Our process

To resilient security in four steps

A clear, repeatable path from the first analysis to ongoing operation. Every phase creates transparency and moves you closer to your goal, without losing the overview.

1
Step 1

Analysis

Before we build anything, we gain a clear picture. In under two weeks we capture your current state and compare it systematically against ISO 27001 and BSI IT-Grundschutz.

  • Gap analysis against ISO 27001 and BSI IT-Grundschutz
  • Complete asset inventory
  • Protection needs assessment per asset
  • Initial risk assessment
  • Prioritized roadmap by risk and effort
  • Management summary for the leadership team
Result: You know exactly where you stand and which steps are worth taking first.
2
Step 2

Architecture

Based on the analysis, we design your information security management system, tailored to fit and free of unnecessary ballast.

  • Definition of the scope
  • Policies and procedures created
  • Annex A controls or BSI modules selected
  • Roles and responsibilities defined
  • Statement of Applicability documented
Result: A robust security concept that fits your organization and passes the audit.
3
Step 3

Certification

We implement the measures and prepare you specifically for the external audit, so that it becomes a formality.

  • Implementation of the planned measures
  • Internal audits to verify effectiveness
  • Mock audit under real assessment conditions
  • On-site support on the audit day
  • Findings tracked through to closure
Result: The certificate, with no nasty surprises and no follow-up audit.
4
Step 4

Operation

After the certificate, everyday life begins. We keep your ISMS alive, effective and ready for audit at any time.

  • Ongoing maintenance of the documentation
  • Quarterly reviews with measurable KPIs
  • Awareness measures for the workforce
  • Continuous monitoring of the measures
  • Preparation for the annual surveillance audits
Result: Compliance stays the normal state, instead of lapsing after the audit.
How we work

Three principles in every step

Transparency

You always know where your project stands, with clear interim results instead of a black box.

Prioritization

We work by risk and effort, not by the length of a checklist.

Sustainability

We build for operation, not for the drawer. Your ISMS stays effective.

Ready for the first step?

The free initial assessment is the start of phase 1. Non-binding, confidential and with a clear result.

Request initial assessment