AI software · under 20 employeesISO 27001 and ISO 42001, and a government contract won
2 monthsto audit-ready for both standards
- The situation
- The company was bidding for a contract with a European government institution. To be considered at all, it had to show internationally recognized ISO certification.
- What we did
- Its processes worked well but were barely documented. We turned them into one program for information security and AI governance and closed the remaining gaps.
- The result
- Audit-ready in two months, with certification audits starting in the third. The company achieved ISO 27001 and ISO 42001, then won the government contract.
Security technology · under 20 employees- Certification: Managed
- Virtual CISO
Re-certified on ISO 27001:2022, and still working together
2 monthsfrom contract to re-certification audit
- The situation
- The company's ISO 27001 certificate was in its final year on the 2013 version. Other priorities had left the program behind, and it had to move to the 2022 version.
- What we did
- We ran a gap assessment, moved the program onto a GRC platform, closed the gaps against ISO 27001:2022 and supported the team through the external audit.
- The result
- Re-certified with no findings at all, and the team took the program in-house. Months later, they invited us back as virtual CISO to run the program and explore further certifications.
Real estate technology · under 50 employees- Certification: Managed
- Virtual CISO
From a stalled ISO 27001 program to a certificate
3 monthsto certification, after nine months without progress
- The situation
- After nine months with another provider and a GRC platform, certification was still out of reach, while prospects kept sending security questionnaires.
- What we did
- We quickly assessed the existing program, pinpointed the gaps blocking certification and closed them with the team. Within two months, it was ready for its audits.
- The result
- The company passed its certification audit and received its ISO 27001 certificate the following month. The certificate has since helped it win new customers.
Software development · 150–200 employees- Certification: Managed
- Virtual CISO
A virtual CISO for a company-wide security program
6 monthsto ISO 27001 across the whole company
- The situation
- After seeing our work for another client, the company brought us in as virtual CISO to build security across the organization, including its HIPAA and GDPR obligations.
- What we did
- We rolled out a GRC platform company-wide, set up the security program, coordinated control implementation across teams and prepared the company for certification.
- The result
- Within six months, the platform was running across the company, ISO 27001 was achieved and a structured program was in place for HIPAA and GDPR.