoing service rather than a one-off project. Your external information security officer runs your ISMS and your security awareness, from day one and without a dedicated full-time role. You gain expertise without staffing risk.

Setup & Implementation

We build your management system from the ground up: an ISMS to ISO 27001, IT-Grundschutz to BSI and a resilient incident and business continuity management. Tailored, audit-proof and workable in everyday operations.

Compliance & Regulation

NIS2, DORA and GDPR made understandable and cleanly implemented. We clarify whether they apply to you, prioritise the right measures and bring you into compliance on time, before fines or liability arise.

Analysis & Assessment

Before you invest, you know where you stand. Gap analysis, risk assessment to ISO 27005 and audit support deliver a prioritised roadmap instead of an endless list of shortcomings, with clear results for management.

Our process

Resilient security in four steps

A clear, repeatable path that creates transparency and never leaves you in the dark.

1

Analysis

Current-state assessment and gap analysis against ISO 27001 and BSI IT-Grundschutz in under two weeks.

2

Architecture

ISMS structure, policies and tailored Annex A controls, prioritised by risk.

3

Certification

Internal audits, mock audit and on-site support all the way to a passed certificate.

4

Operations

Ongoing maintenance, quarterly reviews and measurable KPIs instead of standstill after the audit.

Why WM Best Service

Trust you can verify

Neutrality and independence

Independent. And still close by.

We sell neither software nor hardware. Our recommendation is guided solely by your security, on equal terms, transparent and free of hidden interests.

The people behind our work

Technically strong. Personally approachable.

What defines us are people with character: experienced consultants who bring conviction and genuinely want to make a difference, rather than just ticking boxes.

Certification level, not paperwork

Security with a seal. And substance.

We do not build for the drawer, but for the auditor. What we set up is verified, documented and resilient, convincing internally and presentable externally.

Sustainable problem-solving

It is the root cause that counts, not the symptom.

We keep looking until it is clear where the real issue lies, and we do not stop until the solution takes hold. Sustainable means it still works long after we are gone.

Knowledge transfer

Knowledge has to flow, otherwise it is worthless.

We pass on what we have learned: openly, understandably and applicably. So that your team stays capable of acting, even without us. For us, that is the benchmark of good consulting.

Recognised standards and evidence

Quality that can be proven. Not just claimed.

We work to recognised standards such as ISO 27001 and BSI IT-Grundschutz, whether to international norms or industry-specific assessment procedures. Visible, transparent, resilient.

In focus

External ISO, ready to go

Instead of creating and filling a full-time position, you get an experienced information security officer as a managed service, with full responsibility and no cover risk.

Direct reporting line to management

Clear responsibility, short decision paths and regular status reports.

Immediate coordination during incidents

In an emergency every minute counts, we know what to do before it happens.

Quarterly reviews with measurable KPIs

Security becomes visible and manageable, instead of remaining a gut feeling.

Compliance without detours. We bring your information security up to certification level and keep it there.

WM
WM Best Service GmbH
Information Security, Dortmund
Frequently asked questions

Clarity before the first conversation

NIS2 applies to companies with 50 or more employees or 10 million EUR in revenue across 18 sectors, as well as smaller organisations classified as critical. In the free initial assessment we clarify whether it applies to you and what specific action is required.

Depending on your starting point, typically four to nine months: from the gap analysis through the ISMS setup to the external certification audit. We support every step until the findings are closed.

You get an experienced information security officer as a managed service, without having to create a dedicated full-time role. They run your ISMS, prepare audits and maintain ongoing compliance.

ISO 27001 is internationally recognised and risk-based, while BSI IT-Grundschutz is measure-oriented and widespread in the German public sector. Internationally active companies are usually better served by ISO 27001, while the public sector often calls for BSI IT-Grundschutz. Both can be combined.

See all questions
See all posts

Ready for security by design?

In a free initial assessment we clarify whether the regulations apply to you, what action is required and the fastest route to certification.

Request initial assessment