Technical implementation support for ISO and NEN standards (Netherlands)
We support small and medium-sized organisations (20–500 employees) with the technical implementation required for ISO and NEN certifications.
Many organisations have policies, risk assessments and an ISMS in place, but audits still fail or are delayed. The reason is usually not documentation, it is the IT environment. Auditors ultimately verify whether security controls actually exist and operate in practice.
Our role is to ensure that the implemented controls in the infrastructure match the requirements of the standard and can be demonstrated during an audit.
We are not auditors and not a policy consultancy. We implement and verify technical security controls so organisations can demonstrate compliance.
Typical audit findings relate to:
We address these issues directly in the IT environment.
We map systems, applications, services and data flows and relate them to business processes. This supports risk assessments, Business Impact Analyses and supplier management.
Implementation of secure configuration standards for:
Centralised logging and audit trails allowing organisations to demonstrate that security incidents would be detectable and traceable.
Processes and reporting that demonstrate timely remediation of vulnerabilities and updates.
Verification of backup integrity and restore capability, including recovery objectives (RTO/RPO) and disaster recovery procedures.
Implementation of domain authentication and transport security mechanisms such as SPF, DKIM, DMARC, DNSSEC, DANE and MTA-STS.
Audits often fail not because controls are missing, but because they cannot be demonstrated.
We ensure organisations can show:
This makes the audit a verification step rather than a discovery process.
We do not replace the information security governance function or the certification body. We work alongside them by implementing the technical measures required by the ISMS and providing demonstrable evidence from the infrastructure.
We typically start with a short technical assessment to determine the current state of the environment and the gap towards certification readiness. The organisation receives a practical improvement plan with prioritised actions.
We operate in the Netherlands and work on-site or remotely.
If you are an auditor, consultant, or international client and want to understand how the technical controls are implemented, feel free to contact us. We are happy to explain our approach or coordinate directly during an audit.