Answers on information security
ISO 27001, BSI IT-Grundschutz, NIS2, DORA, ISMS and external ISO: the most important questions, answered clearly and honestly.
NIS2 applies to companies with 50 or more employees or 10 million EUR in revenue across 18 sectors, as well as to smaller businesses classified as critical. In the free initial assessment, we clarify whether you are affected and what specific action is required.
An information security management system (ISMS) is the organisational framework of policies, processes and controls with which a company systematically manages its information security. It ensures that risks are identified, measures are implemented and their effectiveness is regularly reviewed. ISO 27001 and BSI IT-Grundschutz are the most widely used frameworks for this.
No. IT security protects technical systems such as networks and servers. Information security is broader and protects information in every form, including paper documents, processes and the knowledge of employees. An ISMS covers both aspects and complements them with organisational measures.
Depending on the starting point, typically four to nine months: from the gap analysis and ISMS implementation through to the external certification audit. We support every step until all findings are closed.
The costs depend on company size, scope and existing documentation. After a free initial assessment, you receive a fixed quote rather than a flat rate.
We start with a gap analysis, define the scope and create a prioritised roadmap. We then build up policies and controls, conduct internal audits and support you through to the external certification audit.
You receive an experienced information security officer as a managed service, without having to create a dedicated full-time position. They manage your ISMS, prepare audits and maintain ongoing compliance.
An internal information security officer knows the company inside out but creates fixed costs and cover risks. An external ISO as a service brings immediate experience from many projects, remains independent and scales with demand. For mid-sized businesses, the external model is usually more cost-effective.
ISO 27001 is internationally recognised and risk-based, while BSI IT-Grundschutz is measure-oriented and widely used in the German public sector. Companies operating internationally are usually better served by ISO 27001, whereas the public sector often requires BSI IT-Grundschutz. The two can be combined.
TISAX is based on ISO 27001 but is the mandatory assessment standard of the automotive industry. Anyone supplying OEMs or suppliers generally needs TISAX; an existing ISMS based on ISO 27001 is the ideal foundation and considerably shortens the path.
DORA has applied since January 2025 to financial entities in the EU, including banks, insurers, payment service providers and investment firms, as well as to their ICT third-party service providers. The regulation requires robust ICT risk management, incident reporting and resilience testing.
The GDPR protects personal data, while NIS2 governs the cybersecurity of essential and critical entities. NIS2 requires technical and organisational measures as well as reporting obligations, regardless of whether personal data is affected. Many companies have to comply with both.
For NIS2 violations, fines of up to 10 million EUR or 2 % of global annual turnover can be imposed, depending on the type of entity. In addition, management can be held personally liable. We help you meet the requirements on time and avoid this risk.
We support companies throughout the DACH region, that is Germany, Austria and Switzerland, in German, English and French. We work remotely and, where needed, on site, for example on audit day.
Was your question not covered?
Tell us about your situation in a free initial assessment. We answer clearly and without obligation.
Request initial assessment