Information Security Consulting

Information Security Consulting

Approaching information security in a structured way – pragmatic and tailored to the organisation.

Whether you are facing initial requirements, concrete incidents, or the desire for a structured management system: information security raises many questions. The goal is to create clarity together – so you know where you stand and which next steps make sense.Building on that, I support you in a structured way through all phases – from the initial assessment to ongoing operations.Common starting points include requirements from customers or partners, specific security incidents, or the introduction of an information security management system (ISMS).

Analysis and Assessment

The starting point is a structured look at the current situation. The focus is not only on identifying weaknesses, but above all on developing a clear understanding of the actual requirements and objectives.Together, we clarify what expectations exist – whether driven by regulatory requirements, customer demands, or internal goals – and how these can be meaningfully implemented within the organisation. On this basis, existing processes, measures, and systems are reviewed to obtain a realistic picture of the current situation. The assessment follows established standards and proven practices, but is always interpreted in the context of individual conditions.The result is not a purely formal evaluation, but a solid foundation for your decisions – with clear priorities and concrete starting points for the next steps. From this foundation, further measures can be specifically derived and transferred into structured implementation.

Further information: Conducting Internal Audits

Establishing and Developing an ISMS

Based on the analysis, the next steps are defined together and implemented in a structured way – as part of a continuous development of information security.The implementation or further development of an ISMS follows the individual requirements and conditions. The goal is not a standardised solution, but a structure that fits the organisation and works in everyday practice.Depending on the starting point, different approaches may be appropriate – for example ISO/IEC 27001, BSI IT-Grundschutz, or industry-specific requirements such as TISAX, as well as regulatory requirements in the context of KRITIS and NIS2. What matters is choosing and practically implementing the right path for each organisation.A key element is also a functioning risk management system. Together, a suitable methodology is developed or an existing approach refined, to systematically identify and assess risks and derive appropriate measures. This creates a management system that not only meets requirements but also works in everyday operations and is embraced by your organisation.Implementation proceeds in a structured and transparent manner – from planning to managing individual measures and projects. This keeps progress visible and objectives in focus.Further information: Project ManagementDepending on requirements, adjacent topics can also be integrated, such as data protection management (PIMS/DSMS according to ISO/IEC 27701) or AI management systems according to ISO/IEC 42001 (AIMS). These can be sensibly incorporated into existing structures and developed further alongside information security as part of an integrated management system.Further information: AI Management Systems & Governance

Operations and Continuous Development

With the introduction of a management system, the foundation is laid – however, information security continues to develop and requires permanent management.Ongoing support can be provided flexibly, for example in the role of an external Information Security Officer (ISO), Information Security Manager, or CISO.The focus is on the structured further development of the ISMS, the coordination of security-relevant topics, and support with strategic questions. This includes, among other things, tracking measures, further developing policies and processes, and preparing and accompanying internal and external audits.Through regular involvement, requirements can be addressed early, measures managed proactively, and information security developed sustainably – without additional burden on day-to-day operations. This creates continuous and sustainable support – from the initial analysis through implementation to a stable, long-term management system.

From Implementation to Certification

Once a management system has been established or further developed, the next step may be certification.Further information: Certification Support

Ready for more security? Let's talk.

Schedule an appointment //

Whether you are facing initial requirements, concrete incidents, or the desire for a structured management system: information security raises many questions. The goal is to create clarity together – so you know where you stand and which next steps make sense.Building on that, I support you in a structured way through all phases – from the initial assessment to ongoing operations.Common starting points include requirements from customers or partners, specific security incidents, or the introduction of an information security management system (ISMS).

Analysis and Assessment

The starting point is a structured look at the current situation. The focus is not only on identifying weaknesses, but above all on developing a clear understanding of the actual requirements and objectives.Together, we clarify what expectations exist – whether driven by regulatory requirements, customer demands, or internal goals – and how these can be meaningfully implemented within the organisation. On this basis, existing processes, measures, and systems are reviewed to obtain a realistic picture of the current situation. The assessment follows established standards and proven practices, but is always interpreted in the context of individual conditions.The result is not a purely formal evaluation, but a solid foundation for your decisions – with clear priorities and concrete starting points for the next steps. From this foundation, further measures can be specifically derived and transferred into structured implementation.

Further information: Conducting Internal Audits

Establishing and Developing an ISMS

Based on the analysis, the next steps are defined together and implemented in a structured way – as part of a continuous development of information security.The implementation or further development of an ISMS follows the individual requirements and conditions. The goal is not a standardised solution, but a structure that fits the organisation and works in everyday practice.Depending on the starting point, different approaches may be appropriate – for example ISO/IEC 27001, BSI IT-Grundschutz, or industry-specific requirements such as TISAX, as well as regulatory requirements in the context of KRITIS and NIS2. What matters is choosing and practically implementing the right path for each organisation.A key element is also a functioning risk management system. Together, a suitable methodology is developed or an existing approach refined, to systematically identify and assess risks and derive appropriate measures. This creates a management system that not only meets requirements but also works in everyday operations and is embraced by your organisation.Implementation proceeds in a structured and transparent manner – from planning to managing individual measures and projects. This keeps progress visible and objectives in focus.Further information: Project ManagementDepending on requirements, adjacent topics can also be integrated, such as data protection management (PIMS/DSMS according to ISO/IEC 27701) or AI management systems according to ISO/IEC 42001 (AIMS). These can be sensibly incorporated into existing structures and developed further alongside information security as part of an integrated management system.Further information: AI Management Systems & Governance

Operations and Continuous Development

With the introduction of a management system, the foundation is laid – however, information security continues to develop and requires permanent management.Ongoing support can be provided flexibly, for example in the role of an external Information Security Officer (ISO), Information Security Manager, or CISO.The focus is on the structured further development of the ISMS, the coordination of security-relevant topics, and support with strategic questions. This includes, among other things, tracking measures, further developing policies and processes, and preparing and accompanying internal and external audits.Through regular involvement, requirements can be addressed early, measures managed proactively, and information security developed sustainably – without additional burden on day-to-day operations. This creates continuous and sustainable support – from the initial analysis through implementation to a stable, long-term management system.

From Implementation to Certification

Once a management system has been established or further developed, the next step may be certification.Further information: Certification Support

Ready for more security? Let's talk.

Schedule an appointment //

André Scherwinski | Sollschwitz 66A | 02997 Wittichenau

André Scherwinski | Sollschwitz 66A | 02997 Wittichenau