Add your offcanvas content in here

The Company

Simplifying your IT-security journey.

Information Security Management System

An Information Security Management System (ISMS) brings structure to your information security: risk-based, spanning people, processes, and technology. mgm security partners implements your ISMS in a pragmatic and customized manner—easy to implement and tailored to your organization. Whether based on a standard such as ISO 27001 or BSI IT-Grundschutz, or completely customized if certification is not required.

We understand the measures and implement them in detail. No paper-based ISMS and no standard templates—just a system that works in everyday life and truly ensures security.

An ISMS encompasses more than one discipline

An effective ISMS integrates organizational, personnel, process, and technical components into a cohesive whole. We structure all areas to be as streamlined as possible and as comprehensive as necessary.

Information security is more than just IT security

  • People: Awareness, training, clear responsibilities, and a safety culture that is actively practiced at all levels.
  • Processes: Clear procedures for handling information, suppliers, incidents, access, and physical security.
  • Technology: Effective technical measures such as access control, hardening, encryption, logging, and backup.

Our ISMS Services

Offer

From the initial assessment to full-scale operation, in coordinated steps.

  • Assessment of Existing Measures and Processes
  • Define the Scope of Application and Protection Needs
  • Clarify Objectives, Framework Conditions, and Certification Requirements
  • A prioritized, realistic roadmap with milestones
  • Identify Values and Information Worth Protecting
  • Establish a methodology for assessing and managing risks
  • Select and prioritize measures based on sound reasoning
  • Integration with Existing Risk Management
  • Developing Guidelines, Policies, and Procedures
  • Define Roles, Responsibilities, and Reporting Lines
  • Audit-ready documentation instead of mountains of paper
  • Integration into Existing Management Systems
  • Access Management, Hardening, Cryptography, Logging, and Backup
  • Implementing Vulnerability and Patch Management
  • Integration with Penetration Testing and Security Testing
  • Specific, actionable recommendations
  • Awareness initiatives and training for all levels
  • Building a Sustainable Safety Culture
  • Clear, understandable rules instead of abstract guidelines
  • Involvement of Departments and Management
  • Preparing for Internal Audits and Management Reviews
  • Establish Key Performance Indicators and Effectiveness Assessments
  • Manage incident and improvement processes
  • Optional: Support through the certification process

According to standards or completely customized

  • ISO/IEC 27001 (certifiable): The international standard for ISMS. Ideal if you need a globally recognized certificate, such as for tenders, customers, or regulatory compliance. We’ll set up your ISMS so it’s ready for certification and guide you through the external audit.
  • BSI IT-Grundschutz (certifiable): The BSI’s proven approach, which is particularly widespread in the public sector and among KRITIS organizations. We implement IT-Grundschutz in a pragmatic manner, tailored to your security needs and your current situation.
  • Customized Approach (without certification): A streamlined, customized ISMS that implements exactly the measures required to address your risks. Easy to implement, without unnecessary overhead, and scalable at any time should you decide to pursue certification later.

The challenge

  • Setting up an ISMS ties up internal resources that are then lacking in day-to-day operations
  • Standard requirements are abstract and leave plenty of room for interpretation
  • Uncertainty about which measures are truly necessary and which are not
  • The Risk of a Paper ISMS That Isn't Put into Practice in Everyday Life
  • Information security is mistakenly treated as a purely IT issue

Our Added Value

  • Pragmatic, customized, and easy to implement for your company
  • We understand the measures and are implementing them in detail
  • In accordance with standards (ISO 27001, BSI Basic Protection) or tailored to your specific needs
  • An ISMS that is actually put into practice rather than just existing on paper
  • Security experts who are equally knowledgeable about technology and organizational matters

ISMS: Quick Answers to Your Questions

No. An ISMS and certification are two different things. If you don’t need a certificate, we’ll build a streamlined, customized ISMS that implements exactly the measures required to address your risks. It can be expanded at any time in the future to include certification under ISO 27001 or BSI IT-Grundschutz.

No. The scope of an ISMS depends on your security needs and the size of your organization. Even small and medium-sized businesses benefit from clear guidelines and a proactive approach to risk management. We tailor the ISMS so that it remains easy to implement and does not create unnecessary overhead.

Information security affects the entire organization, not just IT. People, processes, and technology all work together. Many incidents stem from a lack of awareness, issues with suppliers, or physical security. That is why we involve line departments, management, human resources, and procurement, working together with IT.

That depends on your specific context. ISO/IEC 27001 is internationally recognized and flexible in its approach. The BSI IT-Grundschutz is particularly widespread in the public sector and among KRITIS organizations, and it specifies concrete building blocks. During the assessment, we’ll recommend the appropriate path for you or a customized solution that does not require certification.

Yes. An effective ISMS addresses key requirements of current regulations, such as risk management, reporting processes, and technical security measures. We integrate regulatory requirements into the workflows your teams already use, rather than requiring them to document these requirements twice.

An ISMS is a cycle, not a one-time project

  • 1 – Analysis & Planning: Assess the current situation and define the scope, risks, and objectives.
  • 2 – Development & Implementation: Implement guidelines, processes, and technical measures.
  • 3 – Review & Audit: Verify effectiveness, conduct an internal audit, and hold a management review.
  • 4 – Improvement & Operation: Make adjustments, continue to develop, and optionally obtain certification.

From the Management System to Technical Depth

An ISMS defines which technical measures are necessary. We also implement and test them. Our portfolio of application security and security testing services ensures that these requirements translate into effective protection—from threat modeling and secure coding to penetration testing.

Why mgm security partners?

  • 25+ Years of Enterprise Security Consulting
  • ISO 27001, BSI Basic Protection, or a completely customized solution
  • 100% led by senior security experts
  • We understand the measures and are implementing them

We build ISMS solutions that work in everyday practice. Our consultants have in-depth knowledge of the standards and, at the same time, understand how measures actually work from a technical perspective, based on over 25 years of experience working on projects for banks, insurance companies, industrial firms, and software manufacturers. Instead of rolling out standard templates, we implement exactly what your risks require—solutions that are easy to implement and sustainable.

Maximiliane Mayer

Let's talk about your ISMS! Schedule an appointment!

DeepDive

Why an ISMS?

Information security is not achieved through individual tools or occasional projects, but through a system that provides lasting support. That is exactly what an ISMS is: a framework of guidelines, responsibilities, processes, and measures that an organization uses to systematically identify its sensitive information, assess risks, and select, implement, and continuously improve appropriate security measures.

The benefits are clear: You understand your risks and address them proactively, rather than waiting for the next incident to occur. You demonstrate a robust level of security to customers, partners, and regulatory authorities. And you meet growing regulatory requirements such as NIS2, DORA, and the Cyber Resilience Act, which require a structured approach to security management. A well-implemented ISMS makes security predictable, verifiable, and cost-effective.

Risks
Proactively assess and address issues rather than reacting to incidents
Proof
Demonstrate a reliable level of security to customers and partners
Regulatory Framework
Foundation for NIS2, DORA, CRA, and other requirements
Continuity
A system that delivers lasting results and grows with the company