ISO 27001 is the internationally recognised standard for information security management systems (ISMS). It defines the requirements for establishing, implementing, operating, monitoring and improving information security in order to ensure the confidentiality, integrity and availability of data through structured risk management.
Formal certification in the area of information security is a central component for our company in order to counteract the increasingly complex cyber threats and to be able to act as a reliable and secure partner for our customers on the market.
Decisive advantages
The ISO 27001 certification provides tangible improvements in collaboration to our customers and partners.
- Clear, standardised processes create transparency - resulting in traceable information security.
- Higher availability: our services become more fail-proof.
- More security: the protection of customer data is strengthened even further.
- Faster response to incidents: standardised incident management with rapid analysis of the causes.
- More quality in implementation: optimised standards in software development.
- Continuous improvement through regular audits.
Digital sovereignty is the order of the day
Against the backdrop of current geopolitical developments, digital sovereignty has become a focus topic for Europe. Operating IT services and storing data in data centres under European jurisdiction creates the proximity and security needed to ensure data protection compliance and the greatest possible independence.
In the area of information security, we must constantly stay ahead of the curve and continue to evolve. ISO 27001 certification is crucial for making our services even more secure for our customers in order to ensure future-proof collaboration.
Company-wide changes as a central challenge
In addition to the implementation of the purely technical and formal framework conditions, this project was very much characterised by the aspect of people management. Our positive and forward-looking corporate culture has always been geared towards continuous improvement and further development. Nevertheless, it is an enormous challenge to scrutinise and change processes throughout the company that have grown over many years and are fundamentally functional. Such a transformation requires a great deal of sensitivity and motivation at all levels.
The human factor continues to play an important role when it comes to cybersecurity. Cooperation, collaboration, inclusion and common goals are decisive factors in transformation processes."
The road to success - designing and implementing together
“Our basic premise from the outset was to take everyone in the company with us on this journey, because ultimately information security must be supported by all employees and practised on a daily basis.” says Marta Ban, as CISO responsible for the internal coordination of the certification project.
The key question was how we could motivate an entire company to actively support change. From the outset, we focussed on working together - shaping things together and relying as little as possible on implementing mere regulations. As a result, the process took longer and was more complex. But in doing so, we secured the central aspect of acceptance - the key factor for the success of the project.
We took small steps forward, scrutinised and tried to understand the needs of our employees. We also focussed heavily on cooperation between the departments. On the one hand, this strengthend the feeling of not being alone in this process and, on the other hand, this lead to departments learning a lot from each other. Ultimately the end result turned out to be much better due to this approach.