We support small and medium-sized organisations (20–500 employees) with the technical implementation required for ISO and NEN certifications.

Many organisations have policies, risk assessments and an ISMS in place, but audits still fail or are delayed. The reason is usually not documentation, it is the IT environment. Auditors ultimately verify whether security controls actually exist and operate in practice.

Our role is to ensure that the implemented controls in the infrastructure match the requirements of the standard and can be demonstrated during an audit.

We provide technical support for:

  • ISO 27001, 27002 and 27005
  • ISO 27017 and 27018 (cloud security & privacy)
  • ISO 27701 (privacy / GDPR)
  • ISO 22301 (business continuity)
  • ISO 20000-1 (IT service management)
  • NEN 7510, NEN 7512 and NEN 7513 (Dutch healthcare information security)

What we actually do

We are not auditors and not a policy consultancy. We implement and verify technical security controls so organisations can demonstrate compliance.

Typical audit findings relate to:

  • unknown assets or incomplete inventories
  • excessive administrative privileges
  • lack of logging and monitoring
  • untested backups
  • insecure default system configurations
  • cloud tenant misconfiguration

We address these issues directly in the IT environment.

Scope of technical implementation

Asset management & CMDB

We map systems, applications, services and data flows and relate them to business processes. This supports risk assessments, Business Impact Analyses and supplier management.

Security baselines & hardening

Implementation of secure configuration standards for:

  • Windows and Linux systems
  • network devices
  • Microsoft 365 and cloud platforms
  • new systems (standardised secure deployment)

Identity & Access Management

  • role-based access control
  • multi-factor authentication
  • lifecycle management (joiner/mover/leaver)
  • privileged account management

Logging, monitoring & incident visibility

Centralised logging and audit trails allowing organisations to demonstrate that security incidents would be detectable and traceable.

Vulnerability & patch management

Processes and reporting that demonstrate timely remediation of vulnerabilities and updates.

Backup & continuity

Verification of backup integrity and restore capability, including recovery objectives (RTO/RPO) and disaster recovery procedures.

Email and transport security

Implementation of domain authentication and transport security mechanisms such as SPF, DKIM, DMARC, DNSSEC, DANE and MTA-STS.

How this helps during audits

Audits often fail not because controls are missing, but because they cannot be demonstrated.

We ensure organisations can show:

  • which systems process sensitive or personal data
  • who has access and why
  • how incidents would be detected
  • that backups are restorable
  • that security settings are consistently applied

This makes the audit a verification step rather than a discovery process.

Working together with governance and auditors

We do not replace the information security governance function or the certification body. We work alongside them by implementing the technical measures required by the ISMS and providing demonstrable evidence from the infrastructure.

Initial assessment (Audit-ready analysis)

We typically start with a short technical assessment to determine the current state of the environment and the gap towards certification readiness. The organisation receives a practical improvement plan with prioritised actions.

Location

We operate in the Netherlands and work on-site or remotely.

Contact

If you are an auditor, consultant, or international client and want to understand how the technical controls are implemented, feel free to contact us. We are happy to explain our approach or coordinate directly during an audit.